Five critical Cisco Nexus vulnerabilities could allow unauthenticated attackers to execute code with root privileges on affected switches, threatening enterprise data center operations.
Cisco disclosed the flaws on October 7, 2026, in three NX-OS security advisories. All five carry a CVSS score of 9.8 and affect Nexus 3000 and 9000 Series switches running vulnerable software with specific features enabled.
Successful exploitation could trigger remote code execution, process crashes or switch reloads. Cisco's security response team said it was unaware of malicious exploitation or public announcements involving the flaws. A separate Cisco Secure Email Gateway zero-day disclosed in September was already under active attack.
Exposure depends on the installed NX-OS release, operating mode and enabled features. Administrators must verify these conditions before prioritizing remediation.
Five flaws affect specific Nexus configurations
The vulnerabilities involve three NX-OS features: Next Generation Operation, Administration, and Maintenance (NGOAM); MPLS OAM; and NX-API.
Cisco's NGOAM advisory identifies three vulnerabilities:
- CVE-2026-76485: Requires NGOAM to be enabled.
- CVE-2026-76486: Requires NGOAM plus Segment Routing over IPv6 (SRv6) or a qualifying NV Overlay configuration.
- CVE-2026-76501: Requires NGOAM and SRv6.
The MPLS OAM flaw, CVE-2026-76465, requires MPLS OAM. The NX-API vulnerability, CVE-2026-76471, could allow code execution through crafted HTTP requests when NX-API is enabled.
The flaws affect Nexus 3000 and standalone NX-OS Nexus 9000 switches, but not Nexus 7000 or ACI-mode Nexus 9000 devices. Nexus 3000 switches lack SRv6 support, while Nexus 9000 models using Silicon One ASICs cannot enable MPLS OAM.
CVE-2026-76471 also affects UCS 6300 Series Fabric Interconnects, although exploitation requires valid low-privileged credentials and is rated High on that platform.
Other Cisco infrastructure vulnerabilities have already been exploited. In September, attackers used separate Cisco Firewall Management Center vulnerabilities to steal credentials and access internal networks. Cisco has reported no comparable exploitation of these newly disclosed Nexus flaws.
Exposure checks and mitigation priorities
Administrators can check the relevant NX-OS features using these commands:
| Feature | Command |
|---|---|
| NGOAM | show feature | include ngoam |
| MPLS OAM | show feature | include mpls_oam |
| NX-API | show feature | include nxapi |
| SRv6 | show feature | include srv6 |
| NV Overlay | show feature | include nve |
CVE-2026-76486 also requires specific VXLAN EVPN VNI mappings and a learned tunnel endpoint peer for its NV Overlay attack path. Enabled features alone do not confirm exposure without verifying the software release.
Cisco recommends upgrading to fixed software. Organizations should:
- Verify exposure and patch. Use Cisco's Software Checker to identify affected releases and appropriate fixes.
- Disable unnecessary features. Apply
no feature ngoamorno feature mpls oamwhere operationally appropriate. - Deploy temporary protections. Use Cisco's supported Live Protect shields until fixed software is installed. These temporary protections are documented in Cisco's security advisories.
- Restrict access. Isolate management interfaces, enforce least privilege and limit traffic to affected interfaces.
- Strengthen monitoring and resilience. Review logs, maintain backups and verify redundancy. An earlier Cisco ASA and FTD flaw demonstrated how remote restarts can disrupt network availability.
- Test incident response plans. Exercise switch isolation, compromise investigation, configuration restoration and service recovery.
Feature changes require operational assessment, and temporary mitigations do not replace software updates. Teams should confirm that fixes address all applicable CVEs and verify network functionality after upgrading.
Read more: An actively exploited Check Point management vulnerability highlights the importance of protecting privileged network infrastructure and checking for compromise.





