DIRAS TAKE
Treat this as urgent: public exploit code exists for an unauthenticated, root-impact flaw in an internet-facing component, so immediately limit access to TCP ports 43210/43211 and follow vendor guidance.
What is CVE-2026-20212?
An unauthenticated remote attacker can execute code as root on Cisco NX-OS devices running the Silicon One integration by connecting to exposed TCP ports 43210 or 43211. CVE-2026-20212 affects multiple 10.x NX-OS releases, including listed builds such as 10.3(1), 10.3(2), 10.3(3), 10.4(1), 10.3(4) and several 10.3 series variants. The attacker only needs network access to those ports in the device's default Layer 3 VRF to send crafted input that may be executed or crash the S1HAL process, possibly causing a reload.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Cisco Cisco NX-OS Software are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 10.x | 10.3(1) | |
| 10.x | 10.3(2) | |
| 10.x | 10.3(3) | |
| 10.x | 10.4(1) | |
| 10.x | 10.3(99w) | |
| 10.x | 10.3(3w) | |
| 10.x | 10.3(99x) | |
| 10.x | 10.3(3o) | |
| 10.x | 10.3(4) | |
| 10.x | 10.3(3p) |
Is CVE-2026-20212 being exploited?
Public exploit code is available.
How to fix CVE-2026-20212
- Restrict access to TCP ports 43210 and 43211 in the default L3 VRF from untrusted networks (ACLs or firewall).
- Isolate affected devices from public networks and management from untrusted segments until a vendor fix is applied.
- Monitor device logs and the S1HAL process for crashes or unexpected reloads and investigate any suspicious connections to 43210/43211.
- Follow Cisco communications and apply vendor patches or updates as soon as fixed releases are published.
Frequently asked questions
Is CVE-2026-20212 being actively exploited?
Public exploit code is available for CVE-2026-20212.
Which Cisco NX-OS Software versions are affected by CVE-2026-20212?
Cisco NX-OS Software 10.x releases are affected; the advisory lists specific builds including 10.3(1), 10.3(2), 10.3(3), 10.4(1), 10.3(4) and several 10.3-series variants.
Is there a patch for CVE-2026-20212?
No fixed releases are listed for the affected NX-OS builds in the provided data; follow Cisco guidance for mitigations and patch when vendor fixes are released.
Does CVE-2026-20212 require authentication?
No—CVE-2026-20212 can be exploited by an unauthenticated remote attacker who can reach TCP ports 43210 or 43211 on the device.
References
- nvd.nist.gov/vuln/detail/CVE-2026-20212
- cve.org/CVERecord?id=CVE-2026-20212
- sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n9k-s1-rce-EH8dEtr
- All Cisco CVEs on CVE Radar
- CVEs published in September 2026