The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. Learn more about how Cisco is using Inclusive Language.
Feedback
CVE-2026-20212 - Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability
Live Protect Shield
Cisco has released Live Protect shield for CVE-2026-20212 to temporarily mitigate this vulnerability in Cisco NX-OS Software.
For information about Live Protect for Cisco NX-OS Software, see Cisco Nexus 9000 Series NX-OS Security Configuration Guide.
Note: Live Protect shield is a temporary mitigation to bridge the gap until software updates can be scheduled. To fully remediate this vulnerability, upgrade to a fixed software release, which can be found using the Cisco Software Checker.
Overview
A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges.
For additional information, refer to the security advisory at the following link:
| Attribute |
Details |
| CVE ID |
CVE-2026-20212 |
| Shield ID |
lp00031 |
| Reference CDETS (IDs) |
CSCwu32817 |
| Shield File |
lp00031.lps-sone-secure-se1u-v1.lps |
Requirements
● Affected switches
o N9324C-SE1U
o N9348Y2C6D-SE1U
Any Cisco Nexus Switches other than the above mentioned ones are not affected.
● Access: SSH, Telnet, or NXAPI access required for deployment.
Supported Releases
Cisco NX-OS Release 10.6(3s)
Shield behavior during Upgrade and Downgrade
Upgrade: When upgrading to NX-OS 10.6(4) or higher, shield operational mode transitions to N/A.
Downgrade: When downgrading to NX-OS 10.6(2), the shield will not be removed. You must remove the shied prior to downgrade using nxsecure policy remove method. For information about Live Protect for Cisco NX-OS Software, see Cisco Nexus 9000 Series NX-OS Security Configuration Guide.
Verification & Deployment Flow
The following process map outlines the validation path after policy deployment:

Verification Details
Policy Status
Use the following command to confirm the shield is in enforce mode:
switch# sh nxsecure policy status
Id Name Package Original Override Current Hits
lp00031 lps-sone-secure lp00031.lps-sone-secure-se1u-v enforce none enforce 1
To inspect the hit events, use:
switch# show nxsecure log lp00031
Policy Id : lp00031
Policy Name : lps-sone-secure
Policy Severity : CRITICAL
Policy Event : Hit for CVE-2026-20212: Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability
Policy Event History(last 20 events):
SNo Time Mode Process
1 2026 Aug 25 01:02:38 enforce /usr/bin/nc
A syslog is received for every hit:
Syslog:
2026 Sep 1 16:59:43 switch %$ VDC-1 %$ %APPMGR-2-NXSECURE_CRIT_THREAT: Shield ID: lp00031, Mode: enforce, Msg : Hit for CVE-2026-20212: Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability
Reference
For detailed installation steps about Live Protect for Cisco NX-OS Software, see Cisco Nexus 9000 Series NX-OS Security Configuration Guide.
To provide technical feedback on this document, or to report an error or omission, please send your comments to nexus9k-docfeedback@cisco.com. We appreciate your feedback.
Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: https://www.cisco.com/c/en/us/about/legal/trademarks.html. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1721R)
Any Internet Protocol (IP) addresses and phone numbers used in this document are not intended to be actual addresses and phone numbers. Any examples, command display output, network topology diagrams, and other figures in the document are shown for illustrative purposes only. Any use of actual IP addresses or phone numbers in illustrative content is unintentional and coincidental.
© 2026 Cisco Systems, Inc. All rights reserved.