Cisco Releases Security Updates for Cisco NX-OS Software
Successful exploitation of CVE-2026-20212 could allow an remote, unauthenticated attacker to execute arbitrary code with root privileges
Summary
Successful exploitation of CVE-2026-20212 could allow an remote, unauthenticated attacker to execute arbitrary code with root privileges
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Cisco has released a security advisory to address a critical vulnerability in Cisco NX-OS Software impacting Silicon One integration for Cisco Nexus 9000 Series Switches.
- CVE-2026-20212 - 'Binding to an Unrestricted IP Address' vulnerability CVSSv3.1 Score: 9.8.
Remediation advice
Affected organisations are encouraged to review Cisco advisory cisco-sa-n9k-s1-rce-EH8dEtr and apply the relevant update as soon as possible.
Organisations are encouraged to use the Cisco Software Checker tool to determine the latest available version for their deployment.
Definitive source of threat updates
Last edited: 3 September 2026 2:58 pm