Threat reportVulnerabilityTL-2026-2319

CVE-2026-20212: Critical Unauthenticated RCE in Cisco Nexus 9000 Series Switches (Silicon One ASIC)

criticalACTIVE

CVE-2026-20212 (TL-2026-2319) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-09-03 and last reviewed 2026-09-06. It has no confirmed attribution, affects Cisco Nexus 9000 Series Switches (Silicon One ASIC), references 1 CVE (CVE-2026-20212), maps to 11 MITRE ATT&CK techniques (T1046, T1059, T1190), and is covered by 9 detection rules and 16 indicators of compromise.

CVSS
9.8/10Critical
CVEs
1Referenced vulnerabilities
Techniques
11MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
16Indicators of compromise

Key facts for TL-2026-2319

Threat ID
TL-2026-2319
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
data-center-operators, cloud-service-providers, telecoms, financial-services, enterprise-networking
Target regions
Global
Detection rules
9
Indicators of compromise
16
Updates
2026-09-06 · revalidated 1× · latest source

Malware and tooling in CVE-2026-20212

Malware and tooling: Live Protect Shield lp00031

How CVE-2026-20212 works

Cisco patched CVE-2026-20212 (CVSS 9.8), a critical flaw in Nexus 9000 Series switches equipped with the Silicon One ASIC. TCP ports 43210 and 43211 are reachable in the default Layer 3 VRF, letting an unauthenticated remote attacker send crafted input that the S1HAL process executes as root, or crash S1HAL and force a device reload. Cisco TAC found the flaw during a support case; PSIRT reports no public disclosure or exploitation.

CVE-2026-20212 is a critical (CVSS 3.1 base score 9.8, vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) unauthenticated remote code execution vulnerability affecting Cisco Nexus 9000 Series Switches that ship with Cisco's custom Silicon One packet-processing ASIC. The root cause is classified as CWE-1327 (Binding to an Unrestricted IP Address): TCP ports 43210 and 43211, used by the S1HAL (Silicon One Hardware Abstraction Layer) service that mediates between NX-OS and the Silicon One ASIC, are bound and reachable within the switch's default Layer 3 virtual routing and forwarding (VRF) instance rather than being restricted to loopback or a management-only context.

An attacker who can route traffic to either port on an affected switch — no credentials, no user interaction, low attack complexity — can send specially crafted input directly to the S1HAL service. Successful exploitation executes arbitrary code with root privileges on the device. A failed or partial exploitation attempt can instead crash the S1HAL process, which forces the switch to reload, producing a denial-of-service condition that can disrupt an entire data-center fabric segment given the S1HAL process's role in ASIC packet-processing control. Because the exposed VRF is the switch's default (not a dedicated management-only VRF), any host with routed reachability to the device — including an attacker already positioned elsewhere inside the data-center fabric, not only a perimeter-facing attacker — can reach ports 43210/43211, making the flaw a lateral-movement/pivot risk within a compromised network as well as a direct initial-access risk. Root-level code execution on the NX-OS control plane also creates the technical precondition for an attacker to tamper with or replace the switch's system image to survive reboots, a pattern documented in prior real-world Cisco network-device implant incidents (e.g., SYNful Knock), though no such implant activity has been observed for CVE-2026-20212 specifically.

The vulnerability was identified by Cisco's Technical Assistance Center (TAC) during a customer support investigation rather than through external report, red-team finding, or in-the-wild detection. Cisco published advisory cisco-sa-n9k-s1-rce-EH8dEtr (version 1.0, final status) on 2026-09-02 alongside patched NX-OS releases. As of publication and as of this research (2026-09-03), Cisco PSIRT states it is not aware of any public proof-of-concept exploit code or malicious/exploitation activity involving CVE-2026-20212, and the CVE has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Because no public PoC exists, an attacker seeking to weaponize this CVE would need to independently develop an exploit from Cisco's own published advisory and/or by diffing the patched NX-OS 10.6(4) binaries against the vulnerable release line — i.e., the disclosure itself is currently the only public source of exploit-relevant capability information.

Only ten specific Silicon One-based Nexus 9000 product identifiers are affected: N9324C-SE1U, N9348Y2C6D-SE1U, N9364E-SG2-O, N9364E-SG2-Q, N9396T12C-SE1, N9348Y12C-SE1, N9396Y12C-SE1, N9336C-SE1, N9K-C9804, and N9K-C9808, running NX-OS releases from 10.3(1) through 10.6(3s) (45 releases in the vulnerable range per vendor coverage). Nexus 9000 switches operating in ACI mode, and the Nexus 3000/7000 product lines, are explicitly unaffected. Cisco directs administrators to the Cisco Software Checker to identify and apply the fixed NX-OS 10.6(4) release. Pending upgrade, Cisco recommends infrastructure access control lists (iACLs) denying inbound TCP 43210/43211 to the affected VRF, and — for switches specifically on NX-OS 10.6(3) or 10.6(3s) — offers a temporary "Live Protect Shield" (lp00031) that Cisco explicitly states does not replace patching.

