Skip to content

Security2 publishersIndependently confirmed2 min readPublished

Cisco's five critical Nexus flaws only reach switches running NX-API, NGOAM or MPLS OAM

Cisco patched five critical NX-OS flaws that can give attackers root code execution or force reloads on Nexus 3000 and 9000 switches. Each one needs NX-API, NGOAM or MPLS OAM turned on, so a switch's feature configuration decides its exposure before its software version does.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying Cisco's five critical Nexus flaws only reach switches running NX-API, NGOAM or MPLS OAM
Generated illustration

What happened

  • Two of the flaws, CVE-2026-76471 and CVE-2026-76465, can be exploited by remote attackers without authentication, SecurityWeek reported.
  • Three others, CVE-2026-76485, CVE-2026-76486 and CVE-2026-76501, are triggered by crafted packets sent to an IP interface and need NGOAM enabled.
  • Nexus 7000 switches and Nexus 9000 switches running in ACI mode are not affected by any of the five, according to Cisco.
  • Cisco found all five in internal testing and said it knew of no public disclosure or malicious exploitation when it published the advisories.
  • Cisco offers temporary Live Protect shields for all five flaws, aimed at switches that cannot yet be upgraded and rebooted.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Because NX-API and MPLS OAM ship disabled, the switches carrying an unauthenticated path to root are the ones where an operator turned those features on.
  • decision Where NGOAM, NX-API and MPLS OAM are unused, a configuration change closes all five paths before any upgrade-and-reboot window has to be booked.
  • contradiction A clean feature audit still leaves CVE-2026-76455 and CVE-2026-76459, the two critical NX-OS entries in SecurityWeek's count that fall outside BleepingComputer's five.

Two of the three gating features ship turned off. NX-API is disabled by default [7], and MPLS OAM has to be explicitly activated [10]. The sources do not state NGOAM's default.

CVE-2026-76471 takes a crafted HTTP request sent to NX-API [7]. The MPLS flaw, CVE-2026-76465, takes a crafted MPLS echo-request packet sent to the device's IP address [10]. Nexus 9000 switches built on Silicon One ASICs do not support MPLS OAM and are not affected by that one [11].

Beyond NGOAM itself [3], two of the three NGOAM bugs carry extra conditions. CVE-2026-76486 also needs SRv6 or NV Overlay [8]. For the NV Overlay path, Cisco's advisory requires an EVPN VXLAN Network Identifier mapped to a Network Virtualization Endpoint interface, with at least one peer VXLAN Tunnel Endpoint learned, for example through BGP EVPN or a static ingress-replication peer [8]. CVE-2026-76501 needs SRv6 turned on, and only some Nexus 9000 models support SRv6 [9]. On a Nexus 3000, or a Nexus 9000 without SRv6 support, CVE-2026-76501 has no path and CVE-2026-76486 is reachable only through NV Overlay [19]. All five apply to Nexus 3000 and 9000 switches in standalone NX-OS mode [6].

The two reports count the batch differently. BleepingComputer's account covers the five feature-gated flaws [1]. SecurityWeek counts 14 NX-OS fixes, seven of them critical, among 35 vulnerabilities Cisco announced on Wednesday [5] [16]. The two extra critical entries, CVE-2026-76455 and CVE-2026-76459, group multiple improper access control and out-of-bounds write flaws, SecurityWeek reported [5]. Neither is in the NX-API, NGOAM and MPLS OAM set [17].

Cisco recommends moving to a fixed release, identified through its Software Checker, and disabling NGOAM, NX-API or MPLS OAM where they are not needed, to eliminate the attack vector [13].

What to watch

  • Any report of exploitation or a public proof of concept for CVE-2026-76471 or CVE-2026-76465, the two flaws SecurityWeek describes as reachable without authentication.
  • Cisco's stated preconditions for CVE-2026-76455 and CVE-2026-76459, the two critical NX-OS CVEs outside the feature-gated five.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence72
Adoption
Insufficient
Hype gap+20
Incentives
Insufficient
Confidence68
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Cisco released security advisories for five critical vulnerabilities in NX-OS that could be exploited to run arbitrary code with root privileges on Nexus switches.

  2. [2]

    If remote code execution cannot be achieved, an attacker could exploit the vulnerabilities to crash processes and force the device to reload, causing a denial-of-service condition.

  3. [3]

    CVE-2026-76485, CVE-2026-76486 and CVE-2026-76501 involve improper validation of IP traffic, are exploitable through crafted packets sent to an IP interface, and all require NGOAM to be enabled.

Sources

2 independent publishers whose own reporting we read for this story.

  1. bleepingcomputer.com

    1 article · October 8, 2026

    Cisco warns of critical flaws allowing Nexus switch takeover
  2. securityweek.com

    1 article · October 8, 2026

    Cisco Patches a Dozen Critical Vulnerabilities

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Entities

Loading related stories