Cisco Patches Critical Nexus and IOS XR Flaws, Flags Secure Email Decryption Bugs

Server Security

Cisco has released fixes for critical vulnerabilities in Nexus 9000 switches and IOS XR software, including flaws rated 9.8 out of 10 that can lead to root-level remote code execution or improper access control. A separate Secure Email advisory warns that two publicly disclosed S/MIME weaknesses can expose plaintext from encrypted messages.

The advisories were published on September 2 as part of Cisco’s scheduled security release. The most immediately actionable issue for data-center operators is CVE-2026-20212, a critical vulnerability affecting specific Nexus 9000 Series switches equipped with Silicon One ASICs.

Cisco said it is not aware of malicious exploitation of the Nexus, IOS XR or Secure Email vulnerabilities. The company has nevertheless advised customers to move to fixed software, while operators unable to patch the Nexus flaw immediately have temporary mitigation options.

Highest severity CVSS 9.8 Cisco assigned critical 9.8 scores to the Nexus 9000 remote-code-execution flaw and to vulnerability classes addressed in the September IOS XR hardening release.

Nexus 9000 Flaw Can Give Attackers Root Access

CVE-2026-20212 affects Cisco Nexus 9000 Series switches that contain a Silicon One ASIC. Cisco said TCP ports 43210 and 43211 are accessible through the default Layer 3 virtual routing and forwarding instance on affected devices.

An unauthenticated remote attacker able to reach those ports could send crafted input and execute code with root privileges. Exploitation can also crash the S1HAL process and force the switch to reload.

Cisco lists ten affected Nexus 9000 product identifiers, including N9324C-SE1U, N9348Y2C6D-SE1U, N9336C-SE1, N9396T12C-SE1, N9348Y12C-SE1, N9396Y12C-SE1, N9364E-SG2-O, N9364E-SG2-Q, N9K-C9804 and N9K-C9808.

The company has released software updates for the flaw. As a temporary measure, Cisco says infrastructure access control lists can be used to block TCP traffic to ports 43210 and 43211 on locally configured addresses unless that traffic is explicitly required. Cisco has also released a Live Protect shield for CVE-2026-20212.

Those mitigations are not a substitute for patching. Cisco says operators should upgrade to a fixed NX-OS release to fully remediate the issue.

All IOS XR Releases Are Affected by New Hardening Advisory

Cisco’s second critical advisory is broader. Its September IOS XR hardening release addresses multiple internally discovered flaws grouped under seven CVE identifiers: CVE-2026-20274 through CVE-2026-20280.

Two vulnerability classes reach a maximum CVSS score of 9.8. CVE-2026-20274 covers resource-lifetime and memory-safety issues, including buffer overflows, out-of-bounds access and use-after-free conditions. CVE-2026-20279 covers improper access-control weaknesses, including missing authentication or authorization and improper certificate validation.

Cisco says the vulnerabilities affect all releases of IOS XR Software, including IOS XR7, regardless of device configuration. They were found during Cisco’s internal testing and are not known to be actively exploited.

There are no workarounds for the IOS XR issues. Cisco has made Software Maintenance Upgrades available for a number of supported release trains, while some other fixes remain scheduled for future releases. The company says IOS XR 26.2.2 and 26.3.1 will be the first future releases to incorporate the fixes without requiring the advisory’s SMUs.

Issue Affected infrastructure Severity Operator action
CVE-2026-20212 Nexus 9000 switches with listed Silicon One ASIC platforms Critical, 9.8 Upgrade; iACL or Live Protect shield can provide temporary mitigation
CVE-2026-20274 to CVE-2026-20280 All Cisco IOS XR releases Up to 9.8 Install fixed releases and applicable SMUs; no workaround
CVE-2026-20354 and CVE-2026-20355 Secure Email with AsyncOS 16.5.0 or earlier and S/MIME gateway communication enabled Medium, 5.9 Review Cisco fixed-release information; no workaround

Secure Email Bugs Can Expose Encrypted Messages

The same disclosure cycle also included CVE-2026-20354 and CVE-2026-20355, two medium-severity vulnerabilities in Cisco Secure Email’s S/MIME decryption functionality.

The flaws result from insufficient validation of message integrity. Cisco says an unauthenticated attacker capable of intercepting and modifying traffic between email gateways could use a machine-in-the-middle attack to recover plaintext from encrypted communications.

Affected systems are Cisco Secure Email devices running AsyncOS 16.5.0 or earlier when S/MIME is configured for communication between email gateways. Cisco assigns the vulnerabilities a CVSS score of 5.9 and says no workaround is available.

The Secure Email flaws differ from the switch vulnerabilities in one important respect: Cisco says a public announcement about the S/MIME weaknesses already exists. However, PSIRT said it was not aware of malicious exploitation when the advisory was published.

What operators should do now
Network teams should first identify Nexus 9000 systems with the affected Silicon One hardware and patch or restrict access to ports 43210 and 43211. IOS XR operators need to map deployed release trains to Cisco’s available SMUs or fixed versions, while Secure Email administrators should check AsyncOS versions and whether S/MIME gateway-to-gateway communication is enabled.

Why It Matters for Infrastructure

The Nexus issue is the highest-priority data-center exposure in the release because successful remote exploitation can provide root-level execution on an affected switch without authentication. Compromise or forced reloads at the switching layer can have consequences beyond a single server or application workload.

The IOS XR advisory has a different operational challenge: its scope covers every IOS XR release, making inventory and patch planning important for operators running the software across routing infrastructure. With no workaround available, Cisco’s SMUs and fixed releases are the remediation path.

For Secure Email, the severity score is lower, but environments that use S/MIME between gateways face a confidentiality risk involving content that is expected to remain encrypted. Administrators should therefore treat configuration exposure, not only the CVSS number, as part of prioritization.

Cisco first published the Nexus 9000, IOS XR and Secure Email advisories on September 2, 2026. The IOS XR advisory was subsequently updated on September 3. Cisco PSIRT said it was not aware of malicious exploitation of the vulnerabilities at the time of its latest published information.