Cisco has disclosed five critical vulnerabilities in NX-OS that can expose configured Nexus 3000 and Nexus 9000 Series switches to remote code execution or denial-of-service attacks.
The flaws affect three network-facing components: NX-API, Next Generation OAM (NGOAM), and MPLS OAM. An unauthenticated attacker could send specially constructed traffic to an exposed interface, potentially execute arbitrary code with root privileges, crash processes, or force the switch to reload.
Exposure is configuration-dependent. The relevant feature must be active, while two NGOAM vulnerabilities require additional SRv6 or NV Overlay settings.
Cisco published its NX-API and NGOAM advisories on October 7, 2026, at 16:00 GMT. The NX-API advisory was updated on October 8, 2026, at 14:11 GMT and is marked final, version 1.1. The NGOAM advisory is final, version 1.0.
Five attack paths share a critical 9.8 severity score
Cisco rates all five vulnerabilities Critical. The advisories assign a base CVSS v3.1 score of 9.8 and the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting a low-complexity network attack requiring neither credentials nor user interaction.
Each vulnerability reaches a different NX-OS feature or configuration:
-
CVE-2026-76471 is an NX-API input-validation flaw classified as
CWE-122. An attacker can target a vulnerable switch by sending a crafted HTTP request to its NX-API interface. NX-API is disabled by default on Nexus 3000 and Nexus 9000 switches. Cisco tracks the issue as CSCwu46199 and CSCwu58579. -
CVE-2026-76485 affects NGOAM and is classified as
CWE-121. NGOAM being enabled is the only additional feature requirement described by Cisco. Exploitation involves crafted traffic sent to an IP interface. -
CVE-2026-76486 also affects NGOAM but requires either Segment Routing over IPv6 (SRv6) or NV Overlay. In the NV Overlay case, an EVPN VXLAN Network Identifier must be mapped to an NVE interface, with at least one learned peer VXLAN Tunnel Endpoint. Cisco gives BGP EVPN and an ingress-replication static peer as examples of how the peer may be learned.
-
CVE-2026-76501 requires NGOAM and SRv6 to be enabled together. Nexus 3000 switches do not support SRv6, and Cisco says only a subset of Nexus 9000 models supports it.
-
CVE-2026-76465 results from improper validation during MPLS echo-request processing and is classified as
CWE-590. A remote attacker can send a crafted MPLS echo-request to an IP address on the switch. MPLS OAM is disabled by default and must be explicitly enabled. The reporting on Cisco’s disclosure says Nexus 9000 switches with Silicon One ASICs do not support this feature and are therefore unaffected by this particular flaw.
Cisco tracks the three NGOAM issues under bug IDs CSCwu19785, CSCwu19823, and CSCwu57455.
For all five vulnerabilities, the documented consequences include root-level arbitrary code execution and process crashes that may reload the device. The latter outcome would interrupt switching operations and create a denial-of-service condition.
Nexus exposure depends on mode, software and configuration
The primary affected products are Nexus 3000 and Nexus 9000 Series switches running vulnerable NX-OS releases in standalone mode. Membership in either product family alone does not establish exposure: administrators must also determine whether the corresponding NX-API, NGOAM, MPLS OAM, SRv6, or NV Overlay conditions are present.
Cisco confirms that Nexus 7000 Series switches and Nexus 9000 Series Fabric Switches operating in ACI mode are not affected. Its advisory-specific unaffected lists also include:
- Firepower 1000, 2100 and 4100 Series, and Firepower 9300 Security Appliances
- MDS 9000 Series Multilayer Switches
- Secure Firewall 200, 1200, 3100, 4200 and 6100 Series
- UCS 6400, 6500 and 6600 Series Fabric Interconnects
- UCS X-Series Direct Fabric Interconnect 9108 100G
UCS 6300 Series Fabric Interconnects require separate treatment. Cisco lists them as affected by CVE-2026-76471, but not by the three NGOAM vulnerabilities.
