Protect.Computer
NEWS

Cisco Patches Five Critical NX-OS Flaws in Nexus Switches

· 1 min read · Network safety Device safety
Cisco Patches Five Critical NX-OS Flaws in Nexus Switches

Cisco has published advisories for five critical vulnerabilities in NX-OS, the operating system of its data center Nexus switches. Each flaw is a validation failure that could let an attacker run arbitrary code as root, or failing that, crash processes and force the switch to reload, causing a denial of service. The bugs sit in three features: NX-API, Next Generation OAM (NGOAM) and MPLS OAM, and affect Nexus 3000 and 9000 Series switches in standalone NX-OS mode.

Exploitation depends on one of those features being active. CVE-2026-76471 is triggered by a crafted HTTP request to NX-API, which is disabled by default. CVE-2026-76485, CVE-2026-76486 and CVE-2026-76501 involve crafted packets sent to an IP interface and require NGOAM; CVE-2026-76486 additionally needs SRv6 or NV Overlay, and CVE-2026-76501 needs SRv6, which only some Nexus 9000 models support. CVE-2026-76465 abuses MPLS echo-request packets and needs MPLS OAM, which is also off by default. Cisco says all five were found in internal testing and it knew of no public announcements or malicious exploitation when it published.

Separately, Cisco released hardening updates for Cisco License (formerly Smart Software Manager) covering CVE-2026-76480 (missing authentication, CVSS 9.8), CVE-2026-76482 (improper signature verification, CVSS 10.0), CVE-2026-76483 (insufficiently protected credentials, CVSS 9.1) and CVE-2026-76484 (code injection, CVSS 8.8). Those apply regardless of configuration, and no workarounds exist.

How to check if you’re affected

Affected products are Nexus 3000 and Nexus 9000 Series switches running standalone NX-OS with NX-API, NGOAM or MPLS OAM enabled. Cisco says Nexus 7000 switches and Nexus 9000 switches in ACI mode are not affected by these five flaws, and Nexus 9000 models with Silicon One ASICs do not support MPLS OAM and are unaffected by CVE-2026-76465. Check the running software version and the enabled features on each switch, then use Cisco’s Software Checker to find the fixed release for your version.

If you cannot upgrade right away, disable NX-API, NGOAM or MPLS OAM where they are not needed, or apply the temporary Live Protect shields Cisco provides for all five flaws. For Cisco License, upgrade to version 10-202609; older releases branded Smart Software Manager will not be patched, so migrate to a supported release.

Sources

Related reading