Five critical Cisco NX-OS flaws give root on Nexus switches
Cisco fixed five CVSS 9.8 flaws in NX-OS NGOAM, MPLS OAM and NX-API. Who is exposed, how to check each switch, and what to switch off today.
By Yaali. October 9, 2026, 6 min read, Vulnerabilities, Patching.
On October 7, Cisco published three critical advisories covering five vulnerabilities in NX-OS, the operating system of its Nexus 3000 and Nexus 9000 data center switches. All five are rated CVSS 9.8. Each lets an attacker with no account send crafted network traffic to a switch and run code as root, or crash a process badly enough to reload the switch. The flaws sit in three optional features: NGOAM (CVE-2026-76485, CVE-2026-76486, CVE-2026-76501), MPLS OAM (CVE-2026-76465) and NX-API (CVE-2026-76471).
You are affected if you run a Nexus 3000 or a Nexus 9000 in standalone NX-OS mode and one of those features is enabled. Nexus 9000 switches in ACI mode, Nexus 7000 and MDS 9000 are not. Cisco found the bugs in internal testing and says it knows of no public exploit or attacks. That gives you a window, but a root shell on a spine or leaf switch is a strong position inside a data center, and these switches tend to be patched far less often than servers.

How it works
OAM (Operation, Administration and Maintenance) features are the switch's own troubleshooting tools: they answer ping and traceroute probes that run across an overlay network, so operators can see where a path breaks. Because they have to answer probes from other devices, they parse packets that arrive from the network on the switch's data plane interfaces, not only on the management port.
NGOAM, Cisco's name for VXLAN OAM, is where three of the flaws live. Cisco's advisory describes improper input validation of IP traffic that reaches an IP interface while NGOAM is on, and the CVE record classes CVE-2026-76485 as a stack-based buffer overflow (CWE-121). That one needs only NGOAM. CVE-2026-76486 also needs SRv6 (Segment Routing over IPv6) or NV Overlay, the feature behind VXLAN tunnel endpoints. CVE-2026-76501 is in the SRv6 OAM code and needs NGOAM plus SRv6, which Nexus 3000 does not support and only some Nexus 9000 models do.
The MPLS OAM flaw, CVE-2026-76465, is triggered by a crafted MPLS echo-request, the packet that MPLS ping and traceroute send, aimed at any IP address on the switch. Cisco files it under CWE-590, freeing memory that was not allocated on the heap. MPLS OAM is off by default, and Nexus 9000 models with a Silicon One ASIC cannot turn it on.
NX-API is the switch's HTTP and HTTPS interface for automation tools, which send CLI commands as JSON or XML. CVE-2026-76471 is a heap-based buffer overflow (CWE-122) reached by a crafted HTTP request before any login. NX-API is also off by default, but automation projects often enable it. The same bug exists on UCS 6300 Series fabric interconnects, where it can only be reached through the UCS Manager XML API with a low-privileged login, so Cisco rates it High there.
In every case the vulnerable process runs as root, so a successful overflow gives the attacker full control of the switch operating system. A failed attempt usually crashes the process and can reload the switch, which is an outage in its own right.
What attackers are doing
Nothing has been reported so far. Cisco's Product Security Incident Response Team (PSIRT) says it is not aware of public announcements or malicious use of any of the five. All five came out of Cisco's own security testing, no outside researcher is credited, and no exploit details or proof-of-concept code have been published.
Nexus switches have been targeted before. In 2024 the China-linked group Velvet Ant exploited CVE-2024-20399, an NX-OS command injection flaw, as a zero-day to run custom malware on the switches' underlying Linux, and Sygnia, which found it, noted that switch logs were rarely forwarded to central logging. That flaw required an administrator login. Anyone who can send packets to an exposed switch can try these five, once someone has compared the fixed releases with the vulnerable ones.
What to do

1. Find exposed switches
On each Nexus 3000 and standalone Nexus 9000, run show feature | include ngoam, show feature | include mpls_oam and show feature | include nxapi. For NGOAM switches, also run show feature | include nve and show feature | include srv6 to see which of the three NGOAM CVEs apply. A switch with none of the three features enabled is outside these advisories.
Cisco's CVE records list every release in the 9.3, 10.3, 10.4, 10.5 and 10.6 trains as affected, up to 9.3(17), 10.4(7), 10.5(5), 10.6(3) and 10.6(3s), plus 9.2(1) to 9.2(4) for the NGOAM and NX-API flaws.
2. If you cannot upgrade today
Cisco says no workaround keeps these features working while removing the flaw. If a feature is not in use, turn it off in global configuration mode: no feature ngoam removes the attack path for all three NGOAM CVEs and no feature mpls oam for the MPLS OAM one. Cisco tested both in its lab and asks customers to test them on their own network first, since disabling NGOAM also removes VXLAN OAM troubleshooting.
Where a feature has to stay on, Cisco has released Live Protect shields for all five CVEs. These are temporary mitigations that load into a running switch; check the download page for your release, since the MPLS OAM shield is published for 10.6(3). For NX-API, also bind it to the management VRF with nxapi use-vrf management and allow only your automation hosts to reach it. That does not fix the bug, but it shrinks the set of machines that can send the request.
3. Upgrade
None of the three advisories names fixed releases in its text. Cisco points to its Software Checker, which gives the first fixed release for your version. The NX-OS Security Hardening Release advisory published the same day, which fixes six further NX-OS bugs rated up to 9.8, lists 10.3(10), 10.4(8), 10.5(6) and 10.6(4) for Nexus 3000 and 9000. Releases older than 10.3 must migrate to a supported train. For UCS 6300 on 4.3, the NX-API fix is 4.3(6j) under UCS Manager.
4. Check whether a switch was touched
Cisco has published no indicators. On switches that had a vulnerable feature on, run show system reset-reason and show cores to look for unexplained reloads or process crashes, and show accounting log for configuration changes nobody made. Compare show running-config | include username against your list of local accounts. Because root access lets an attacker edit local logs, check the copies on your syslog server and your TACACS+ or RADIUS accounting records as well. If something does not add up, reinstall NX-OS from a verified image on a fixed release and rotate local passwords, SNMP communities and any keys stored in the configuration.
The wider lesson
Most switch hardening guides focus on the management plane: SSH, SNMP, the management port. These five flaws are reached through OAM probes on data plane interfaces and through an automation API that was switched on for a project and left running. A switch with NGOAM, MPLS OAM and NX-API turned off was never exposed to any of the five, so an inventory of which optional features are on, per switch, is worth keeping and pruning.
Our network penetration tests check which switch services and APIs can be reached from user and server networks, and our safeguarding and hardening work trims feature sets and access on network gear. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would do the work.
Sources: Cisco advisory: NGOAM, Cisco advisory: MPLS OAM, Cisco advisory: NX-API, Cisco NX-OS hardening release, October 2026, Cisco advance notice for October 7, 2026, CVE-2026-76485 record, BleepingComputer, Threat Frontier, Security Affairs on CVE-2024-20399.
Read next
- Android October 2026 patches: set the right MDM rules
- Splunk CVE-2026-76268: no-login commands via Patroni
- NetScaler SAML flaw gets a CVE and a fix: upgrade again
Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.