CVE-2026-20212
published 2026-09-02CVE-2026-20212: A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root…
PriorityP271critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.53%
43.0th percentile
A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges.
This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device and send crafted input that could be executed as code with root privileges. The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload.
Affected
45 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
| cisco | cisco_nx-os_software | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges.
ghsa_unreviewed·2026-09-02
CVE-2026-20212 [CRITICAL] CWE-1327 A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges.
A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges.
This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device and send crafted input that could be executed as code with root privileges. The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload.
VulDB
Cisco NX-OS Software up to 10.6(3s) Silicon One integration privileges management (EUVD-2026-70201)
vuldb·2026-09-02·CVSS 9.8
CVE-2026-20212 [CRITICAL] Cisco NX-OS Software up to 10.6(3s) Silicon One integration privileges management (EUVD-2026-70201)
A vulnerability marked as very critical has been reported in Cisco NX-OS Software. This affects an unknown function of the component Silicon One integration. Performing a manipulation results in improper privilege management.
This vulnerability is identified as CVE-2026-20212. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
Suricata
ET WEB_SPECIFIC_APPS FLIR file Parameter Arbitrary File Read Attempt (CVE-2017-20212)
suricata·2026-01-08·CVSS 8.7
CVE-2017-20212 [HIGH] ET WEB_SPECIFIC_APPS FLIR file Parameter Arbitrary File Read Attempt (CVE-2017-20212)
ET WEB_SPECIFIC_APPS FLIR file Parameter Arbitrary File Read Attempt (CVE-2017-20212)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS FLIR file Parameter Arbitrary File Read Attempt (CVE-2017-20212)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/api/xml?file=/"; startswith; fast_pattern; reference:url,www.zeroscience.mk/codes/flir_info.txt; reference:cve,2017-20212; classtype:attempted-admin; sid:2066628; rev:1; metadata:affected_product FLIR, attack_target Networking_Equipment, tls_state plaintext, created_at 2026_01_08, cve CVE_2017_20212, deployment Perimeter, deployment Internal, performance_impact Low, confidence High, signature_severity Major, tag Exploit, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2026_01_08, mitre_
No public exploits indexed.
Hackernews
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
blogs_hackernews·2026-09-07·CVSS 6.9
CVE-2026-86206 [MEDIUM] ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on.
Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management gave outsiders useful clues before login. Add active attacks on browsers, routers, and online stores, and there’s plenty to check—even for teams that have k
Hackernews
Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
blogs_hackernews·2026-09-03·CVSS 9.8
CVE-2026-20212 [CRITICAL] Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version.
The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), is a case of binding to an unrestricted IP address that leaves TCP ports 43210 and 43211 reachable in the default Layer 3 virtual routing and forwardin
2026-09-02
Published