Cisco's own commentary on this disclosure cycle is itself relevant context: Russ Smoak, Cisco's VP of Information Security, stated regarding the company's twice-monthly vulnerability disclosure cadence that "the window between disclosure and exploitation has effectively closed" — underscoring why Cisco frames rapid patch adoption for CVE-2026-20212 as urgent even absent current exploitation evidence. Separately, industry coverage of this disclosure has noted it lands amid a broader pattern of increased adversary interest in Cisco network infrastructure in mid-to-late 2026, including the China-linked Fire Ant group's custom IOS XR implants on Cisco routers reported in August 2026 and other actively exploited Cisco firewall CVEs the same month. None of that reporting ties any actor or campaign to CVE-2026-20212 itself — it is included here only as deployment-risk context, not as attribution.

MITRE ATT&CK techniques used in TL-2026-2319

Discovery

T1046 Network Service Discovery

Execution

T1059 Command and Scripting Interpreter

Initial Access

T1190 Exploit Public-Facing Application

Impact

T1499.004 Endpoint Denial of Service: Application or System Exploitation; T1529 System Shutdown/Reboot

Defense Evasion

T1562 Impair Defenses

Resource Development

T1584.008 Compromise Infrastructure: Network Devices; T1588.006 Obtain Capabilities: Vulnerabilities

Reconnaissance

T1595.001 Active Scanning: Scanning IP Blocks; T1595.002 Active Scanning: Vulnerability Scanning

defense-impairment

T1601.001 Modify System Image: Patch System Image

Affected products and versions in CVE-2026-20212

  • Cisco — Nexus 9000 Series Switches (Silicon One ASIC)
    Vulnerable versions: NX-OS 10.3(1) through 10.6(3s)
    Fixed in: NX-OS 10.6(4) and later

Remediation for CVE-2026-20212

Patches

  • NX-OS 10.6(4) and later resolves CVE-2026-20212 (per Cisco Software Checker guidance in advisory cisco-sa-n9k-s1-rce-EH8dEtr)

Immediate actions

  • Deploy an infrastructure ACL (iACL) denying inbound TCP traffic to destination ports 43210 and 43211 on the default Layer 3 VRF of any affected Nexus 9000 switch
  • Inventory the Nexus 9000 fleet for the 10 affected Silicon One PIDs (N9324C-SE1U, N9348Y2C6D-SE1U, N9364E-SG2-O/Q, N9396T12C-SE1, N9348Y12C-SE1, N9396Y12C-SE1, N9336C-SE1, N9K-C9804, N9K-C9808) using `show module`
  • Where running NX-OS 10.6(3) or 10.6(3s), apply Cisco's temporary Live Protect Shield lp00031 as an interim measure only

Workarounds

  • Infrastructure ACL blocking TCP 43210/43211 to the default L3 VRF
  • Live Protect Shield lp00031 (NX-OS 10.6(3)/10.6(3s) only, temporary, does not replace patching)

Longer-term hardening

  • Upgrade all affected switches to NX-OS 10.6(4) or later via the Cisco Software Checker
  • Segment switch management/control-plane VRFs from untrusted or general-purpose network segments
  • Track Cisco PSIRT and CISA KEV for any change in exploitation status for CVE-2026-20212

CVEs associated with CVE-2026-20212

CVE-2026-20212

Weaknesses (CWE) in CVE-2026-20212

CWE-1327

Timeline of CVE-2026-20212

  • CVE-2026-20212 is assigned an EPSS score of 1% (43rd percentile), consistent with no observed active exploitation.
  • Cisco publishes Snort Rule 67005 for intrusion detection systems to detect exploitation attempts against CVE-2026-20212 targeting TCP ports 43210/43211.
  • CISA-ADP coordinator records an SSVC assessment for CVE-2026-20212 classifying it as having no known exploitation but automatable with total technical impact.
  • Cisco PSIRT states it is not aware of any public disclosure or malicious exploitation of CVE-2026-20212 at time of publication.
  • Cisco publishes the temporary Live Protect Shield lp00031 for NX-OS 10.6(3)/10.6(3s), explicitly noting it does not replace patching.
  • Cisco releases patched NX-OS 10.6(4), directing administrators to the Cisco Software Checker to identify and apply the fix.
  • Cisco publishes security advisory cisco-sa-n9k-s1-rce-EH8dEtr disclosing CVE-2026-20212 (CVSS 9.8) in Nexus 9000 Series Switches with Silicon One ASIC.
  • In coverage of Cisco's twice-monthly PSIRT disclosure model, Cisco VP of Information Security Russ Smoak is quoted stating the window between vulnerability disclosure and exploitation has effectively closed, framing the urgency of patching CVE-2026-20212 promptly despite no observed exploitation.
  • CVE-2026-20212 confirmed absent from the CISA Known Exploited Vulnerabilities catalog as of this research, consistent with Cisco's no-known-exploitation statement.
  • The Hacker News, CyberSecurityNews, eSecurityPlanet, and other outlets publish independent technical coverage of CVE-2026-20212.
  • Security Affairs publishes coverage of the Cisco Nexus 9000 Silicon One RCE disclosure.

Update history for TL-2026-2319

Sources cited for CVE-2026-20212

Detection coverage for TL-2026-2319

As of 2026-09-06, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2319 across Splunk SPL, Microsoft KQL and Sigma, covering 16 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
16 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats