Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
Read original article ↗AI Summary
Cisco disclosed a critical vulnerability, CVE-2026-20212, in 10 Silicon One-based Nexus 9000 switches that allows unauthenticated remote attackers to execute code with root privileges by exploiting exposed TCP ports 43210 and 43211. The flaw stems from binding to an unrestricted IP address, enabling direct access to a privileged service. Cisco has released patches and recommends immediate upgrades, while also providing temporary mitigations such as infrastructure ACLs and a Live Protect shield. Separately, a hardening release for IOS XR addresses 7 CVEs, including two rated 9.8, and ongoing exploitation of similar infrastructure is linked to the China-nexus threat actor Fire Ant, which has deployed stealthy implants on IOS XR routers to manipulate traffic and exfiltrate data.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.