# CVE-2026-20212: Critical Unauthenticated RCE in Cisco Nexus 9000 Series Switches (Silicon One ASIC)

> Cisco patched CVE-2026-20212 (CVSS 9.8), a critical flaw in Nexus 9000 Series switches equipped with the Silicon One ASIC. TCP ports 43210 and 43211 are reachable in the default Layer 3 VRF, letting an unauthenticated remote attacker send crafted input that the S1HAL process executes as root, or crash S1HAL and force a device reload. Cisco TAC found the flaw during a support case; PSIRT reports no public disclosure or exploitation.

- **Published:** 2026-09-03T00:00:00Z
- **Last reviewed:** 2026-09-06T13:52:28.662Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2319
- **ID:** TL-2026-2319
- **Severity:** CRITICAL (CVSS 9.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 16 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-20212

## Description

CVE-2026-20212 is a critical (CVSS 3.1 base score 9.8, vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) unauthenticated remote code execution vulnerability affecting Cisco Nexus 9000 Series Switches that ship with Cisco's custom Silicon One packet-processing ASIC. The root cause is classified as CWE-1327 (Binding to an Unrestricted IP Address): TCP ports 43210 and 43211, used by the S1HAL (Silicon One Hardware Abstraction Layer) service that mediates between NX-OS and the Silicon One ASIC, are bound and reachable within the switch's default Layer 3 virtual routing and forwarding (VRF) instance rather than being restricted to loopback or a management-only context.

An attacker who can route traffic to either port on an affected switch — no credentials, no user interaction, low attack complexity — can send specially crafted input directly to the S1HAL service. Successful exploitation executes arbitrary code with root privileges on the device. A failed or partial exploitation attempt can instead crash the S1HAL process, which forces the switch to reload, producing a denial-of-service condition that can disrupt an entire data-center fabric segment given the S1HAL process's role in ASIC packet-processing control. Because the exposed VRF is the switch's default (not a dedicated management-only VRF), any host with routed reachability to the device — including an attacker already positioned elsewhere inside the data-center fabric, not only a perimeter-facing attacker — can reach ports 43210/43211, making the flaw a lateral-movement/pivot risk within a compromised network as well as a direct initial-access risk. Root-level code execution on the NX-OS control plane also creates the technical precondition for an attacker to tamper with or replace the switch's system image to survive reboots, a pattern documented in prior real-world Cisco network-device implant incidents (e.g., SYNful Knock), though no such implant activity has been observed for CVE-2026-20212 specifically.

The vulnerability was identified by Cisco's Technical Assistance Center (TAC) during a customer support investigation rather than through external report, red-team finding, or in-the-wild detection. Cisco published advisory cisco-sa-n9k-s1-rce-EH8dEtr (version 1.0, final status) on 2026-09-02 alongside patched NX-OS releases. As of publication and as of this research (2026-09-03), Cisco PSIRT states it is not aware of any public proof-of-concept exploit code or malicious/exploitation activity involving CVE-2026-20212, and the CVE has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Because no public PoC exists, an attacker seeking to weaponize this CVE would need to independently develop an exploit from Cisco's own published advisory and/or by diffing the patched NX-OS 10.6(4) binaries against the vulnerable release line — i.e., the disclosure itself is currently the only public source of exploit-relevant capability information.

Only ten specific Silicon One-based Nexus 9000 product identifiers are affected: N9324C-SE1U, N9348Y2C6D-SE1U, N9364E-SG2-O, N9364E-SG2-Q, N9396T12C-SE1, N9348Y12C-SE1, N9396Y12C-SE1, N9336C-SE1, N9K-C9804, and N9K-C9808, running NX-OS releases from 10.3(1) through 10.6(3s) (45 releases in the vulnerable range per vendor coverage). Nexus 9000 switches operating in ACI mode, and the Nexus 3000/7000 product lines, are explicitly unaffected. Cisco directs administrators to the Cisco Software Checker to identify and apply the fixed NX-OS 10.6(4) release. Pending upgrade, Cisco recommends infrastructure access control lists (iACLs) denying inbound TCP 43210/43211 to the affected VRF, and — for switches specifically on NX-OS 10.6(3) or 10.6(3s) — offers a temporary "Live Protect Shield" (lp00031) that Cisco explicitly states does not replace patching.

Cisco's own commentary on this disclosure cycle is itself relevant context: Russ Smoak, Cisco's VP of Information Security, stated regarding the company's twice-monthly vulnerability disclosure cadence that "the window between disclosure and exploitation has effectively closed" — underscoring why Cisco frames rapid patch adoption for CVE-2026-20212 as urgent even absent current exploitation evidence. Separately, industry coverage of this disclosure has noted it lands amid a broader pattern of increased adversary interest in Cisco network infrastructure in mid-to-late 2026, including the China-linked Fire Ant group's custom IOS XR implants on Cisco routers reported in August 2026 and other actively exploited Cisco firewall CVEs the same month. None of that reporting ties any actor or campaign to CVE-2026-20212 itself — it is included here only as deployment-risk context, not as attribution.

## MITRE ATT&CK

- T1595.002 Active Scanning: Vulnerability Scanning
- T1595.001 Active Scanning: Scanning IP Blocks
- T1588.006 Obtain Capabilities: Vulnerabilities
- T1584.008 Compromise Infrastructure: Network Devices
- T1046 Network Service Discovery
- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1601.001 Modify System Image: Patch System Image
- T1499.004 Endpoint Denial of Service: Application or System Exploitation
- T1529 System Shutdown/Reboot
- T1562 Impair Defenses

## Sources

- [Cisco fixed critical RCE in Nexus 9000 Series Switches](https://securityaffairs.com/198366/security/cisco-fixed-critical-rce-in-nexus-9000-series-switches.html)
- [Cisco Security Advisory: Cisco Nexus 9000 Series Switches Silicon One RCE (cisco-sa-n9k-s1-rce-EH8dEtr)](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n9k-s1-rce-EH8dEtr)
- [NVD - CVE-2026-20212 Detail](https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-20212)
- [Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Execute Code](https://thehackernews.com/2026/09/critical-cisco-nexus-9000-flaw-lets.html)
- [CVE-2026-20212 - Rapid7 Vulnerability & Exploit Database](https://www.rapid7.com/db/vulnerabilities/cve-2026-20212/)
- [Cisco Nexus 9000 Series Switches Vulnerability Allows Remote Code Execution](https://cybersecuritynews.com/cisco-nexus-9000-series-switches-vulnerability/)
- [Critical Cisco Nexus 9000 Flaw Allows Remote Root Code Execution](https://www.esecurityplanet.com/news/news-cisco-nexus-9000-vulnerability/)
- [CVE-2026-20212: Binding to an Unrestricted IP Address in Cisco NX-OS Software](https://radar.offseq.com/threat/cve-2026-20212-binding-to-an-unrestricted-ip-address-in-cisco-cisco-nx-os-software-1519dc1b9d3b58c9)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2319
