FR
live

Cisco patches five critical NX-OS flaws that hand root on Nexus 3000 and 9000 switches

On October 7, 2026, Cisco shipped five critical fixes for NX-OS, the operating system of its Nexus 3000 and 9000 switches: a forged request can run code with root privileges, or crash a process and force a reload. Check whether NX-API, NGOAM or MPLS OAM is enabled on your gear, then patch or disable those features.

A row of dark RJ45 ports on a data center switch faceplate, one amber link LED glowing.

October 7, 2026. Cisco ships five critical fixes for NX-OS, the operating system that runs its Nexus data center switches. CVE-2026-76471. That is the number of the first one, a remote code execution flaw reachable through the switch’s API. Root. That is the privilege level an attacker gets by exploiting any of them, or they can crash a process and force the device to reload. Why it matters: Nexus 3000 and 9000 switches carry the network core of thousands of organizations, and these five flaws live in management and overlay features that plenty of teams leave switched on without a second thought.

Five flaws, one validation failure

The five vulnerabilities share a single root cause: insufficient input validation. Cisco is explicit in its advisories — each one can be triggered either by a crafted HTTP request or by crafted IP packets, and an unauthenticated attacker can reach the vulnerable code as soon as they can reach the switch.

Remote code execution is not the only scenario. If the RCE fails, an attacker can at minimum crash the affected process and force the device to reload, which amounts to a denial of service on a box that carries live traffic. On an aggregation or core switch, an unplanned reload is not a minor incident; it is an outage.

The five flaws break down into three groups, according to the feature they target.

  • NX-API. CVE-2026-76471 is exploited through a crafted HTTP request sent to the switch’s management API. It is the most direct entry point, but the feature is disabled by default.
  • NGOAM. CVE-2026-76485, CVE-2026-76486 and CVE-2026-76501 target Next Generation OAM, the operations, administration and maintenance tooling. They are exploited through crafted IP packets sent to an interface, provided NGOAM is enabled. CVE-2026-76486 additionally requires Segment Routing over IPv6 (SRv6) or NV Overlay to be active, and CVE-2026-76501 requires SRv6, which is only available on some Nexus 9000 models.
  • MPLS OAM. CVE-2026-76465 is exploited through a crafted MPLS echo-request sent to the device’s IP address. The feature is disabled by default, and Nexus 9000 switches with Silicon One ASICs do not support it at all — so they are unaffected by this particular flaw.

That breakdown is not a technical footnote; it determines who is actually exposed.

The real risk lives in the features you enabled

The question every network team has to answer is a single sentence: which features are running on my switches? NX-API, NGOAM and MPLS OAM are not enabled everywhere, and that is the key to the real blast radius.

NX-API is the door to automation — the Ansible scripts, telemetry collectors and CI/CD integrations that drive the network. Any team that automates its Nexus configuration has likely opened NX-API, often on a management address reachable from the admin network. That is exactly the surface an attacker moving laterally likes to find.

NGOAM and MPLS OAM belong to another register: running and diagnosing overlays. NGOAM is enabled in deployments that monitor tunnel and path continuity, and MPLS OAM in MPLS networks that need to test their LSPs. These features are less common, but they are precisely present where the network is most critical — MPLS cores and EVPN/VXLAN architectures.

The operational consequence is clear. A switch that enables none of the three features is not directly exploitable by these flaws, even if it is technically vulnerable. A switch that enables them multiplies its attack surface.

Nexus 7000 and ACI mode spared

The hardware scope is worth stating precisely. The vulnerabilities affect Nexus 3000 and Nexus 9000 running in standalone NX-OS mode. Two families are explicitly not affected: Nexus 7000 switches, and Nexus 9000 switches operated in ACI mode.

That distinction matters. Many data centers run their Nexus 9000 switches in ACI mode, Cisco’s controller-driven architecture. In that mode the management surface is different, and these five flaws do not apply. A team running an ACI estate needs to know that before raising a blanket alarm.

For everyone else, the triage is simple: inventory the switches in standalone NX-OS mode, then determine which features are enabled on each one.

The defenses: disable, shield, patch

Cisco offers three levels of response, and they do not replace each other.

First, shrink the surface. The vendor recommends disabling NX-API, NGOAM and MPLS OAM if those features are not in use. This is the fastest and most effective step: without the feature active, the attack vector disappears, even before a patch.

Second, the Live Protect shield. Cisco provides Live Protect shields for all five flaws — a protection mechanism aimed at switches that cannot yet be upgraded and rebooted. It is a temporary mitigation, not a destination: a switch under Live Protect is still vulnerable on paper and must eventually be patched.

Third, the upgrade. Cisco points to its Software Checker tool to identify the fixed NX-OS release for each train. This is the only durable exit, and it requires rebooting the device — which is exactly why Live Protect exists for distant maintenance windows.

The origin of the flaws is both reassuring and worrying. All five were discovered during Cisco’s internal security testing, and the vendor said it was unaware of any public announcement or exploitation at the time of publication. That is the good news: no active zero-day at this stage. But Cisco’s recent history teaches that an advisory with no known exploitation can turn into an emergency within days.

Cisco License: four more flaws, including a CVSS 10.0

In the same batch of advisories, Cisco hardens Cisco License, formerly Smart Software Manager, with four vulnerabilities that deserve to be treated separately.

  • CVE-2026-76480 — missing authentication on critical functions, rated CVSS 9.8.
  • CVE-2026-76482 — improper cryptographic signature verification, rated CVSS 10.0, the top of the scale.
  • CVE-2026-76483 — insufficiently protected credentials, rated CVSS 9.1.
  • CVE-2026-76484 — code injection, rated CVSS 8.8.

The hard part is this: these four flaws affect releases regardless of configuration, and Cisco asks users to move to version 10-202609. Older releases sold as Smart Software Manager will not receive a patch — the vendor recommends migrating to a supported release. For teams still running a legacy Smart Software Manager, that is a hard deadline, not a gentle reminder.

Verdict

If your Nexus 3000 or 9000 switches run standalone NX-OS with NX-API, NGOAM or MPLS OAM enabled, treat these five fixes as a priority for the week: a forged request can hand root on a device that carries your traffic, and disabling the unused features neutralizes the risk today, before the upgrade even lands. If you run your estate in ACI mode or on Nexus 7000, you are not affected by these specific flaws, but use the moment to check the Cisco advisories that do touch your models. In every case, if you still run a legacy Smart Software Manager, schedule the migration to 10-202609 — there will be no patch for the older versions, and an unpatched CVSS 10.0 is a time bomb, not a theoretical risk.

References

The cyber brief, every Tuesday

The flaws that matter and the patches to apply, in a ten-minute read.

No spam. One-click unsubscribe.
read next

On the same topic

Homa cuts datacenter short-message latency thirteenfold versus TCP

On October 1, 2026, John Ousterhout, Stanford professor emeritus, made the case for Homa, a message-based transport protocol whose p99 latency on short messages drops to 92 microseconds against 1.2 milliseconds for TCP over a 100 Gbps link. Evaluate it on the datacenter links where every millisecond idles a GPU, but price the adoption cost before replacing anything.

← Back to the feed

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss