Nexus switch vulnerabilities allow root code execution on Cisco NX-OS

Cisco published advisories for five critical NX-OS flaws that can lead to remote code execution or denial of service on Nexus 3000 and 9000 switches when certain features are enabled.

padlock resting on a disassembled network switch module with loose Ethernet cables

Cisco released advisories for five critical vulnerabilities in its NX-OS data center operating system that could let attackers run arbitrary code as root or crash Nexus switches, according to BleepingComputer. The flaws affect Nexus 3000 and Nexus 9000 Series switches running NX-OS in standalone mode, and successful attacks depend on particular features being active.

Nexus switch vulnerabilities, the basics

According to BleepingComputer, all five vulnerabilities stem from input or packet validation failures and are tied to three NX-OS features: NX-API, Next Generation OAM (NGOAM), and MPLS OAM. If an attacker cannot execute code, the same flaws can still crash processes and force the device to reload, producing a denial-of-service condition.

The five tracked CVEs and how they are reached are summarized by Cisco and reported by BleepingComputer as follows:

  • CVE-2026-76471, an insufficient input validation bug, can be triggered by a crafted HTTP request sent to the NX-API. Cisco notes NX-API is disabled by default.
  • CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501 involve improper validation of IP traffic and are exploitable via crafted packets sent to an IP interface, but only when NGOAM is enabled.
  • CVE-2026-76465 involves improper validation of MPLS echo-request packets and can be exploited through a crafted request to the device IP; MPLS OAM must be explicitly activated to be exposed.

Additional configuration conditions apply. Leveraging CVE-2026-76486 also requires either Segment Routing over IPv6, often called SRv6, or Network Virtualization Overlay to be enabled. Cisco’s advisory further explains NV Overlay needs a VXLAN Network Identifier mapped to an NVE interface with at least one learned peer VTEP. CVE-2026-76501 is exploitable if SRv6 is enabled, and SRv6 is supported only on some Nexus 9000 models.

Not affected are Nexus 7000 switches and Nexus 9000 switches running in ACI mode. Nexus 9000 switches with Silicon One ASICs do not support MPLS OAM and so are not vulnerable to the MPLS OAM issue.

Why this matters to small orgs and public sector teams

If you operate Nexus 3000 or 9000 switches in standalone NX-OS mode, and you have enabled NX-API, NGOAM, MPLS OAM, SRv6, or NV Overlay, these vulnerabilities can directly affect your network core. An attacker who can reach an exposed interface may be able to run code with full privileges or cause device reboots, disrupting services and potentially allowing deeper compromise.

Even if you do not use those features today, configuration drift, vendor templates, or third-party services could enable them without a recent review. Cisco said these issues were found during internal testing and that it was not aware of public reports or active exploitation at the time the advisories were published, according to BleepingComputer.

What Cisco recommends and temporary protections

Cisco’s guidance, as reported by BleepingComputer, is clear: upgrade affected NX-OS releases to fixed versions identified with the vendor’s Software Checker tool. If you cannot upgrade immediately, Cisco recommends disabling NX-API, NGOAM, or MPLS OAM when they are not needed to remove the attack surface. For switches that cannot be upgraded and rebooted right away, Cisco is providing temporary Live Protect shields to block exploitation.

Practical steps you can take now:

  • Inventory switches: confirm whether you have Nexus 3000 or 9000 Series devices running NX-OS in standalone mode and document where NX-API, NGOAM, MPLS OAM, SRv6 or NV Overlay are configured.
  • Disable unused features: turn off NX-API, NGOAM, or MPLS OAM on devices that do not need them, following your change control process.
  • Schedule upgrades: use Cisco’s Software Checker to identify fixed NX-OS releases and plan upgrades for affected devices.
  • Apply Live Protect shields: if immediate upgrade is not possible, see Cisco’s shields as a temporary mitigation until you can apply the fix.
  • Verify exceptions: confirm Nexus 7000 and ACI-mode Nexus 9000 devices are out of scope, and note that some Nexus 9000 models with Silicon One ASICs are not affected by the MPLS OAM flaw.

If you want to know how exposed your own site is, start with a free external scan on our security page: /security.html.

Other Cisco advisories to check

BleepingComputer also reports that Cisco released security hardening updates for Cisco License, the product formerly called Smart Software Manager. Those fixes cover a set of separate high-severity issues including missing authentication for critical functions, improper signature verification, exposed credentials, and code injection. Cisco recommends upgrading to release 10-202609 for those fixes and migrating older Smart Software Manager branded releases to supported releases, because older branded releases will not be patched for these problems.

Next steps for operators

Treat these NX-OS advisories as high priority if you manage affected Nexus hardware and the named features are in use. Follow your normal change management and test upgrades in staging before production rollouts. If you do not run the features named in the advisories, verify that they remain disabled and monitor for unexpected configuration changes. Finally, keep an eye on Cisco and trusted reporting for any updates about exploitation or additional mitigations, and plan upgrades as a definitive fix.

Sources

This post was drafted with AI from the reporting linked above and published by Jones Web Designs. For full details, read the original sources.

Found this useful? Pass it on to someone who would want to know.

All Online Security posts →

Cookie Notice

We use cookies to enhance your browsing experience and analyze site traffic. By clicking "Accept All", you consent to our use of cookies.