Cisco Nexus 9000 CVE-2026-20212 is a Cisco-rated Critical vulnerability, but it does not affect every Nexus 9000 switch. Cisco limits the issue to a defined set of Silicon One-based Nexus 9000 product IDs, and administrators must also check the installed NX-OS release before deciding whether the device is actually in an affected software state.
Cisco says an unauthenticated remote attacker who can reach the affected service may be able to execute code with root privileges. Exploitation can also crash the S1HAL process and reload the device. Cisco PSIRT said it was not aware of public announcements or malicious use of CVE-2026-20212 at disclosure, so TPS does not describe this vulnerability as actively exploited.
Check your Cisco Nexus 9000 in four stages
1. Identify the switch PID
Confirm the exact product identifier and compare it with Cisco’s affected-model list. A Nexus 9000 family name by itself is not enough to establish exposure.
2. Check the installed NX-OS release
If the PID is listed, use Cisco’s current Software Checker or advisory guidance to determine whether the actual installed release is affected and which release first fixes the vulnerability for that platform.
3. Evaluate temporary mitigation only if needed
Cisco documents infrastructure ACL controls and Live Protect shielding in applicable environments. These are temporary exposure-reduction options and must be checked against the actual model and software combination.
4. Move to fixed software and verify
Full remediation requires the device to be on software Cisco identifies as fixed for the specific platform. A temporary mitigation is not the same as completing the software upgrade.

Which Cisco Nexus 9000 models are affected?
Cisco’s current advisory lists the following affected product IDs:
| Product ID | Current CVE-2026-20212 scope |
|---|---|
| N9324C-SE1U | Listed affected |
| N9348Y2C6D-SE1U | Listed affected |
| N9364E-SG2-O | Listed affected |
| N9364E-SG2-Q | Listed affected |
| N9396T12C-SE1 | Listed affected |
| N9348Y12C-SE1 | Listed affected |
| N9396Y12C-SE1 | Listed affected |
| N9336C-SE1 | Listed affected |
| N9K-C9804 | Listed affected |
| N9K-C9808 | Listed affected |
Cisco says Nexus 9000 models outside its listed affected products are not affected by this vulnerability. It also says Nexus 9000 Fabric Switches running in ACI mode and Cisco Nexus 3000 and 7000 Series switches are not affected.
How do you identify the affected hardware?
Administrators should verify the actual device PID rather than relying on the broad Nexus 9000 family name. Cisco documents the show module command as one way to identify module and product information on the device.
If the PID is not in Cisco’s current affected list, do not automatically apply the CVE-2026-20212 remediation path to that device. If it is listed, continue to the installed-software check.
What does CVE-2026-20212 allow?
Cisco describes CVE-2026-20212 as an unauthenticated remote-code-execution vulnerability involving services reachable on TCP ports 43210 and 43211 in the default L3 VRF. An attacker who can reach the affected service and successfully exploit the flaw may execute code with root privileges.
Cisco also states that exploitation can cause the S1HAL process to crash and the device to reload, creating a potential availability impact in addition to the code-execution risk.
Which NX-OS versions are vulnerable?
Do not use a single hard-coded NX-OS version from a third-party article as the universal answer. Cisco’s remediation path is platform and release specific.
For an affected PID, administrators should use Cisco’s current Software Checker to determine whether the installed NX-OS release is vulnerable and to identify the first fixed release for that specific platform and software branch.
Can an infrastructure ACL reduce exposure?
Cisco documents infrastructure ACL controls as a possible temporary mitigation. The purpose is to restrict access to the affected service where the deployment allows it.
This should not be treated as a universal copy-and-paste fix. Cisco warns that mitigation choices can affect network functionality or performance depending on the environment, so administrators should evaluate the effect of any ACL change before deployment.
What is Cisco Live Protect for this CVE?
Cisco has also published Live Protect shielding for CVE-2026-20212 on supported model and software combinations. Live Protect can provide temporary protection while a fixed NX-OS upgrade is scheduled.
Live Protect is not the permanent remediation. Cisco’s documentation treats the shield as a temporary measure. The complete remediation path remains upgrading to software that Cisco identifies as fixed.
Does the same Live Protect shield apply to every affected model?
No universal applicability is established by the reviewed evidence. Cisco’s Live Protect release notes are model and release specific. For example, one reviewed shield release identifies support for N9324C-SE1U and N9348Y2C6D-SE1U under that particular software context.
Administrators should therefore verify Live Protect support for the exact model and release instead of assuming one shield package covers every PID in the CVE advisory.
Is CVE-2026-20212 actively exploited?
Active exploitation is not established in the reviewed evidence. Cisco PSIRT said it was not aware of public announcements or malicious use of the vulnerability at disclosure.
A critical CVSS score and remote-code-execution capability do not by themselves prove that exploitation is occurring in the wild.
How do you verify full remediation?
Verification should return to the same two facts used to establish exposure: the device model and the installed software state.
- Confirm the switch PID.
- Confirm the currently installed NX-OS release.
- Re-check that combination against Cisco’s current Software Checker or advisory guidance.
- Verify that the deployed software is no longer identified as affected.
If an ACL or Live Protect shield was used temporarily, do not treat the presence of that mitigation alone as proof that the underlying vulnerable software has been removed.
Does updating prove the switch was never compromised?
No. A fixed software state establishes remediation of the known vulnerable software condition, but it does not by itself prove that no historical exploitation occurred before the upgrade.
TPS did not recover a complete authoritative CVE-2026-20212-specific indicator-of-compromise or forensic checklist from the reviewed Cisco and CERT-In evidence. This article therefore does not invent logs, attacker artifacts or compromise indicators.
Limitations & unresolved facts
- TPS cannot determine whether a particular organisation exposes the affected service to an attacker-reachable network path.
- The fixed NX-OS release is platform and release specific; TPS does not publish a fabricated universal version number.
- Active exploitation was not established in the reviewed evidence.
- CISA KEV status was not established from a controlling direct source during this research.
- Live Protect applicability varies by model and release.
- No complete authoritative CVE-specific IOC or forensic checklist was recovered.
Verification method
ThePulseSignal reviewed Cisco’s primary CVE-2026-20212 advisory, affected and unaffected product scope, Cisco Software Checker guidance, Live Protect documentation, CERT-In CIVN-2026-0436 and current independent security coverage. TPS kept temporary mitigation, fixed-software remediation and exploitation status separate.
Frequently asked questions
Is every Cisco Nexus 9000 affected by CVE-2026-20212?
No. Cisco limits the vulnerability to a defined list of Silicon One-based Nexus 9000 product IDs.
Are Nexus 9000 switches in ACI mode affected?
Cisco says Nexus 9000 Fabric Switches running in ACI mode are not affected by this vulnerability.
Which NX-OS release fixes CVE-2026-20212?
The correct fixed release depends on the actual platform and software branch. Use Cisco’s current Software Checker rather than assuming one universal fixed version.
Can Live Protect replace the NX-OS upgrade?
No. Cisco describes Live Protect as temporary protection while administrators schedule an upgrade to fixed software.
Is CVE-2026-20212 being actively exploited?
Cisco said it was not aware of malicious use at disclosure. TPS does not classify the vulnerability as actively exploited based on the reviewed evidence.



