Apply the patches released by Cisco for Nexus 9000 and IOS XR immediately. No workarounds exist for the IOS XR vulnerabilities; upgrading to the hardened release is required.
Quick answers
What is CVE-2026-20212?
Apply the patches released by Cisco for Nexus 9000 and IOS XR immediately. No workarounds exist for the IOS XR vulnerabilities; upgrading to the hardened release is required.
How severe is CVE-2026-20212?
critical, CVSS 9.8
Is CVE-2026-20212 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-20212 be mitigated?
Apply the patches released by Cisco for Nexus 9000 and IOS XR immediately. No workarounds exist for the IOS XR vulnerabilities; upgrading to the hardened release is required.
CVSS
9.8
Vendor
Cisco
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
Nexus 9000, IOS XR
Mitigation
Apply the patches released by Cisco for Nexus 9000 and IOS XR immediately. No workarounds exist for the IOS XR vulnerabilities; upgrading to the hardened release is required.
Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root (CVE-2026-20212, CVSS 9.8). Concurrently, an IOS XR hardening release bundles fixes for seven umbrella CVEs, two of which are rated 9.8, with Cisco stating there are no workarounds for any IOS XR version.