Newsletter Subscribe
Enter your email address below and subscribe to our newsletter
[forminator_form id="25163"]

theroboticsmedia+1bleepingcomputerthehackernews+1Cisco disclosed a critical vulnerability on September 2, 2026, affecting its Nexus 9000 Series switches equipped with Silicon One ASICs, a flaw that could allow unauthenticated attackers to execute code with root privileges on hardware that underpins many of the world's largest AI data center networks. The disclosure landed alongside a separate IOS XR security-hardening release and days after cybersecurity firm Sygnia revealed that a China-linked espionage group had been hiding inside Cisco routers to steal credentials and spy on traffic.
Tracked as CVE-2026-20212, the vulnerability carries a CVSS score of 9.8 out of 10. It stems from TCP ports 43210 and 43211 being reachable through the default Layer 3 virtual routing and forwarding instance on affected switches. An attacker with network access can send crafted input to those ports and gain root-level execution, or crash the S1HAL process and force a device reload.theroboticsmedia+3
Ten Nexus 9000 models are affected, including the N9K-C9804 and N9K-C9808 modular platforms. Nexus 9000 switches operating in ACI mode, along with Nexus 3000, Nexus 7000, and several other product families, are confirmed unaffected. Cisco said the flaw was found during a Technical Assistance Center support case rather than through active exploitation, and PSIRT reported no known malicious use as of disclosure. The company released fixed NX-OS software and recommended infrastructure ACLs blocking the two ports as an interim mitigation.cyberpress+3
On the same day, Cisco published a separate IOS XR security-hardening release addressing seven groups of vulnerabilities, two of which also carry a 9.8 CVSS score.thehackernews+1
Days before Cisco's advisories, Sygnia published research detailing how a China-linked group it tracks as Fire Ant had compromised Cisco IOS XR routers and used them to intercept traffic, steal administrator credentials, and probe critical infrastructure networks. Investigators discovered an unexplained GRE tunnel on a router that the device's configuration records could not account for, prompting a deeper investigation.bleepingcomputer+1
Fire Ant deployed custom malware on the routers, selectively suppressed syslog messages to hide from administrators, and captured network traffic that was uploaded to external servers. The group also compromised TACACS authentication servers using a previously undocumented tool called TacTap to harvest credentials as administrators logged in. A second backdoor, BridgeAgent, was disguised as a Zabbix monitoring agent and provided persistent root-level access.cybersecuritydive+1
"Fire Ant collected network traffic and administrative credentials, mapped routes and trusted relationships, established multiple persistent access mechanisms and manipulated evidence to reduce the likelihood of detection," Asaf Perlman, director of incident response at Sygnia, told Cybersecurity Dive.cybersecuritydive
The twin disclosures highlight a broadening attack surface for organizations running AI workloads. The Nexus 9000 Silicon One switches serve as backbone infrastructure for GPU-to-GPU traffic in large-scale AI training clusters. Root-level compromise of such hardware could allow an attacker to intercept or manipulate data moving between GPUs, bypassing protections implemented at the software layer.forkast
Sygnia's research described Fire Ant's approach as pursuing a "target behind the target" — first seizing control of trusted network equipment and then using it as a bridge into connected high-value environments. Cisco's IOS XR advisory does not reference Fire Ant or Sygnia's findings, and Sygnia did not identify a specific Cisco vulnerability used in the intrusions.ntd+2