• PoC PUBLIC

CVE-2026-20212: pre-auth remote code execution in Cisco Cisco NX-OS Software

An unauthenticated remote attacker can execute code as root on Cisco NX-OS devices running the Silicon One integration by connecting to exposed TCP ports 43210 or 43211. CVE-2026-20212 affects multiple 10.x NX-OS releases, including listed builds such as 10.3(1), 10.3(2), 10.3(3), 10.4(1), 10.3(4) and several 10.3 series variants. The attacker only needs network access to those ports in the device's default Layer 3 VRF to send crafted input that may be executed or crash the S1HAL process, possibly causing a reload.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00721
CWE
CWE-1327
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Treat this as urgent: public exploit code exists for an unauthenticated, root-impact flaw in an internet-facing component, so immediately limit access to TCP ports 43210/43211 and follow vendor guidance.

What is CVE-2026-20212?

An unauthenticated remote attacker can execute code as root on Cisco NX-OS devices running the Silicon One integration by connecting to exposed TCP ports 43210 or 43211. CVE-2026-20212 affects multiple 10.x NX-OS releases, including listed builds such as 10.3(1), 10.3(2), 10.3(3), 10.4(1), 10.3(4) and several 10.3 series variants. The attacker only needs network access to those ports in the device's default Layer 3 VRF to send crafted input that may be executed or crash the S1HAL process, possibly causing a reload.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Cisco Cisco NX-OS Software are affected?

BRANCHAFFECTEDFIXED
10.x10.3(1)
10.x10.3(2)
10.x10.3(3)
10.x10.4(1)
10.x10.3(99w)
10.x10.3(3w)
10.x10.3(99x)
10.x10.3(3o)
10.x10.3(4)
10.x10.3(3p)

Is CVE-2026-20212 being exploited?

Public exploit code is available.

How to fix CVE-2026-20212

  1. Restrict access to TCP ports 43210 and 43211 in the default L3 VRF from untrusted networks (ACLs or firewall).
  2. Isolate affected devices from public networks and management from untrusted segments until a vendor fix is applied.
  3. Monitor device logs and the S1HAL process for crashes or unexpected reloads and investigate any suspicious connections to 43210/43211.
  4. Follow Cisco communications and apply vendor patches or updates as soon as fixed releases are published.

Frequently asked questions

Is CVE-2026-20212 being actively exploited?

Public exploit code is available for CVE-2026-20212.

Which Cisco NX-OS Software versions are affected by CVE-2026-20212?

Cisco NX-OS Software 10.x releases are affected; the advisory lists specific builds including 10.3(1), 10.3(2), 10.3(3), 10.4(1), 10.3(4) and several 10.3-series variants.

Is there a patch for CVE-2026-20212?

No fixed releases are listed for the affected NX-OS builds in the provided data; follow Cisco guidance for mitigations and patch when vendor fixes are released.

Does CVE-2026-20212 require authentication?

No—CVE-2026-20212 can be exploited by an unauthenticated remote attacker who can reach TCP ports 43210 or 43211 on the device.

References