A Network Packet Could Give Attackers Root on Cisco Nexus 9000 Switches

A critical Cisco Nexus 9000 flaw exposes root-level remote code execution through TCP ports 43210 and 43211 on affected Silicon One switches.

A critical Cisco Nexus 9000 flaw exposes root-level remote code execution through TCP ports 43210 and 43211 on affected Silicon One switches.

Seven flaws affect every Cisco IOS XR release, two carry a 9.8 score, and operators have no general workaround while planning fixes.

Cisco warns that model publishers and country labels can hide inherited weights, training data and upstream dependencies.

Cisco Talos found UAT-10147 using agentic AI to scale exploitation and post-compromise work across a target list containing approximately 170,000 web-server URLs.

Cisco has documented three distinct FMC attack campaigns, including no-login root access, Sandworm-linked tooling and ransomware preparation. Patch exposed managers and investigate each cluster separately.

Cisco says attackers are exploiting a denial-of-service flaw in ASA and Secure Firewall Threat Defense. The lesson is not only to patch the VPN edge, but to design for the moment the security device itself becomes unavailable.

Cisco fixed nine vulnerability classes across Crosswork and Secure Workload, including five with maximum CVSS scores. There are no workarounds, and several components must be upgraded together.

JWR combines 44 phishing pages with an encrypted WebSocket and live operator commands, turning a fake page into an adaptive fraud session.

Cisco confirmed active exploitation of a Unified CM WebDialer flaw that let unauthenticated attackers write files and work toward root.

Cisco ISE's critical command injection required an administrator, while the lower-scored flaw exposed hashed credentials without authentication.