Cisco discloses critical flaw letting attackers seize root on Nexus 9000 switches
A maximum-severity vulnerability in switches that anchor large data center networks arrived alongside a separate patch bundle for seven critical bugs in Cisco's core router software, all disclosed the same day.

Cisco disclosed a critical vulnerability this week that could let an unauthenticated attacker execute code with root privileges on Nexus 9000 Series switches, the workhorse hardware that anchors many large data center networks, while separately patching seven critical flaws in the IOS XR software that runs its core routers.
Both sets of advisories were published September 2 as part of Cisco's regular security advisory bundle, and the company's product security team says it has no evidence either issue has been exploited so far.
The numbers
The switch flaw, tracked as CVE-2026-20212, carries the maximum-severity CVSS score of 9.8. It affects roughly ten Nexus 9000 hardware models built around Cisco's Silicon One switching chips, including the modular N9K-C9804 and N9K-C9808 chassis. The problem stems from two TCP ports, 43210 and 43211, that are reachable on the default routing instance without authentication; an attacker who can reach either port can send crafted input that runs as code with full root access, or simply crash the switch's hardware-abstraction process and force a reload. Cisco and outside researchers both note the switch does not need to be exposed to the internet to be at risk — reachability from any compromised or less-trusted segment of an internal network is enough, which is why guidance for administrators includes running a simple hardware-inventory command to check whether their switches are on the affected list before assuming the flaw doesn't apply.
The router-software bundle is larger in scope. Cisco's IOS XR hardening advisory groups seven separate CVEs — ranging from 8.2 to 9.8 on the CVSS scale and covering distinct weaknesses such as improper access control, unsafe resource handling and faulty exception handling — across the operating system that runs Cisco's 8000 Series routers, NCS 540L and NCS 5700 platforms, and several optical NCS product lines. Cisco says the bugs touch all 111 currently supported IOS XR releases; fixes exist for only 14 of those today, four more are pending, and the remaining 93 require customers to first upgrade to a newer release before a patch can even be applied.
How Cisco got here
Cisco found both sets of bugs itself, not through outside researchers. The Nexus flaw surfaced while engineers were resolving a customer support case, and the IOS XR bundle came out of what the company calls an internal hardening review — one that, according to a post from Russ Smoak, Cisco's vice president of information security, now leans on "frontier AI models and agentic analysis harnesses" combing through the company's code alongside traditional testing. That AI-assisted scrutiny is turning up bugs faster than the old case-by-case patch cycle could handle, which is why Cisco moved in July to bundling internally found issues into twice-monthly release windows, published the first and third Wednesday of every month, rather than disclosing them piecemeal as they're found.
"The window between disclosure and exploitation has effectively closed," Smoak wrote, explaining the shift to a more predictable, batched release schedule.
Who is affected
Nexus 9000 switches sit at the center of enterprise and service-provider data centers, often carrying the traffic between servers inside a cloud or colocation environment, so a successful exploit there could give an attacker a foothold deep inside a network rather than just at its edge. IOS XR, meanwhile, runs on service-provider and carrier-grade routers, including Cisco's 8000 Series and the optical NCS product lines, that make routing decisions for internet backbones and large enterprise wide-area networks. Neither platform is aimed at home or small-office users; the customers most exposed are telecom carriers, cloud and colocation providers, and large enterprises running their own data centers, the operators for whom a single compromised switch or router can ripple across thousands of downstream connections.
The stakes around that class of hardware were underlined last month, when researchers at Sygnia disclosed that a China-linked hacking group it calls Fire Ant had been quietly living inside Cisco IOS XR routers, deploying custom implants that suppressed log output and altered command results to hide its activity while it harvested credentials and explored connected networks. That campaign did not rely on this week's newly disclosed flaws, but it illustrated why security teams treat router and switch compromises as more than a routine patching chore: a device that controls network traffic can also be used to hide the evidence of an intrusion.
What happens next
Cisco is urging customers to move to fixed NX-OS and IOS XR software as their primary remedy, and has published its Software Checker tool so network teams can identify which release applies to their hardware. Where an immediate upgrade isn't practical, the company is recommending infrastructure access control lists that block outside traffic to the vulnerable Nexus ports, and it released a temporary "Live Protect" shield meant to blunt exploitation attempts while patches are scheduled. For the IOS XR bundle, Cisco says two upcoming software releases, 26.2.2 and 26.3.1, will be the first versions with the fixes built in rather than requiring a separately applied patch, meaning many affected networks will still be running an interim workaround for some time yet.
Cisco's own security team has been explicit that its new batching approach is meant to make disclosures more predictable, not to make them less urgent. Smoak's post frames the shift as an acknowledgment that AI-accelerated code review has permanently changed the math: vulnerabilities that might once have sat undiscovered for years are now being found in bulk, internally, before any outside researcher or attacker gets there first — which Cisco argues is the safer outcome, provided customers actually apply the resulting patches on a predictable cadence rather than letting advisories pile up.
Neither advisory reports exploitation in the wild as of publication, and Cisco's PSIRT said the same in both bundles. But with root-level access on the line for switches that see no authentication requirement at all, and a router-software bundle spanning nearly every supported release, network security teams have been told to treat both as priorities rather than routine maintenance.

Adobe names Anil Chakravarthy CEO, ending Shantanu Narayen's 18-year run

Apple, OpenAI clash over new evidence in trade-secrets lawsuit as October hearing looms

Texas Freezes New Data Center Grid Connections Over 'Ghost Demand'
