Ten switch models. Two open TCP ports. Root on the fabric that carries your AI training traffic.

CVE-2026-20212 — CVSS 9.8 — unauthenticated remote code execution as root on Cisco Nexus 9000 Series switches built on the Silicon One ASIC. Disclosed September 2, 2026 (cisco-sa-n9k-s1-rce-EH8dEtr).

WHAT ACTUALLY HAPPENED

The Silicon One integration in NX-OS binds a service to an unrestricted IP address — CWE-1327. The result: TCP ports 43210 and 43211 are reachable in the default Layer 3 VRF.

Send crafted data to that listener and it executes with root privileges. No credentials. No user interaction. It can also crash the S1HAL process and force a reload — so the same flaw is both RCE and denial of service.

Cisco did not find this via a bug bounty or a red team. TAC engineers hit it while working an unrelated support case.

Ten Silicon One-based Nexus 9000 models are affected. Nexus 3000, Nexus 7000, other Nexus 9000 platforms and 9000 Fabric Switches in ACI mode are not. Cisco PSIRT reported no known exploitation at publication. Patches are available.

WHY LOSING THE FABRIC IS WORSE THAN LOSING A SERVER

A compromised server is one workload. A compromised leaf or spine is every workload that transits it.

Root on a data centre switch means arbitrary traffic mirroring, silent ACL changes, route injection, and a persistence point that no EDR agent watches and no vulnerability scanner logs into. Network devices are the least monitored tier in most estates and the most privileged.

The detail that should worry you is the default VRF. Many teams assume management-plane services are confined to a management VRF and firewalled accordingly. Here the listener sits in the data-plane VRF — the one that reaches your compute, your storage and, in AI builds, your GPU fabric.

If your east-west segmentation assumes the switch itself is not a target, that assumption just expired.

WHAT TO DO NOW

INVENTORY BY ASIC, NOT BY MODEL NAME — the exposure follows Silicon One, so confirm the platform rather than trusting the Nexus 9000 label.

PROBE PORTS 43210 AND 43211 FROM THE DATA PLANE — test from where an attacker would actually sit, not from your management jump host.

PATCH, THEN RESTRICT — apply Cisco's fixed release and add infrastructure ACLs so control services are never reachable from workload segments.

TREAT SWITCHES AS MONITORED ASSETS — ship NX-OS syslog and config diffs to your SIEM, because unexplained reloads are a detection signal here.

Your firewalls are useless if the thing forwarding packets to them is owned.

Do you know which of your switches expose services in the default VRF today?
Turn the analysis into a plan

The gap between knowing the risk and closing it is a purchase order and a weekend.

We specify, source and deploy the equipment that closes it — firewalls, segmentation, secure remote access — and we support it afterwards.