Cisco disclosed a critical flaw in Nexus 9000 switches on September 2, 2026, that lets unauthenticated attackers execute code as root over two exposed TCP ports. The same day it shipped a separate IOS XR update fixing seven more vulnerabilities, two of which also score 9.8 out of 10.

Read the full story: Cisco Nexus 9000 Flaw Lets Hackers Run Code as Root →

Transcript

Cisco just disclosed a flaw that lets an attacker with zero credentials run code as root on your data center switches. CVE-2026-20212, a nine point eight out of ten, hits ten Nexus 9000 switch models. The bug is blunt: a service binds to an unrestricted IP address, leaving two ports wide open. Send the right crafted packet, and you own the box as root. The same day, Cisco quietly shipped seven more fixes for IOS XR, the software running its carrier routers. Two of those also score nine point eight. All one hundred eleven supported releases are affected, and ninety three of them cannot even get a direct patch, they need a full version upgrade first. Nexus 9000 and IOS XR sit at the center of the internet's plumbing. Patch now, or block the ports.