Cisco has issued a warning regarding five critical vulnerabilities identified in its NX-OS data center network operating system, which could enable attackers to execute arbitrary code with root privileges on Nexus switches. In scenarios where remote code execution is not achievable, exploitation of these flaws could lead to process crashes and device reloads, resulting in denial-of-service conditions.
The vulnerabilities affect Nexus 3000 and Nexus 9000 Series switches operating in standalone NX-OS mode. Their successful exploitation is contingent upon the activation of specific features: NX-API, Next Generation OAM (NGOAM), or MPLS OAM. All five issues stem from insufficient input validation.
CVE-2026-76471, rated 9.8 on the CVSS scale, is exploitable via a specially crafted HTTP request sent to the NX-API, a feature that is disabled by default.
Three vulnerabilities—CVE-2026-76485 (CVSS 9.8), CVE-2026-76486 (CVSS 9.8), and CVE-2026-76501 (CVSS 9.8)—involve improper validation of IP traffic. These can be exploited by sending crafted packets to an IP interface, and all three require NGOAM to be enabled. Specifically, exploiting CVE-2026-76486 also necessitates the enablement of either Segment Routing over IPv6 (SRv6) or Network Virtualization (NV) Overlay. For NV Overlay, a VXLAN Ethernet VPN (EVPN) VXLAN Network Identifier (VNI) must be mapped to a Network Virtualization Endpoint (NVE) interface with at least one learned peer VXLAN Tunnel Endpoint (VTEP), such as through BGP EVPN or an ingress-replication static peer. CVE-2026-76501 is exploitable if SRv6, which is only supported on certain Nexus 9000 models, is active.
The fifth vulnerability, CVE-2026-76465 (CVSS 9.8), concerns improper validation of MPLS echo-request packets. It can be exploited by sending a crafted request to an affected device's IP address, requiring MPLS OAM to be explicitly activated, as it is disabled by default. Nexus 9000 switches equipped with Silicon One ASICs are not affected by this particular flaw, as they do not support the feature.
Cisco has confirmed that Nexus 7000 switches and Nexus 9000 switches operating in ACI mode are not susceptible to any of these five vulnerabilities.
The company recommends upgrading NX-OS releases to a patched version, which can be identified using Cisco's Software Checker tool. As a mitigating measure, Cisco advises disabling NGOAM, NX-API, or MPLS OAM features if they are not essential, thereby removing the potential attack vector. For switches that cannot be immediately upgraded or rebooted, Cisco has also provided temporary Live Protect shields for all five flaws.
These vulnerabilities were discovered during internal security testing by Cisco, and the company stated it had no knowledge of public disclosures or malicious exploitation at the time its advisories were published.
In addition to the Nexus flaws, Cisco also released security hardening updates for Cisco License, formerly known as Smart Software Manager. These updates address several issues, including missing authentication for critical functions (CVE-2026-76480, CVSS 9.8), improper cryptographic signature verification (CVE-2026-76482, CVSS 10.0), insufficiently protected credentials (CVE-2026-76483, CVSS 9.1), and code injection (CVE-2026-76484, CVSS 8.8). Affected releases are vulnerable regardless of their configuration. Cisco recommends upgrading to version 10-202609, noting that no workarounds are available for these specific issues. Older releases branded as Smart Software Manager will not receive patches, and users are advised to migrate to a supported release.






