Cisco Nexus 9000에서 심각한 취약점 발견, 원격으로 악성 코드 실행 가능.
Cisco에서 10개의 Silicon One 기반 Nexus 9000 스위치에서 발견된 심각한 보안 취약점에 대한 패치를 발표했습니다. 이 취약점(CVE-2026-20212)은 인증되지 않은 원격 공격자가 root로서 코드를 실행할 수 있도록 허용하며, CVSS 점수는 9.8로 매우 높습니다. 또한, Cisco는 IOS XR 하드닝 릴리스를 포함하여 7개의 CVE를 수정했습니다.
A critical flaw in Cisco Nexus 9000 allows remote attackers to run code as root.
Cisco has issued patches for a critical security flaw found in 10 Silicon One-based Nexus 9000 switches that could enable unauthenticated remote attackers to execute code as root. This vulnerability, tracked as CVE-2026-20212, has a CVSS score of 9.8, indicating high severity. Additionally, Cisco bundled an IOS XR hardening release addressing 7 CVEs, with some rated at 9.8, and no workarounds available for any IOS XR version.