Get Your Free Report
Start for Free
SOCRadar® Cyber Intelligence Inc. | Critical Cisco NX-OS Flaws Threaten Nexus Switches
Oct 09, 2026
4 Mins Read
Moon
Summarize with:

Critical Cisco NX-OS Flaws Threaten Nexus Switches

Cisco has patched five critical vulnerabilities affecting Nexus 3000 and Nexus 9000 switches running standalone NX-OS. The flaws can allow unauthenticated remote attackers to execute code with root privileges or trigger Denial of Service (DoS) conditions when the relevant features are enabled.

What Are the Cisco NX-OS Vulnerabilities?

The five vulnerabilities affect NX-API and two Operation, Administration, and Maintenance (OAM) features, all carrying CVSS 3.1 scores of 9.8:

  • CVE-2026-76471: Heap-based buffer overflow (CWE-122) in NX-API.
  • CVE-2026-76485: NGOAM stack-based buffer overflow requiring NGOAM.
  • CVE-2026-76486: NGOAM flaw requiring NGOAM plus SRv6 or NV Overlay.
  • CVE-2026-76501: NGOAM flaw requiring NGOAM and SRv6.
  • CVE-2026-76465: Improper validation (CWE-590) in MPLS OAM echo request processing.

Cisco’s NX-API advisory confirms that CVE-2026-76471 can be triggered with a crafted HTTP request, potentially resulting in root level code execution, process crashes, or a device reload.

The three NGOAM vulnerabilities can similarly result in root level code execution or DoS when their configuration prerequisites are met.

Details of CVE-2026-76471 (SOCRadar Vulnerability Intelligence)

Details of CVE-2026-76471 (SOCRadar Vulnerability Intelligence)

Which Cisco Nexus Systems Are Affected?

The primary affected platforms are Nexus 3000 and Nexus 9000 Series switches running standalone NX-OS.

Exposure depends heavily on configuration:

Vulnerability Required Feature/Condition
CVE-2026-76471 NX-API enabled
CVE-2026-76485 NGOAM enabled
CVE-2026-76486 NGOAM + SRv6 or NV Overlay
CVE-2026-76501 NGOAM + SRv6
CVE-2026-76465 MPLS OAM enabled

For CVE-2026-76486 with NV Overlay, Cisco additionally requires a VXLAN EVPN VNI mapped to an NVE interface with at least one learned VTEP. Nexus 3000 switches do not support SRv6, limiting exposure to CVE-2026-76501.

NX-API and MPLS OAM are disabled by default. Nexus 9000 switches using Silicon One ASICs do not support MPLS OAM and are therefore unaffected by CVE-2026-76465.

Cisco also confirms that Nexus 7000 switches and Nexus 9000 switches in ACI mode are not affected by these vulnerabilities.

What About UCS 6300 Fabric Interconnects?

CVE-2026-76471 also affects UCS 6300 Series Fabric Interconnects, but the attack conditions differ.

Exploitation occurs through the UCS Manager XML API and requires valid low-privileged credentials, so Cisco rates the issue High rather than Critical for UCS 6300. UCS Manager 4.3 is fixed in 4.3(6j); 4.2 and earlier must migrate to a fixed release.

Why Are These Vulnerabilities High Risk?

These flaws affect data center switching infrastructure responsible for routing, segmentation, and application connectivity.

Successful exploitation could provide root-level control of a switch, allowing an attacker to interfere with network operations or potentially use the compromised device as a foothold. Failed exploitation may still crash processes or force a reload, causing service disruption.

Cisco details the NGOAM conditions in its NGOAM security advisory and the MPLS flaw in its MPLS OAM advisory.

Is There Active Exploitation or a Public PoC?

No confirmed exploitation has been reported as of October 9, 2026.

Cisco PSIRT says it is not aware of public announcements or malicious use involving any of the five vulnerabilities.

Track Cisco NX-OS Exposure with SOCRadar

Powered by SOCRadar’s Cyber Threat Intelligence module, Vulnerability Intelligence can help teams track these five vulnerabilities, exploit developments, and remediation updates.

Combined with Attack Surface Management, teams can identify exposed Cisco infrastructure and prioritize switches where vulnerable features and broad network reachability overlap.

SOCRadar’s Vulnerability Intelligence

SOCRadar’s Vulnerability Intelligence

What Should Defenders Do?

Upgrade to Cisco’s Fixed Releases

Cisco strongly recommends upgrading affected devices. Because fixed versions vary by hardware and NX-OS train, use Cisco’s Software Checker to identify the earliest fixed release for each switch rather than applying one version across the fleet.

Disable Unnecessary Features

Where patching cannot happen immediately:

  • Disable NX-API if it is not required.
  • Disable NGOAM with no feature ngoam.
  • Disable MPLS OAM with no feature mpls oam.
  • Review whether SRv6, NV Overlay, VXLAN EVPN, and NVE configurations are necessary.

Cisco has also released Live Protect shields for all five CVEs. These are temporary mitigations and do not replace upgrading.

Hunt for Suspicious Activity

Review NX-API HTTP traffic, NGOAM and MPLS OAM network activity, configuration changes, process crashes, service restarts, and unexpected switch reloads.

Correlate device events with firewall, proxy, and out-of-band management telemetry. Treat unexplained crashes or reloads on feature-enabled Nexus switches as potential security events until investigated.

Prioritize internet-facing and cross-segment reachable switches first, then validate feature status and fixed versions across the remaining fleet.