HIGHVulnerability
Verified
Global

Critical Cisco NX-OS Command Injection Affects Data Center Switches

Wednesday, March 11, 2026 at 10:00 AM UTC·Source: Cisco PSIRT

Updated: Thursday, March 12, 2026 at 08:00 AM UTC

Executive Summary

Command injection in Cisco NX-OS CLI allows authenticated users to escalate to root on Nexus data center switches. PoC exploit published.

Analysis

CVE-2026-20356 is a command injection in the NX-OS CLI that allows an authenticated user with basic access to execute arbitrary commands as root. A public PoC exploit was published within 48 hours of Cisco disclosure. Affects Nexus 3000, 5000, 7000, and 9000 series switches — the backbone of many enterprise data centers.

Timeline

Discovered
Mar 4, 2026
Published
Mar 11, 2026
Patch Available
Mar 11, 2026

Indicators of Compromise (1)

CVE (1)
CVE-2026-20356
Source Attribution

Originally published by Cisco PSIRT on Mar 11, 2026. Verified by: Cisco PSIRT, CISA.

Related Threats