Cisco has released fixes for critical vulnerabilities in Nexus 9000 switches and IOS XR software, including flaws rated 9.8 out of 10 that can lead to root-level remote code execution or improper access control. A separate Secure Email advisory warns that two publicly disclosed S/MIME weaknesses can expose plaintext from encrypted messages.
The advisories were published on September 2 as part of Cisco’s scheduled security release. The most immediately actionable issue for data-center operators is CVE-2026-20212, a critical vulnerability affecting specific Nexus 9000 Series switches equipped with Silicon One ASICs.
Cisco said it is not aware of malicious exploitation of the Nexus, IOS XR or Secure Email vulnerabilities. The company has nevertheless advised customers to move to fixed software, while operators unable to patch the Nexus flaw immediately have temporary mitigation options.
Nexus 9000 Flaw Can Give Attackers Root Access
CVE-2026-20212 affects Cisco Nexus 9000 Series switches that contain a Silicon One ASIC. Cisco said TCP ports 43210 and 43211 are accessible through the default Layer 3 virtual routing and forwarding instance on affected devices.
An unauthenticated remote attacker able to reach those ports could send crafted input and execute code with root privileges. Exploitation can also crash the S1HAL process and force the switch to reload.
Cisco lists ten affected Nexus 9000 product identifiers, including N9324C-SE1U, N9348Y2C6D-SE1U, N9336C-SE1, N9396T12C-SE1, N9348Y12C-SE1, N9396Y12C-SE1, N9364E-SG2-O, N9364E-SG2-Q, N9K-C9804 and N9K-C9808.
The company has released software updates for the flaw. As a temporary measure, Cisco says infrastructure access control lists can be used to block TCP traffic to ports 43210 and 43211 on locally configured addresses unless that traffic is explicitly required. Cisco has also released a Live Protect shield for CVE-2026-20212.
Those mitigations are not a substitute for patching. Cisco says operators should upgrade to a fixed NX-OS release to fully remediate the issue.
All IOS XR Releases Are Affected by New Hardening Advisory
Cisco’s second critical advisory is broader. Its September IOS XR hardening release addresses multiple internally discovered flaws grouped under seven CVE identifiers: CVE-2026-20274 through CVE-2026-20280.
Two vulnerability classes reach a maximum CVSS score of 9.8. CVE-2026-20274 covers resource-lifetime and memory-safety issues, including buffer overflows, out-of-bounds access and use-after-free conditions. CVE-2026-20279 covers improper access-control weaknesses, including missing authentication or authorization and improper certificate validation.
Cisco says the vulnerabilities affect all releases of IOS XR Software, including IOS XR7, regardless of device configuration. They were found during Cisco’s internal testing and are not known to be actively exploited.
There are no workarounds for the IOS XR issues. Cisco has made Software Maintenance Upgrades available for a number of supported release trains, while some other fixes remain scheduled for future releases. The company says IOS XR 26.2.2 and 26.3.1 will be the first future releases to incorporate the fixes without requiring the advisory’s SMUs.
| Issue | Affected infrastructure | Severity | Operator action |
|---|---|---|---|
| CVE-2026-20212 | Nexus 9000 switches with listed Silicon One ASIC platforms | Critical, 9.8 | Upgrade; iACL or Live Protect shield can provide temporary mitigation |
| CVE-2026-20274 to CVE-2026-20280 | All Cisco IOS XR releases | Up to 9.8 | Install fixed releases and applicable SMUs; no workaround |
| CVE-2026-20354 and CVE-2026-20355 | Secure Email with AsyncOS 16.5.0 or earlier and S/MIME gateway communication enabled | Medium, 5.9 | Review Cisco fixed-release information; no workaround |
Secure Email Bugs Can Expose Encrypted Messages
The same disclosure cycle also included CVE-2026-20354 and CVE-2026-20355, two medium-severity vulnerabilities in Cisco Secure Email’s S/MIME decryption functionality.
The flaws result from insufficient validation of message integrity. Cisco says an unauthenticated attacker capable of intercepting and modifying traffic between email gateways could use a machine-in-the-middle attack to recover plaintext from encrypted communications.
Affected systems are Cisco Secure Email devices running AsyncOS 16.5.0 or earlier when S/MIME is configured for communication between email gateways. Cisco assigns the vulnerabilities a CVSS score of 5.9 and says no workaround is available.
The Secure Email flaws differ from the switch vulnerabilities in one important respect: Cisco says a public announcement about the S/MIME weaknesses already exists. However, PSIRT said it was not aware of malicious exploitation when the advisory was published.
Why It Matters for Infrastructure
The Nexus issue is the highest-priority data-center exposure in the release because successful remote exploitation can provide root-level execution on an affected switch without authentication. Compromise or forced reloads at the switching layer can have consequences beyond a single server or application workload.
The IOS XR advisory has a different operational challenge: its scope covers every IOS XR release, making inventory and patch planning important for operators running the software across routing infrastructure. With no workaround available, Cisco’s SMUs and fixed releases are the remediation path.
For Secure Email, the severity score is lower, but environments that use S/MIME between gateways face a confidentiality risk involving content that is expected to remain encrypted. Administrators should therefore treat configuration exposure, not only the CVSS number, as part of prioritization.







