Cisco discloses critical flaw in Nexus 9000 switches used in AI data centers

17 sources
  • Cisco on Sept. 2 disclosed CVE-2026-20212, a remote code execution flaw in 10 Nexus 9000 switch models that exposes TCP ports to unauthenticated root access.
  • The disclosure came days after Sygnia revealed a China-linked group called Fire Ant had been hiding inside Cisco routers to intercept traffic and steal credentials.
  • Cisco released fixed NX-OS software and recommends blocking TCP ports 43210 and 43211 as an interim mitigation; no exploitation in the wild has been confirmed.
Sources (17)
  1. 1 Cisco Nexus 9000 Silicon One CVE-2026-20212 Critical RCE theroboticsmedia.com
  2. 2 Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Attackers ... cyberpress.org
  3. 3 Chinese Fire Ant hackers turn Cisco routers into spying ... www.bleepingcomputer.com
  4. 4 Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote ... thehackernews.com
  5. 5 Cisco Nexus 9000 Series Switches Vulnerability Allows Remote ... cybersecuritynews.com
  6. 6 Cisco Advance Notification for Publication of September 2 ... sec.cloudapps.cisco.com
  7. 7 State-linked actor targets Cisco routers for espionage www.cybersecuritydive.com
  8. 8 Cisco Nexus 9000 Silicon One RCE Exposes AI Data Center Fabric to Root Compromise forkast.news
  9. 9 China-Linked Hackers Hid in Cisco Routers, Stole Administrator Credentials: Report www.ntd.com
  10. 10 Cisco Patches High-Severity IOS XR Vulnerabilities - SecurityWeek www.securityweek.com
  11. 11 China's 'Fire Ant' campaign used compromised Cisco ... therecord.media
  12. 12 CVE-2026-20118: Cisco IOS XR Software DoS Vulnerability www.sentinelone.com
  13. 13 Cisco Event Responses sec.cloudapps.cisco.com
  14. 14 China State-Sponsored Hackers Turn Cisco Routers Into ... www.linkedin.com
  15. 15 Alert: Cisco Security Updates - November 2025 cyber.gov.rw
  16. 16 China-linked hackers turn Cisco routers into covert attack ... www.csoonline.com
  17. 17 Cisco IOS XR Software - Support www.cisco.com