SB2026090282 - Remote code execution in Cisco Nexus 9000 Series Switches Silicon One



SB2026090282 - Remote code execution in Cisco Nexus 9000 Series Switches Silicon One

Published: September 2, 2026

Security Bulletin ID SB2026090282
CSH Severity
Critical
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Critical 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Binding to an Unrestricted IP Address (CVE-ID: CVE-2026-20212)

CWE-ID: CWE-1327 - Binding to an Unrestricted IP Address

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to exposed network services in the Silicon One integration when connecting to TCP ports 43210 or 43211 in the default Layer 3 virtual routing and forwarding instance. A remote attacker can send crafted input to execute arbitrary code.

Successful exploitation may execute code with root privileges or cause the S1HAL process to crash, which could cause the device to reload.


Remediation

Install update from vendor's website.