Cisco warns of critical flaws allowing Nexus switch takeover
Cisco warns of five critical NX-OS flaws allowing Nexus switch takeover and RCE.
Summary
Cisco has issued advisories for five critical vulnerabilities in its NX-OS data center network operating system affecting Nexus 3000 and 9000 Series switches. Exploitation could lead to arbitrary code execution with root privileges or denial-of-service conditions. The vulnerabilities are rooted in input validation failures within features like NX-API, NGOAM, and MPLS OAM, and require specific features to be active for successful exploitation.
Full text
Cisco warns of critical flaws allowing Nexus switch takeover By Bill Toulas October 8, 2026 11:26 AM 0 Cisco released security advisories for five critical vulnerabilities in its NX-OS data center network operating system that could be exploited to run arbitrary code with root privileges on Nexus switches. If remote code execution cannot be achieved, an attacker could exploit the vulnerabilities to crash processes and force the vulnerable device to reload, resulting in a denial-of-service condition. The issues affect the NX-API, Next Generation OAM (NGOAM), and MPLS OAM features in Nexus 3000 and Nexus 9000 Series switches. All vulnerabilities relate to The issues impact Nexus 3000 and Nexus 9000 Series switches in standalone NX-OS mode. However, successful exploitation depends on the NX-API, Next Generation OAM (NGOAM), and MPLS OAM features being active. All five vulnerabilities are rooted in a validation failure and require at least one of the three features to be active on the affected device: CVE-2026-76471: Insufficient input validation; it can be exploited through a crafted HTTP request sent to the NX-API, a feature that is disabled by default. CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501: Improper validation of IP traffic can be exploited through crafted packets sent to an IP interface; all three require NGOAM to be enabled. CVE-2026-76465: Improper validation of MPLS echo-request packets allows exploitation through a crafted request sent to an affected device’s IP address. Leveraging the CVE-2026-76486 flaw also requires either Segment Routing over IPv6 (SRv6) or Network Virtualization (NV) Overlay to be enabled. "NV Overlay also requires a VXLAN Ethernet VPN (EVPN) VXLAN Network Identifier (VNI) mapped to a Network Virtualization Endpoint (NVE) interface with at least one peer VXLAN Tunnel Endpoint (VTEP) learned (for example, BGP EVPN or an ingress-replication static peer)," reads Cisco's advisory. CVE-2026-76501 is exploitable if SRv6, which is supported only on some Nexus 9000 models, is turned on. In the case of CVE-2026-76465, MPLS OAM must be explicitly activated, as it is disabled by default. Nexus 9000 switches with Silicon One ASICs do not support the feature and are unaffected by this flaw. The vendor notes that Nexus 7000 switches and Nexus 9000 switches operating in ACI mode are not affected by any of the five vulnerabilities. Cisco recommends upgrading NX-OS releases to a fixed version, as can be identified through the vendor’s Software Checker tool. The company recommends disabling NGOAM, NX-API, or MPLS OAM features if not needed, to eliminate the attack vector. Cisco also provides temporary Live Protect shields for all five flaws, which is a protection system for switches that cannot yet be upgraded and rebooted. All five vulnerabilities were discovered during internal security testing, and Cisco said it was unaware of public announcements or malicious exploitation at the time of publishing the advisories. In addition to the five Nexus flaws Cisco addressed this time, the security and networking firm also released security hardening updates for Cisco License (formerly Smart Software Manager). The issues span missing authentication for critical functions (CVE-2026-76480, CVSS 9.8), improper cryptographic signature verification (CVE-2026-76482, CVSS 10.0), insufficiently protected credentials (CVE-2026-76483, CVSS 9.1), and code injection (CVE-2026-76484, CVSS 8.8). Affected releases are vulnerable regardless of configuration, and Cisco recommends upgrading to version 10-202609, with no workarounds available. Older releases branded as Smart Software Manager will not receive a patch for these flaws, so Cisco recommends migrating to a supported release in those cases. For the complete list of all security advisories Cisco released yesterday, check out this page. Build your security blueprint for AI-powered attacks Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat Related Articles: Critical Cisco bug lets hackers add root users on SEG devicesCISA orders feds to patch exploited Citrix flaws by WednesdayCisco warns of high-severity ClamAV flaws with public exploitsCheck Point warns of hackers exploiting Security Gateway VPN RCE flawHackers start exploiting critical WordPress flaw for code execution
Indicators of Compromise
- cve — CVE-2026-76471
- cve — CVE-2026-76485
- cve — CVE-2026-76486
- cve — CVE-2026-76501
- cve — CVE-2026-76465
- cve — CVE-2026-76480
- cve — CVE-2026-76482
- cve — CVE-2026-76483
- cve — CVE-2026-76484