# Cisco Issues Critical Security Patches for Nexus 9000 Switches and IOS XR Platforms
Cisco has issued urgent security patches addressing multiple high-severity vulnerabilities across its networking infrastructure, affecting both its Silicon One-based Nexus 9000 series switches and IOS XR-powered platforms. The patches target a combination of remote code execution flaws, authentication bypasses, and other critical weaknesses that, if left unaddressed, could expose enterprise and service-provider networks to significant risk.
## Nexus 9000 Switches Vulnerable to Remote Code Execution
A newly disclosed vulnerability, catalogued under CVE-2026-20212, carries a CVSS score of 9.8 and affects Nexus 9000 switches built on Cisco’s Silicon One architecture. The flaw stems from the binding of services to an unrestricted IP address, leaving TCP ports 43210 and 43211 exposed within the default Layer 3 virtual routing and forwarding (VRF) instance.
This means that any unauthenticated attacker capable of reaching a switch’s network address on either of those ports can connect directly to the exposed service. Once connected, specially crafted input sent to the service is executed with root-level privileges on the device. Additionally, a malicious exploitation attempt can cause the S1HAL process to crash, forcing an automatic reload of the affected switch.
### Affected Hardware Models
Cisco has identified ten specific product identifiers (PIDs) as vulnerable to this Nexus 9000 flaw:
– N9324C-SE1U (Nexus Smart Switch)
– N9348Y2C6D-SE1U (Nexus Smart Switch)
– N9364E-SG2-O
– N9364E-SG2-Q
– N9396T12C-SE1
– N9348Y12C-SE1
– N9396Y12C-SE1
– N9336C-SE1
– N9K-C9804
– N9K-C9808
Other Nexus 9000 variants, switches operating in Application Centric Infrastructure (ACI) mode, and the Nexus 3000 and 7000 product lines are not affected by this vulnerability.
### Mitigation Strategies Before Patching
As of the disclosure date, Cisco stated it was not aware of any active exploitation of the flaw in the wild. The company has not yet published a comprehensive fixed-release table, instead directing customers to its Software Checker tool to determine eligibility for patched software. In the interim, Cisco has recommended several stopgap measures:
– **Upgrade** to the release version identified by Cisco’s Software Checker. Cisco noted that the protective shield’s operational mode transitions to “N/A” once the NX-OS version is upgraded to 10.6(4) or higher.
– **Infrastructure access control lists (iACLs)** that restrict management and control-plane traffic, or explicitly block TCP packets destined for TCP ports 43210 or 43211 on a locally configured IP address. Cisco confirmed this approach was validated in a test environment.
– **Live Protect shield lp00031**, a temporary mitigation tool described in Cisco’s Live Protect documentation. This shield is supported only on NX-OS 10.6(3), with a second shield package extending support to version 10.6(3s) on the two Smart Switch models. It is not available for the Nexus 9804 and 9808 platforms and requires SSH, Telnet, or NX-API access to deploy.
The vulnerability spans 45 NX-OS release versions, from 10.3(1) through 10.6(3s), according to an independent verification of the CVE Program’s record.
## IOS XR Hardening Release Addresses Seven Umbrella CVEs
In a separate but equally concerning announcement, Cisco rolled out an IOS XR hardening release that bundles seven umbrella CVEs across all supported IOS XR versions. The hardening model groups internally identified bugs under single umbrella CVEs, each mapped to a Common Weakness Enumeration (CWE) category and scored based on the most severe defect within that bucket.
### Critical CVEs in the Bundle
Two of the seven umbrella CVEs carry the maximum severity rating of 9.8:
– **CVE-2026-20274** — Covers memory-safety and resource-lifetime bugs that could lead to undefined system behavior or crashes.
– **CVE-2026-20279** — Addresses access-control weaknesses, including missing authentication for critical functions and improper certificate validation.
The remaining five CVEs, numbered CVE-2026-20275 through CVE-2026-20280, carry maximum scores ranging from 8.2 to 8.8. Cisco stated that the vulnerabilities impact all IOS XR releases, regardless of device configuration, and no workaround is available for any IOS XR version.
### Software Maintenance Updates (SMUs)
Cisco has provided Software Maintenance Updates (SMUs) for 15 specific IOS XR releases. The Cisco 8000 Series, NCS 1010, NCS 540L, and NCS 5700 Series — collectively known as XR7 (LNT) platforms — receive a dedicated SMU (CSCwv19790) that applies across all releases. Cisco indicated that approximately 16 SMUs may be available for each release.
A selection of the SMUs currently available covers the following release versions:
6.9.2, 7.3.2, 7.9.2, 7.9.21, 7.10.2, 7.11.2, 7.11.21, 24.2.2, 24.2.21, 24.4.2, 25.2.21, 25.4.1, 25.4.2, 26.1.2, and 26.2.1.
Cisco noted that future releases 26.2.2 and 26.3.1 will be the first fixed releases that do not require separate SMUs. For customers running a release outside the provided SMU table, Cisco recommended opening a Technical Assistance Center (TAC) case.
### SMU Coverage by Functional Area
The SMUs are organized by the functional area of the network protocol or feature they address:
– **BGP** — CSCwu14807; the 7.10 and earlier trains and 26.2.1 are not vulnerable.
