Cisco released security advisories for five critical vulnerabilities in its NX-OS data center network operating system that could be exploited to run arbitrary code with root privileges on Nexus switches.
If remote code execution cannot be achieved, an attacker could exploit the vulnerabilities to crash processes and force the vulnerable device to reload, resulting in a denial-of-service condition.
The issues affect the NX-API, Next Generation OAM (NGOAM), and MPLS OAM features in Nexus 3000 and Nexus 9000 Series switches.
All vulnerabilities relate to
The issues impact Nexus 3000 and Nexus 9000 Series switches in standalone NX-OS mode. However, successful exploitation depends on the NX-API, Next Generation OAM (NGOAM), and MPLS OAM features being active.
All five vulnerabilities are rooted in a validation failure and require at least one of the three features to be active on the affected device:
- CVE-2026-76471: Insufficient input validation; it can be exploited through a crafted HTTP request sent to the NX-API, a feature that is disabled by default.
- CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501: Improper validation of IP traffic can be exploited through crafted packets sent to an IP interface; all three require NGOAM to be enabled.
- CVE-2026-76465: Improper validation of MPLS echo-request packets allows exploitation through a crafted request sent to an affected device’s IP address.
Leveraging the CVE-2026-76486 flaw also requires either Segment Routing over IPv6 (SRv6) or Network Virtualization (NV) Overlay to be enabled.
“NV Overlay also requires a VXLAN Ethernet VPN (EVPN) VXLAN Network Identifier (VNI) mapped to a Network Virtualization Endpoint (NVE) interface with at least one peer VXLAN Tunnel Endpoint (VTEP) learned (for example, BGP EVPN or an ingress-replication static peer),” reads Cisco’s advisory.
CVE-2026-76501 is exploitable if SRv6, which is supported only on some Nexus 9000 models, is turned on.
In the case of CVE-2026-76465, MPLS OAM must be explicitly activated, as it is disabled by default. Nexus 9000 switches with Silicon One ASICs do not support the feature and are unaffected by this flaw.
The vendor notes that Nexus 7000 switches and Nexus 9000 switches operating in ACI mode are not affected by any of the five vulnerabilities.
Cisco recommends upgrading NX-OS releases to a fixed version, as can be identified through the vendor’s Software Checker tool.
The company recommends disabling NGOAM, NX-API, or MPLS OAM features if not needed, to eliminate the attack vector.
Cisco also provides temporary Live Protect shields for all five flaws, which is a protection system for switches that cannot yet be upgraded and rebooted.
All five vulnerabilities were discovered during internal security testing, and Cisco said it was unaware of public announcements or malicious exploitation at the time of publishing the advisories.
In addition to the five Nexus flaws Cisco addressed this time, the security and networking firm also released security hardening updates for Cisco License (formerly Smart Software Manager).
The issues span missing authentication for critical functions (CVE-2026-76480, CVSS 9.8), improper cryptographic signature verification (CVE-2026-76482, CVSS 10.0), insufficiently protected credentials (CVE-2026-76483, CVSS 9.1), and code injection (CVE-2026-76484, CVSS 8.8).
Affected releases are vulnerable regardless of configuration, and Cisco recommends upgrading to version 10-202609, with no workarounds available.
Older releases branded as Smart Software Manager will not receive a patch for these flaws, so Cisco recommends migrating to a supported release in those cases.
For the complete list of all security advisories Cisco released yesterday, check out this page.

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat

