Cisco patches critical Nexus 9000 bug that lets attackers run code as root
A flaw tracked as CVE-2026-20212 scores 9.8 out of 10. Cisco also shipped a bundled fix for seven separate IOS XR bugs, two of them equally severe, with no workaround available.

Key points
- Cisco has patched a critical flaw, tracked as CVE-2026-20212, in 10 of its Silicon One-based Nexus 9000 data centre switches.
- The bug scores 9.8 out of 10 on the industry severity scale and lets a remote attacker run commands as the top-level "root" user without logging in.
- A separate IOS XR hardening release fixes seven CVEs at once, two of them also rated 9.8, and Cisco says there is no workaround for any affected IOS XR version.
- Customers running the affected switches or routers need to install the updates; there is no configuration change that blunts the risk.
Cisco has shipped fixes for a critical vulnerability in its Nexus 9000 switches, the kind of hardware that quietly runs the networks inside large offices, hospitals and cloud data centres. If exploited, the bug hands a remote attacker complete control of the device without needing a password.
The flaw is tracked as CVE-2026-20212 and carries a severity score of 9.8 out of 10. In plain terms, that score is reserved for bugs that are easy to exploit over the network and give attackers the keys to the whole machine.
At the same time, Cisco released a hardening update for its IOS XR software, the operating system that powers many of its carrier-grade routers. That single release rolls up seven separate CVEs, or Common Vulnerabilities and Exposures (the industry's way of numbering security bugs), and two of them also score 9.8. Cisco says no workaround exists for any affected IOS XR version, so patching is the only option.
The reporting was first surfaced by The Hacker News.
What is actually vulnerable?
The Nexus bug affects 10 models in Cisco's Silicon One-based Nexus 9000 line, which are high-end switches used to move traffic inside data centres. An attacker who can reach the switch over the network can send it a crafted request and run code as "root", the most privileged account on the device.
Once an attacker has root, they can read any traffic passing through, redirect it, or use the switch as a quiet foothold to reach the servers behind it. For a hospital or a bank, that means the machine that carries every internal connection is under someone else's control.
The IOS XR bundle is different in shape but similar in stakes. It packages seven bugs into one hardening release so administrators fix them in a single maintenance window rather than seven.
| Item | Detail |
|---|---|
| Nexus CVE | CVE-2026-20212 |
| Nexus CVSS | 9.8 |
| Affected Nexus models | 10 Silicon One-based Nexus 9000 switches |
| IOS XR CVEs in release | 7 |
| IOS XR critical count | 2 rated 9.8 |
| Workaround | None for IOS XR |
Is this being exploited yet?
Cisco has not said the bugs are being used in live attacks. That distinction matters. A 9.8 score describes capability, meaning what an attacker could do if they wrote a working exploit, not intent, meaning whether anyone has actually done it yet.
Critical Cisco flaws tend to draw fast attention from both security researchers and, on a longer tail, from state-linked intrusion crews. Groups that historically prospect edge network gear, including clusters Cisco Talos tracks under names like Static Tundra, have a track record of holding on to router and switch access for months. That is a pattern, not an attribution for this bug.
What should network teams do now?
Install the fixed software. For the Nexus 9000 switches, apply the release Cisco has flagged as containing the fix for CVE-2026-20212. For IOS XR, apply the hardening release that rolls up the seven CVEs; because Cisco explicitly notes no workaround, filtering or access lists will not save you.
If you run this hardware, treat the patch window as urgent rather than routine. And check switch logs for unfamiliar administrative sessions before and after the update, in case someone was already inside.



