Affected Systems
Cisco Silicon One-based Nexus 9000 switches (10 models, NX-OS 10.3(1) through 10.6(3s)) via CVE-2026-20212. All Cisco IOS XR releases across all platforms via 7 umbrella CVEs (CVE-2026-20274 through 20280), including XR7 (LNT) platforms: Cisco 8000 Series, NCS 1010, NCS 540L, NCS 5700 Series, ASR 9000 Series. Nexus 9000 in ACI mode, Nexus 3000/7000 unaffected.
Exploitation Status
No active exploitation reported as of September 2, 2026 disclosure. No public PoC available. Nexus flaw is easily exploitable (CVSS 9.8, unauthenticated remote access to exposed TCP ports). IOS XR vulnerabilities affect all releases with no workarounds available.
Business Impact
Nexus 9000: Unauthenticated remote attackers can execute arbitrary code as root by sending crafted input to TCP ports 43210 or 43211 exposed in default Layer 3 VRF. Failed exploitation attempts crash S1HAL process and reload device, causing service disruption. IOS XR: Multiple critical vulnerabilities (two rated CVSS 9.8) covering memory safety, access control, missing authentication, and improper certificate validation across all IOS XR versions. No workarounds exist; patching requires applying SMUs across approximately 16 releases per platform. Cisco's twice-monthly disclosure model compresses time-to-exploit window.
Urgency
🔴 Immediate
Recommended Actions
- Identify affected Nexus 9000 switches using 'show module' command and cross-reference against 10 PIDs listed in Cisco advisory (N9324C-SE1U, N9348Y2C6D-SE1U, N9364E-SG2-O, N9364E-SG2-Q, N9396T12C-SE1, N9348Y12C-SE1, N9396Y12C-SE1, N9336C-SE1, N9K-C9804, N9K-C9808)
- For Nexus 9000: Immediately deploy infrastructure ACL blocking TCP ports 43210 and 43211 to locally configured IP addresses, test in lab environment first; apply Live Protect shield lp00031 on NX-OS 10.6(3) or 10.6(3s) where supported (not available for Nexus 9804/9808)
- For Nexus 9000: Use Cisco Software Checker to identify fixed NX-OS release (10.6(4) or higher per shield release notes) and schedule upgrade; verify ACL effectiveness via packet capture before and after deployment
- For IOS XR: Identify platform and release, apply SMUs per advisory tables for releases 6.9.2 through 26.2.1; XR7 (LNT) platforms apply CSCwv19790 across all releases; open TAC case if running release not listed in advisory
- Monitor Cisco advisory updates for IOS XR fixed releases 26.2.2 and 26.3.1 (first releases not requiring SMUs); prioritize patching internet-facing and management-accessible devices within 48 hours