– **crypto-ike** — CSCwv19170.
– **gRPC** — CSCwt41683.
– **IP-SLA** — CSCwv19173.
– **IS-IS** — CSCwv45645 and CSCwv19171, with additional platform-specific SMUs.
– **MPLS and MPLS-TE** — CSCwv40753 and CSCwu14825.
– **Multicast** — CSCwv19180 and CSCwu08799.
– **OSPF** — CSCwv40741 and CSCwv19171, with additional platform-specific SMUs.
– **Segment routing (IPv6 only)** — CSCwu13268 and CSCwv56312 across multiple release trains.
– **Segment routing (IPv4 only or IPv4 and IPv6)** — CSCwv38342.
– **TCP Authentication Option** — CSCwv36143 across multiple release trains.
– **Zero Touch Provisioning (ZTP)** — CSCwu36622; 26.2.1 is not vulnerable.
A cross-check by an independent source found that of the 111 IOS XR releases Cisco lists as affected, 14 currently have SMUs available, four are awaiting SMUs, and 93 must first be upgraded to a supported release before a fix can be applied.
## Broader Context: Escalating Threat Landscape
The September 2 patch cycle marks Cisco’s third scheduled hardening release in 30 days, following the first hardening drop on August 5, which also delivered IOS XE and Catalyst SD-WAN updates along with two CVSS 10.0 releases for Crosswork and Secure Workload platforms. This acceleration in disclosure cadence reflects Cisco’s shift toward a twice-monthly model that groups internally discovered bugs under umbrella CVEs.
The timing of these patches coincides with heightened scrutiny of Cisco IOS XR platforms, following a recent report by cybersecurity firm Sygnia documenting the activities of the China-nexus threat actor known as Fire Ant. First identified in 2025, Fire Ant has been observed deploying purpose-built implants on IOS XR routers that suppress syslog delivery, filter show command output, and maintain hidden Generic Routing Encapsulation (GRE) tunnels. The actor has also been observed capturing packet data from compromised routers, uploading it to external FTP servers, and conducting connection attempts and port scans against connected systems tied to critical infrastructure.
Sygnia noted that the investigation was triggered by the discovery of a tunnel interface active on a router with no corresponding running configuration or commit history, raising the alarming possibility that a device’s operational state could no longer be trusted to match its configuration and audit records.
## FAQs
**Q1: What is the most critical vulnerability in the latest Cisco patches?**
A1: The most critical vulnerability is CVE-2026-20212 affecting Nexus 9000 Silicon One-based switches, which allows unauthenticated, remote code execution with root privileges via TCP ports 43210 and 43211. It carries a CVSS score of 9.8.
**Q2: Which Nexus 9000 models are not affected by CVE-2026-20212?**
A2: Other Nexus 9000 models not listed in the vulnerable PIDs, Nexus 9000 fabric switches running in ACI mode, and the Nexus 3000 and 7000 lines are not affected.
**Q3: Is there a workaround available for the IOS XR vulnerabilities?**
A3: No. Cisco has stated there is no workaround for any IOS XR version affected by the hardening release vulnerabilities. Customers must upgrade to a fixed release or apply the relevant SMU.
**Q4: What is a Software Maintenance Update (SMU) in the context of IOS XR?**
A4: An SMU is a targeted software package that addresses specific bugs or vulnerabilities in a given IOS XR release without requiring a full version upgrade. Cisco has made SMUs available for 15 currently supported IOS XR releases.
**Q5: Which platforms are affected by the IOS XR hardening release?**
A5: The vulnerabilities affect all IOS XR releases regardless of device configuration. Specific XR7 (LNT) platforms include the Cisco 8000 Series, NCS 1010, NCS 540L, and NCS 5700 Series.
**Q6: Has Cisco confirmed any active exploitation of the Nexus 9000 flaw?**
A6: As of the disclosure date, Cisco stated it is not aware of any malicious use of CVE-2026-20212. However, the window between disclosure and potential exploitation is considered to be closing rapidly.
**Q7: What are the recommended immediate steps for Nexus 9000 switch owners?**
A7: Cisco recommends checking the Software Checker for the appropriate fixed release, implementing iACLs to block TCP ports 43210 and 43211, and, where applicable, deploying the Live Protect shield lp00031 as a temporary safeguard.
**Q8: How many IOS XR releases are affected by the hardening release?**
A8: Cisco lists 111 IOS XR releases as affected. Of these, 14 have SMUs available, four are awaiting SMUs, and 93 require an upgrade before a fix can be applied.
## Conclusion
The simultaneous disclosure of critical vulnerabilities across Cisco’s Nexus 9000 and IOS XR platforms underscores the growing complexity of securing modern networking infrastructure. With root-level code execution possible on unpatched Nexus switches and no workaround available for IOS XR vulnerabilities, network administrators face an urgent imperative to prioritize patch deployment. The trend of accelerating disclosure cadence and grouping bugs under umbrella CVEs signals a more transparent — but also more demanding — patching environment for enterprise security teams. Organizations running affected hardware should immediately assess their exposure, implement interim mitigations where available, and coordinate with Cisco support to expedite remediation.
Thank you for reading



