Home / Sep 04, 2026 / Story
0
#2 The Hacker News general September 03, 2026 at 15:52 UTC

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

By [email protected] (The Hacker News)

AI Summary

Cisco patched CVE-2026-20212 (CVSS 9.8), a critical unauthenticated RCE flaw in 10 Silicon One-based Nexus 9000 switches, alongside an IOS XR hardening release covering 7 CVEs — two rated 9.8 — with no available workaround for any IOS XR version. The Nexus vulnerability allows a remote attacker to execute arbitrary code as root without authentication. Network defenders running affected Nexus 9000 or IOS XR gear should apply patches immediately given the CVSS scores and lack of mitigations.

Relevance score: 91.0/100

# More from September 04