← Back to overview

Cisco has released patches for a critical vulnerability (CVE-2026-20212, CVSS 9.8) affecting 10 Silicon One-based Nexus 9000 switches. The flaw allows unauthenticated remote attackers to execute arbitrary code as root. Additionally, Cisco released an IOS XR hardening update bundling 7 umbrella CVEs, two of which are rated 9.8. No workarounds exist for any IOS XR version, making patching the only remediation. The severity and unauthenticated nature of the exploit make this a high-priority issue for network administrators running affected Cisco hardware.

Affected products

  • Cisco IOS XR
  • Cisco Nexus 9000
  • Cisco Silicon One

Related CVE's

  • CVE-2026-20212

Categories

  • Critical Infrastructure
  • Network Infrastructure
  • Zero-Day Vulnerabilities