Cisco Patches Critical NX-OS Flaws That Could Let Attackers Seize Nexus Switches
Cisco has released patches for five critical vulnerabilities in NX-OS, the operating system powering its Nexus 3000 and 9000 Series data center switches. Successful exploitation could hand an attacker root-level code execution on the device; where that isn't possible, the same bugs can still be abused to crash the switch and force it offline.
What happened
All five vulnerabilities trace back to the same root cause: the switch fails to properly validate certain network traffic before processing it, and each flaw depends on one specific feature being enabled on the target device.
- CVE-2026-76471 stems from insufficient input validation in the NX-API management interface and can be triggered with a single crafted HTTP request — but only if NX-API, which ships disabled, has been turned on.
- CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501 all come from improper validation of IP traffic reaching a device's network interface, and each requires Next Generation OAM (NGOAM) to be active. CVE-2026-76486 additionally needs Segment Routing over IPv6 or a Network Virtualization (NV) Overlay configured, and CVE-2026-76501 only applies to the subset of Nexus 9000 models that support SRv6.
- CVE-2026-76465 is caused by improper validation of MPLS echo-request packets and needs MPLS OAM explicitly switched on; Nexus 9000 switches built on Silicon One ASICs don't support that feature and are unaffected.
Nexus 7000 switches and any Nexus 9000 running in ACI mode sit outside the blast radius entirely. Cisco found all five issues through its own internal security testing and says it has seen no evidence of public exploitation so far.
Separately, in the same advisory batch, Cisco hardened its License platform (the former Smart Software Manager) against four additional bugs — missing authentication on critical functions, weak cryptographic signature checks, poorly protected credentials, and a code-injection flaw — three of which carry CVSS scores of 9.1 or higher. Those issues affect every configuration, with no workaround available.
Why it matters
Nexus switches sit at the core of enterprise and data center networks, so a root-level compromise there is a worst-case scenario: an attacker could pivot deeper into the network, intercept or redirect traffic, or simply take the switch down and disrupt everything behind it. Because several of the flaws only activate alongside specific features like NX-API, NGOAM, or MPLS OAM, exposure varies a lot between environments — but any site running those features on the named models is squarely in scope.
What to do
- Identify every Nexus 3000 and 9000 switch in standalone NX-OS mode and check which of NX-API, NGOAM, MPLS OAM, SRv6, or NV Overlay are enabled — Cisco's Software Checker tool can map your running version against the fixed releases.
- Patch to a fixed NX-OS release as soon as possible; for Cisco License, upgrade to release 10-202609, and migrate off any Smart Software Manager–branded build that won't receive a fix.
- Disable NX-API, NGOAM, or MPLS OAM on any switch that doesn't actually need them — this removes the attack surface outright.
- Where a device can't be patched or rebooted immediately, enable Cisco's temporary Live Protect shields as a stopgap.
