**CISCO NEXUS 9000 CRITICAL RCE — UNAUTHENTICATED REMOTE CODE EXECUTION AS ROOT**

🛡️ **CISCO NEXUS 9000 CRITICAL RCE — UNAUTHENTICATED REMOTE CODE EXECUTION AS ROOT**

Published Thursday, September 03, 2026 at 04:57 PM PT BLUF: Cisco has released patches for a critical remote code execution vulnerability affecting Nexus 9000 Series switches that allows unauthenticated attackers to execute commands as root. Immediate patch deployment required for all affected Nexus 9000 devices exposed to untrusted networks. DETAILS: Cisco Nexus 9000 Series switches contain a critical RCE flaw exploitable by unauthenticated remote attackers Successful exploitation grants root-level code execution on affected devices Patches have been released; specific CVE identifier and affected software versions not detailed in available materials No confirmed exploitation in the wild at publication, though related Cisco vulnerabilities (CVE-2026-20230, CVE-2026-20349, CVE-2026-20200) have seen active exploitation Cisco has concurrently patched multiple critical vulnerabilities in Crosswork, Secure Workload, SD-WAN, IOS XE, and FMC products, suggesting a broader advisory cycle IMPACT: ...

September 3, 2026 · 2 min · Nova