Cisco Warns of Five Critical NX-OS Flaws That Could Enable Root-Level Takeover of Nexus Switches
Cisco has released a security advisory warning of five critical vulnerabilities in its NX-OS data center operating system. Attackers could exploit the flaws to execute arbitrary code with root privileges on vulnerable Nexus switches.
Even without achieving remote code execution, successful exploitation could crash a process and force an affected device to reload, causing a denial-of-service condition.
The vulnerabilities affect Cisco Nexus 3000 and Nexus 9000 Series switches running in standalone NX-OS mode. Exploitation depends on specific features being enabled, including NX-API, Next-Generation OAM (NGOAM), or MPLS OAM.
Five critical Cisco NX-OS vulnerabilities
All five vulnerabilities stem from input or traffic-validation failures. At least one of the affected features must be active on a vulnerable device:
-
CVE-2026-76471:
Insufficient input validation in NX-API could allow exploitation through a specially crafted HTTP request. NX-API is disabled by default. -
CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501:
Improper validation of IP traffic could allow exploitation through specially crafted packets sent to an IP interface. NGOAM must be enabled. -
CVE-2026-76465:
Improper validation of MPLS echo request packets could allow exploitation through a specially crafted request sent to the IP address of an affected device.
Additional configuration requirements
Exploitation of CVE-2026-76486 also requires Segment Routing over IPv6 (SRv6) or Network Virtualization (NV) overlays to be enabled.
Cisco says an NV overlay must also use a VXLAN Ethernet VPN (EVPN) VXLAN network identifier (VNI) mapped to a network virtualization endpoint (NVE) interface with at least one learned peer VXLAN tunnel endpoint (VTEP), such as a BGP EVPN or ingress-replication static peer.
CVE-2026-76501 can be exploited when SRv6 is enabled. SRv6 is supported only on some Nexus 9000 models.
MPLS OAM is disabled by default and must be explicitly enabled for CVE-2026-76465 to be exploitable. Nexus 9000 switches using Silicon One ASICs do not support MPLS OAM and are not affected by this vulnerability.
Which Cisco switches are affected?
Cisco says Nexus 3000 and Nexus 9000 Series switches operating in standalone NX-OS mode may be affected when the relevant features are enabled. Nexus 7000 switches and Nexus 9000 switches operating in ACI mode are not affected by any of the five vulnerabilities.
Cisco urges customers to upgrade NX-OS
Cisco recommends upgrading affected switches to a fixed NX-OS release. Administrators can identify the appropriate version using the vendor’s Software Checker tool.
When the features are not required, Cisco recommends disabling NGOAM, NX-API, and MPLS OAM to remove the corresponding attack vectors.
Cisco also provides temporary Live Protect shields for all five vulnerabilities for switches that cannot yet be upgraded and rebooted. More information is available in the company’s Live Protect documentation.
The vulnerabilities were discovered during Cisco’s internal security testing. The company said it was not aware of any public disclosure or malicious exploitation when the advisory was published.
Cisco also patches Smart Software Manager flaws
In addition to the Nexus NX-OS vulnerabilities, Cisco released security enhancement updates for Cisco Licensing, formerly known as Smart Software Manager.
The issues include a lack of authentication for critical functionality (CVE-2026-76480, CVSS 9.8), improper cryptographic signature validation (CVE-2026-76482, CVSS 10.0), insufficiently protected credentials (CVE-2026-76483, CVSS 9.1), and code injection (CVE-2026-76484, CVSS 8.8).
Affected releases are vulnerable regardless of configuration, so Cisco says there is no workaround and recommends upgrading to version 10-202609.
Older releases branded as Smart Software Manager will not receive patches for these defects. Cisco recommends migrating to a supported release.
For a complete list of the security advisories released by Cisco, visit the company’s security advisory listing.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



