Cisco released fixes for nine vulnerabilities across Nexus 9000 switches, IOS XR, SIP software, and selected collaboration endpoints. The most severe, CVE-2026-20212 (CVSS 9.8), affects certain Silicon One-based Nexus 9000 switches: unauthenticated remote attackers can send crafted traffic to TCP ports 43210 or 43211 exposed through the default Layer 3 VRF and execute code as root. Cisco also patched critical IOS XR and Nexus flaws, including CVE-2026-20274 and CVE-2026-20279, which can enable remote code execution or authentication bypass, and fixed the high-severity phone denial-of-service issue CVE-2026-20281.
Cisco separately warned that CVE-2026-20354 and CVE-2026-20355 remain unpatched in Secure Email appliances running AsyncOS 16.5.0 or earlier with S/MIME enabled. A man-in-the-middle attacker able to intercept and alter gateway traffic could recover plaintext from encrypted email communications. Cisco reported no known public exploitation of the patched flaws or the Secure Email issues; organizations should promptly deploy applicable NX-OS, IOS XR, and other Cisco updates, while restricting access to ports 43210 and 43211 with infrastructure ACLs or port blocks until Nexus systems can be upgraded.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Cisco published advisory cisco-sa-n9k-s1-rce-EH8dEtr and released fixed NX-OS software for CVE-2026-20212, a CVSS 9.8 unauthenticated remote-code-execution flaw in certain Nexus 9000 switches with Silicon One ASICs. The flaw exposed TCP ports 43210 and 43211 through the default Layer 3 VRF configuration and could permit code execution as root; Cisco said it knew of no public exploitation.
Cisco released Live Protect shield lp00031 as a temporary mitigation to block exploitation attempts against CVE-2026-20212 and published Snort Rule 67005 to detect associated activity. Cisco also provided an infrastructure ACL workaround to block traffic to affected local switch addresses on TCP ports 43210 and 43211.
Cisco fixed CVE-2026-20281, a high-severity denial-of-service vulnerability affecting specified Desk Phone 9800, IP Phone 7800 and 8800, and Video Phone 8875 devices using SIP. An unauthenticated attacker could send continuous crafted HTTP packets to cause a denial-of-service condition.
Cisco released patches for seven critical IOS XR vulnerabilities, including CVE-2026-20274 and CVE-2026-20279, both rated CVSS 9.8. The issues could enable outcomes including remote code execution, authentication bypass, and code injection, and Cisco said it was unaware of exploitation.
Cisco disclosed CVE-2026-20354 and CVE-2026-20355, two publicly disclosed medium-severity flaws affecting Secure Email devices running AsyncOS 16.5.0 or earlier with S/MIME enabled. A man-in-the-middle attacker could intercept and modify gateway traffic to recover plaintext from encrypted communications; Cisco reported no known in-the-wild exploitation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
11 references tracked. Mallory keeps watching after this page renders.
csoonline.com
Open sourcecsirt.sk
Open sourcecysecurity.news
Open sourcesocprime.com
Open sourcesecurityweek.com
Open sourceacn.gov.it
Open sourcecybersecuritynews.com
Open sourcesdxcentral.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.