LIVE · cybersecurity feed
Live wire
vulnerabilitycritical

Cisco warns of critical flaws allowing Nexus switch takeover

Cisco has issued a warning regarding five critical vulnerabilities identified in its NX-OS data center network operating system, which could enable attackers to execute arbitrary code with root privileges on Nexus switches. In scenarios where remote code execution is not achievable, exploitation of these flaws could lead to process crashes and device reloads, resulting in denial-of-service…

ZeroDay News ·

Source: BleepingComputer

Cisco has issued a warning regarding five critical vulnerabilities identified in its NX-OS data center network operating system, which could enable attackers to execute arbitrary code with root privileges on Nexus switches. In scenarios where remote code execution is not achievable, exploitation of these flaws could lead to process crashes and device reloads, resulting in denial-of-service conditions.

The vulnerabilities affect Nexus 3000 and Nexus 9000 Series switches operating in standalone NX-OS mode. Their successful exploitation is contingent upon the activation of specific features: NX-API, Next Generation OAM (NGOAM), or MPLS OAM. All five issues stem from insufficient input validation.

CVE-2026-76471, rated 9.8 on the CVSS scale, is exploitable via a specially crafted HTTP request sent to the NX-API, a feature that is disabled by default.

Three vulnerabilities—CVE-2026-76485 (CVSS 9.8), CVE-2026-76486 (CVSS 9.8), and CVE-2026-76501 (CVSS 9.8)—involve improper validation of IP traffic. These can be exploited by sending crafted packets to an IP interface, and all three require NGOAM to be enabled. Specifically, exploiting CVE-2026-76486 also necessitates the enablement of either Segment Routing over IPv6 (SRv6) or Network Virtualization (NV) Overlay. For NV Overlay, a VXLAN Ethernet VPN (EVPN) VXLAN Network Identifier (VNI) must be mapped to a Network Virtualization Endpoint (NVE) interface with at least one learned peer VXLAN Tunnel Endpoint (VTEP), such as through BGP EVPN or an ingress-replication static peer. CVE-2026-76501 is exploitable if SRv6, which is only supported on certain Nexus 9000 models, is active.

The fifth vulnerability, CVE-2026-76465 (CVSS 9.8), concerns improper validation of MPLS echo-request packets. It can be exploited by sending a crafted request to an affected device's IP address, requiring MPLS OAM to be explicitly activated, as it is disabled by default. Nexus 9000 switches equipped with Silicon One ASICs are not affected by this particular flaw, as they do not support the feature.

Cisco has confirmed that Nexus 7000 switches and Nexus 9000 switches operating in ACI mode are not susceptible to any of these five vulnerabilities.

The company recommends upgrading NX-OS releases to a patched version, which can be identified using Cisco's Software Checker tool. As a mitigating measure, Cisco advises disabling NGOAM, NX-API, or MPLS OAM features if they are not essential, thereby removing the potential attack vector. For switches that cannot be immediately upgraded or rebooted, Cisco has also provided temporary Live Protect shields for all five flaws.

These vulnerabilities were discovered during internal security testing by Cisco, and the company stated it had no knowledge of public disclosures or malicious exploitation at the time its advisories were published.

In addition to the Nexus flaws, Cisco also released security hardening updates for Cisco License, formerly known as Smart Software Manager. These updates address several issues, including missing authentication for critical functions (CVE-2026-76480, CVSS 9.8), improper cryptographic signature verification (CVE-2026-76482, CVSS 10.0), insufficiently protected credentials (CVE-2026-76483, CVSS 9.1), and code injection (CVE-2026-76484, CVSS 8.8). Affected releases are vulnerable regardless of their configuration. Cisco recommends upgrading to version 10-202609, noting that no workarounds are available for these specific issues. Older releases branded as Smart Software Manager will not receive patches, and users are advised to migrate to a supported release.

vulnerabilitycloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
breachcritical

Cisco Patches a Dozen Critical Vulnerabilities

Cisco has released patches addressing a dozen critical vulnerabilities across its product line. These security defects reportedly encompass a range of potential impacts, including unauthorized access, information leaks, privilege escalation, denial-of-service (DoS) attacks, and remote code execution (RCE). The widespread nature of these reported flaws suggests a significant security update…

vulnerability

Chasing AMMYY at Splunk .conf

A recent report detailed the detection of Flawed AMMYY RAT traffic at the Splunk .conf event, an incident uncovered through the combined capabilities of Cisco's Encrypted Visibility Engine (EVE) and Endace PCAP. The key takeaway from this discovery was the ability to identify this malicious activity without the need to decrypt TLS-encrypted communications, highlighting advancements in network…

malware

Midnight Mimosa Malware Found Preinstalled on Low-Cost Android Phones

Recent reports indicate that a new malware strain, dubbed "Midnight Mimosa," has been discovered preinstalled on certain low-cost Android smartphones. This finding suggests that some devices may be compromised with malicious software embedded directly into their firmware before they even reach consumers, posing a significant supply chain security risk.

malware

UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML

A Russia-aligned threat actor, UAC-0099, has reportedly been observed deploying a new .NET-based infostealer and remote access trojan (RAT) named ASHVEIN. This malware has been specifically used in attacks targeting Ukrainian government personnel. The cybersecurity firm TrendAI is tracking this activity cluster under the designation Earth Sirrush, which was previously known as SHADOW-EARTH-065.

cloud

Admin in the Loop: Firewalls and the Agentic SOC

A recent report details the integration of Cisco Secure Firewall and Cloud Control with Splunk ES, specifically highlighting its role in feeding structured Snort 3 and EVE telemetry into an "Agentic SOC pipeline." This integration is presented as a foundational element for advanced security operations, leveraging automated data streams for analysis and response.

ai

Who watches the AI watching your street?

Yusaku Fujii, a professor at Gunma University in Japan, has developed a system designed to audit and penalize the misuse of artificial intelligence that analyzes street camera footage. His proposal, called the Verifiable Record of AI Output (VRAIO), aims to ensure accountability for AI systems operating in what he terms Fully Monitored Public Spaces (FMPS), areas with dense camera coverage…