Security2 publishersIndependently confirmed2 min readPublished
Cisco's five critical Nexus flaws only reach switches running NX-API, NGOAM or MPLS OAM
Cisco patched five critical NX-OS flaws that can give attackers root code execution or force reloads on Nexus 3000 and 9000 switches. Each one needs NX-API, NGOAM or MPLS OAM turned on, so a switch's feature configuration decides its exposure before its software version does.
The Watch · Security desk

What happened
- Two of the flaws, CVE-2026-76471 and CVE-2026-76465, can be exploited by remote attackers without authentication, SecurityWeek reported.
- Three others, CVE-2026-76485, CVE-2026-76486 and CVE-2026-76501, are triggered by crafted packets sent to an IP interface and need NGOAM enabled.
- Nexus 7000 switches and Nexus 9000 switches running in ACI mode are not affected by any of the five, according to Cisco.
- Cisco found all five in internal testing and said it knew of no public disclosure or malicious exploitation when it published the advisories.
- Cisco offers temporary Live Protect shields for all five flaws, aimed at switches that cannot yet be upgraded and rebooted.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Because NX-API and MPLS OAM ship disabled, the switches carrying an unauthenticated path to root are the ones where an operator turned those features on.
- decision Where NGOAM, NX-API and MPLS OAM are unused, a configuration change closes all five paths before any upgrade-and-reboot window has to be booked.
- contradiction A clean feature audit still leaves CVE-2026-76455 and CVE-2026-76459, the two critical NX-OS entries in SecurityWeek's count that fall outside BleepingComputer's five.
Two of the three gating features ship turned off. NX-API is disabled by default [7], and MPLS OAM has to be explicitly activated [10]. The sources do not state NGOAM's default.
CVE-2026-76471 takes a crafted HTTP request sent to NX-API [7]. The MPLS flaw, CVE-2026-76465, takes a crafted MPLS echo-request packet sent to the device's IP address [10]. Nexus 9000 switches built on Silicon One ASICs do not support MPLS OAM and are not affected by that one [11].
Beyond NGOAM itself [3], two of the three NGOAM bugs carry extra conditions. CVE-2026-76486 also needs SRv6 or NV Overlay [8]. For the NV Overlay path, Cisco's advisory requires an EVPN VXLAN Network Identifier mapped to a Network Virtualization Endpoint interface, with at least one peer VXLAN Tunnel Endpoint learned, for example through BGP EVPN or a static ingress-replication peer [8]. CVE-2026-76501 needs SRv6 turned on, and only some Nexus 9000 models support SRv6 [9]. On a Nexus 3000, or a Nexus 9000 without SRv6 support, CVE-2026-76501 has no path and CVE-2026-76486 is reachable only through NV Overlay [19]. All five apply to Nexus 3000 and 9000 switches in standalone NX-OS mode [6].
The two reports count the batch differently. BleepingComputer's account covers the five feature-gated flaws [1]. SecurityWeek counts 14 NX-OS fixes, seven of them critical, among 35 vulnerabilities Cisco announced on Wednesday [5] [16]. The two extra critical entries, CVE-2026-76455 and CVE-2026-76459, group multiple improper access control and out-of-bounds write flaws, SecurityWeek reported [5]. Neither is in the NX-API, NGOAM and MPLS OAM set [17].
Cisco recommends moving to a fixed release, identified through its Software Checker, and disabling NGOAM, NX-API or MPLS OAM where they are not needed, to eliminate the attack vector [13].
What to watch
- Any report of exploitation or a public proof of concept for CVE-2026-76471 or CVE-2026-76465, the two flaws SecurityWeek describes as reachable without authentication.
- Cisco's stated preconditions for CVE-2026-76455 and CVE-2026-76459, the two critical NX-OS CVEs outside the feature-gated five.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence68
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Cisco released security advisories for five critical vulnerabilities in NX-OS that could be exploited to run arbitrary code with root privileges on Nexus switches.
- [2]
If remote code execution cannot be achieved, an attacker could exploit the vulnerabilities to crash processes and force the device to reload, causing a denial-of-service condition.
- [3]
CVE-2026-76485, CVE-2026-76486 and CVE-2026-76501 involve improper validation of IP traffic, are exploitable through crafted packets sent to an IP interface, and all require NGOAM to be enabled.
- [4]
All five vulnerabilities were found during Cisco's internal security testing, and Cisco said it was unaware of public announcements or malicious exploitation when it published the advisories.
- [5]
NX-OS received fixes for 14 vulnerabilities, including seven critical-severity issues; multiple improper access control and out-of-bounds write flaws are grouped under CVE-2026-76455 and CVE-2026-76459.
- [6]
The five flaws affect Nexus 3000 and Nexus 9000 Series switches in standalone NX-OS mode; all are rooted in a validation failure and require at least one of NX-API, NGOAM or MPLS OAM to be active.
- [7]
CVE-2026-76471 is an insufficient input validation flaw exploitable through a crafted HTTP request sent to NX-API, a feature that is disabled by default.
- [8]
CVE-2026-76486 also requires SRv6 or NV Overlay to be enabled; per Cisco's advisory, NV Overlay requires a VXLAN EVPN VNI mapped to an NVE interface with at least one peer VTEP learned, for example via BGP EVPN or an ingress-replication static peer.
- [9]
CVE-2026-76501 is exploitable if SRv6 is turned on; SRv6 is supported only on some Nexus 9000 models.
- [10]
CVE-2026-76465 involves improper validation of MPLS echo-request packets, is exploitable through a crafted request sent to the device's IP address, and requires MPLS OAM, which is disabled by default and must be explicitly activated.
- [11]
Nexus 9000 switches with Silicon One ASICs do not support MPLS OAM and are unaffected by CVE-2026-76465.
- [12]
Nexus 7000 switches and Nexus 9000 switches in ACI mode are not affected by any of the five vulnerabilities.
- [13]
Cisco recommends upgrading to a fixed NX-OS release identified through its Software Checker, and disabling NGOAM, NX-API or MPLS OAM if not needed to eliminate the attack vector.
- [14]
Cisco provides temporary Live Protect shields for all five flaws, for switches that cannot yet be upgraded and rebooted.
- [15]
CVE-2026-76471 and CVE-2026-76465 could allow remote, unauthenticated attackers to execute arbitrary code with root privileges or cause a DoS condition.
- [16]
Cisco on Wednesday announced patches for 35 vulnerabilities across its products, including over a dozen critical-severity bugs.
- [17]
Of the seven critical NX-OS CVEs SecurityWeek lists, five are the feature-gated flaws; the remaining two, CVE-2026-76455 and CVE-2026-76459, are not among the NX-API, NGOAM and MPLS OAM set.
- [18]
Both flaws SecurityWeek describes as remotely exploitable without authentication, CVE-2026-76471 and CVE-2026-76465, depend on features disabled by default (NX-API and MPLS OAM).
- [19]
On a Nexus 3000 or a Nexus 9000 without SRv6 support, CVE-2026-76501 has no exploitation path and CVE-2026-76486 is reachable only through NV Overlay.
- [20]
A Nexus 3000 or 9000 with NX-API, NGOAM and MPLS OAM all disabled is not exploitable through any of the five CVEs.
Sources
2 independent publishers whose own reporting we read for this story.
- bleepingcomputer.comCisco warns of critical flaws allowing Nexus switch takeover
1 article · October 8, 2026
- securityweek.comCisco Patches a Dozen Critical Vulnerabilities
1 article · October 8, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Vulnerability Disclosure and PatchingFollow
- Data Center NetworkingFollow
- Network Infrastructure SecurityFollow