Exploitation on a UCS 6300 requires valid low-privileged credentials and takes place through the Cisco UCS Manager XML API. That interface is enabled by default and cannot be disabled without losing functionality. Because authentication is required, Cisco rates the impact on UCS 6300 systems High rather than Critical.
For UCS Software release 4.3, the first fixed release is 4.3(6j). Cisco instructs customers using release 4.2 or earlier to migrate to a fixed release.
CLI checks reveal whether vulnerable features are active
Cisco provides several NX-OS commands for identifying relevant configurations. These checks show whether attack prerequisites exist; their output is not evidence that a switch has been compromised.
Administrators can check NX-API with:
show feature | include nxapi
Cisco’s example of an active instance is:
nxapi 1 enabled
For NGOAM, use:
show feature | include ngoam
An enabled result appears as:
ngoam 1 enabled
Operators assessing CVE-2026-76486 should also check NV Overlay:
show feature | include nve
Cisco recommends three further commands to identify an NVE interface, mapped VNIs, and learned peers:
show running-config | begin "interface nve"
show nve vni
show nve peers
If all three return data, Cisco says the device may satisfy the NV Overlay conditions for CVE-2026-76486. The advisory’s example contains interface nve1, VNIs 160010 and 160020, multicast group 203.0.113.1, and peer 192.168.2.1. These are illustrative configuration values, not indicators of compromise.
SRv6 status can be checked with:
show feature | include srv6
Cisco shows the following output for an enabled configuration:
srv6 1 enabled
Fixed software is the primary remediation
Cisco has released software updates and strongly recommends upgrading affected switches to a fixed release. Its Software Checker can identify whether a specific NX-OS release is vulnerable and return the earliest corrected version, labelled “First Fixed.”
Where multiple advisories apply, the tool may also provide a “Combined First Fixed” release addressing all identified vulnerabilities. The excerpts reviewed here do not reproduce the affected and fixed NX-OS release tables, so operators should consult Cisco’s advisory and Software Checker for the exact release applicable to each platform.
Cisco says there are no workarounds that directly address the NX-API or NGOAM vulnerabilities. Feature removal can nevertheless eliminate particular attack paths when the functionality is unnecessary.
For all three NGOAM flaws, the documented mitigation is to disable the feature from global configuration mode:
no feature ngoam
Cisco says it deployed and successfully tested this mitigation in a test environment. Customers are instructed to evaluate its suitability and operational effect in their own networks before applying it.
Cisco also recommends disabling NX-API or MPLS OAM when they are not required. Both are disabled by default on the relevant Nexus switches.
Temporary Live Protect shields are available for all five flaws. Cisco characterizes these shields as interim protection while an upgrade is being scheduled, not as a substitute for fixed software. The company also warns that mitigations can affect network functionality or performance depending on the deployment.
Cisco reported no known exploitation at publication
Cisco says all five vulnerabilities were identified through internal security testing. When the advisories were published, Cisco PSIRT was not aware of public announcements or malicious use involving the flaws.
That statement describes Cisco’s knowledge at publication. It does not establish what may have happened subsequently.
Separate Cisco License flaws require another upgrade
The same security release cycle also included hardening updates for Cisco License, formerly Smart Software Manager. These issues are separate from the five NX-OS vulnerabilities and, according to the report describing them, affect vulnerable releases regardless of configuration.
The four flaws are:
- CVE-2026-76480, missing authentication for critical functions, scored 9.8
- CVE-2026-76482, improper cryptographic signature verification, scored 10.0
- CVE-2026-76483, insufficiently protected credentials, scored 9.1
- CVE-2026-76484, code injection, scored 8.8
According to the report, Cisco recommends upgrading Cisco License to version 10-202609; no workarounds are available. Older releases carrying the Smart Software Manager branding will not receive patches for these flaws, so Cisco recommends migrating those installations to a supported release.




