US Edition
Your source for latest news
TechnologyCybersecurity

Cisco fixes critical flaw letting attackers seize root control of switches that anchor AI data centers

A newly disclosed Cisco vulnerability allows unauthenticated attackers to run code as root on Nexus 9000 switches widely used in AI data center networks, one of three critical flaws the company found during an internal security review.

PT
By PressTemps Technology DeskPublished Today, 01:40 ET · 6 min read
Cisco fixes critical flaw letting attackers seize root control of switches that anchor AI data centers
Cisco Systems headquarters, Building 10, San Jose, California. Photo: Travis Wise / Wikimedia Commons, CC BY 2.0
What to know
Cisco disclosed three critical (CVSS 9.8) vulnerabilities on September 2, 2026, found during an internal security review of its networking software.
CVE-2026-20212 lets an unauthenticated attacker run code as root on ten Nexus 9000 Silicon One switch models, hardware widely used as the network backbone of AI data centers.
Two additional critical flaws affect all releases of Cisco IOS XR router software, including carrier-grade 8000 Series, NCS 540L and NCS 5700 platforms, with no available workaround.
Cisco says it has no evidence any of the three flaws have been exploited, and has published patches, an online Software Checker, and interim mitigations including access-control-list blocks.

Cisco disclosed three critical security flaws on September 2, discovered during an internal review of its networking software, including a bug that lets an unauthenticated attacker seize root-level control of switches that anchor some of the largest artificial intelligence data centers now under construction. The company has released fixes and interim mitigations, and says it has no evidence any of the flaws have been exploited.

The most severe of the three, tracked as CVE-2026-20212 in Cisco's own security advisory, affects Nexus 9000 Series switches built with Cisco's Silicon One chips. Two more, found in Cisco's IOS XR router software, round out a trio the company rated 9.8 out of a possible 10 on the industry's standard severity scale.

Three flaws, one severity ceiling

The Nexus 9000 bug stems from a networking service that binds to an unrestricted IP address, leaving TCP ports 43210 and 43211 reachable on any switch connected to a network's default routing instance. Cisco's advisory states plainly what that exposure means.

"A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges."

An attacker who can reach one of the exposed ports needs no password and no user to click anything; crafted network traffic alone is enough to run arbitrary code with the highest level of system access, or to crash the switch's hardware-abstraction process and force it to reload. Ten Silicon One-based Nexus 9000 models are affected, including the N9324C-SE1U, the N9364E-SG2 series and the modular N9K-C9804 and N9K-C9808 chassis, according to the advisory and confirmed in independent write-ups by The Hacker News and SecurityAffairs. Cisco's own Technical Assistance Center found the bug while investigating a customer support case, not through a bug bounty or outside researcher.

The other two critical flaws, detailed in a separate IOS XR hardening advisory, are grouped with five high-severity issues that Cisco says its IOS XR engineering team turned up during the same internal audit. One critical bug involves memory-safety errors such as buffer overflows and use-after-free conditions; the other covers access-control failures, including missing authentication checks and improper certificate validation. Cisco says the flaws affect every release of IOS XR software, "regardless of device configuration," on carrier-grade hardware including the 8000 Series routers and the NCS 540L and NCS 5700 platforms.

Why a switch matters as much as a chip

The Nexus 9000 line is not an obscure product. Built around Cisco's Silicon One application-specific chips, it is one of the switch families most commonly deployed as the spine-and-leaf fabric inside hyperscale data centers, where it carries the remote-direct-memory-access traffic that lets thousands of graphics processors in a single cluster act as one machine during AI model training. Networking-industry coverage of the disclosure, including analysis picked up by Yahoo's technology desk, has focused on that role: a switch sitting at the center of a GPU cluster's network fabric is a single point that, if compromised, could expose or disrupt an entire training run rather than one server.

That context does not mean the bug has been used to attack anyone. Cisco's advisory states it is not aware of any public reports or malicious exploitation of either the Nexus 9000 flaw or the two IOS XR vulnerabilities as of the September 2 disclosure. The vulnerability record is also listed in the National Vulnerability Database maintained by the National Institute of Standards and Technology, the federal government's public catalog of software flaws, giving network defenders a standardized reference to track the fix across vendor tools.

Who has to act, and how fast

The burden falls on network and data-center operators running the affected gear rather than on end users, who will not interact with the flaws directly. For the Nexus 9000 issue, Cisco has published fixed software — NX-OS release 10.6(4) or later resolves it — and points customers to its online Software Checker tool to find the specific patched build for their device. Administrators who cannot patch immediately have two stopgaps: infrastructure access-control lists that block inbound traffic to ports 43210 and 43211, and a temporary "Live Protect" shield Cisco issued for devices still running older code.

The IOS XR flaws offer no such workaround. Cisco says operators must either upgrade to a fixed release or apply one of roughly sixteen Security Maintenance Updates issued per affected release train — a heavier lift for carriers and large enterprises that run IOS XR on core and edge routers and typically test software changes carefully before touching production routing infrastructure.

None of the three vulnerabilities requires a user to be tricked into clicking a link or opening a file, which is what pushed each rating to the top of the severity scale. Security researchers covering the disclosure, including write-ups syndicated through Forkast News, have noted that the absence of a public exploit does not lower the urgency, since the vulnerable ports and the technical mechanism are now public knowledge that any attacker can act on.

What happens next

Cisco routinely issues clusters of advisories tied to internal reviews of its flagship software lines, and the company frames this batch as part of an ongoing, proactive audit rather than a response to an active breach. The immediate test will be how quickly data-center operators and telecommunications carriers apply the fixes or the interim mitigations, given how often large infrastructure changes are scheduled around maintenance windows rather than made overnight. Cisco has not said whether it will extend the same review to other Silicon One-based product lines, and independent researchers are likely to continue probing the disclosed flaws now that the technical details are public.

More on this story

All Technology