Cisco Warns of Critical NX-OS Flaws That Could Hand Attackers Root Access to Nexus Switches
Cisco has released fixes for five critical vulnerabilities in Cisco NX-OS Software used by Nexus data-center switches. The flaws could allow unauthenticated remote attackers to execute arbitrary code with root privileges or cause affected devices to reload, creating a denial-of-service condition.
The vulnerabilities affect Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches running in standalone NX-OS mode when the relevant features are enabled. Cisco’s advisories assign the flaws a CVSS base score of 9.8. Cisco said it was not aware of public announcements or malicious use when the advisories were published.
What is affected
CVE-2026-76471 affects the NX-API feature and can be triggered with a crafted HTTP request. Cisco says NX-API is disabled by default on Nexus 3000 and Nexus 9000 switches.
Three vulnerabilities—CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501—affect the Next Generation OAM feature, or NGOAM. CVE-2026-76485 requires NGOAM to be enabled. CVE-2026-76486 also requires either Segment Routing over IPv6 or Network Virtualization Overlay with the configuration described in Cisco’s advisory. CVE-2026-76501 requires both NGOAM and Segment Routing over IPv6.
The fifth issue, CVE-2026-76465, affects MPLS OAM and can be triggered by a specially crafted MPLS echo-request packet. Cisco says MPLS OAM is disabled by default, and Nexus 9000 switches with Silicon One ASICs do not support the feature.
Cisco says Nexus 7000 switches and Nexus 9000 switches operating in ACI mode are not affected by these five vulnerabilities. Separately, Cisco’s October security release addressed additional vulnerabilities in NX-OS, Meraki, License On-Prem, Application Policy Infrastructure Controller, and Finesse products.
What administrators should do
- Inventory Nexus 3000 and Nexus 9000 switches running standalone NX-OS.
- Check whether NX-API, NGOAM, MPLS OAM, Segment Routing over IPv6, or Network Virtualization Overlay is enabled.
- Use Cisco’s Software Checker to identify the fixed release for each device and advisory.
- Upgrade to a fixed software release as soon as operationally possible. If NGOAM, NX-API, or MPLS OAM is not needed, disable the feature after evaluating the effect on the deployment.
- Review device and network logs for unexpected management requests, unusual OAM traffic, configuration changes, crashes, or unexplained reloads.
For the separate NX-OS hardening release, Cisco lists first-fixed releases including 10.3(10), 10.4(8), 10.5(6), and 10.6(4) for affected Nexus 3000 and Nexus 9000 standalone deployments. Administrators should use the product-specific advisory and Software Checker rather than assume that one release applies to every device.
Why this matters
A successful root-level compromise of a network switch could allow an attacker to disrupt forwarding, alter device behavior, or use the device as a foothold for further attacks. Cisco has not reported exploitation of these vulnerabilities, but their remote, unauthenticated impact makes rapid assessment and patching important for organizations operating affected Nexus switches.
References
Arghire, I. (2026, October 8). Cisco patches a dozen critical vulnerabilities. SecurityWeek. https://www.securityweek.com/cisco-patches-a-dozen-critical-vulnerabilities/
Cisco. (2026, October 7). Cisco Nexus 3000 and 9000 Series switches NGOAM remote code execution vulnerabilities. Cisco Security Advisory. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ngoam-rce-LWKQ4BU
Cisco. (2026, October 7). Cisco NX-OS Software security hardening release: October 2026. Cisco Security Advisory. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-nxosw1-cWzSbtR
Cisco. (2026, October 7). Cisco NX-OS Software NX-API remote code execution vulnerability. Cisco Security Advisory. https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-napi-rce-r2shwu2j
Toulas, B. (2026, October 8). Cisco warns of critical flaws allowing Nexus switch takeover. BleepingComputer. https://www.bleepingcomputer.com/news/security/cisco-warns-of-critical-flaws-allowing-nexus-switch-takeover/
