Skip to content

Build1 publisherNot yet confirmed elsewhere2 min readPublished

Five of Cisco's 11 new NX-OS flaws depend on NX-API or OAM being switched on

Cisco's four critical NX-OS advisories cover 11 CVEs across Nexus, MDS and UCS Fabric Interconnect hardware. Five need NX-API, MPLS OAM or NGOAM enabled while six apply in any configuration, so every affected switch still needs the fixed release.

The Engineer · Build desk

How we use AISend a correction

What happened

  • Cisco PSIRT posted advance notice on September 30, 2026, and published the individual advisories on October 7.
  • An attack reaches NX-API as a specially built HTTP request, MPLS OAM as an echo-request, or NGOAM as a specially built IP packet, and it can end with the switch crashing and reloading or with code running as root.
  • Cisco lists no official workaround; a fixed release is the permanent remedy, with feature disabling and Live Protect shields offered as temporary mitigations.
  • Cisco PSIRT reports no known malicious exploitation of these vulnerabilities.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • decision Exposure requires both an affected release and a reachable attack vector. Matching on version alone overstates exposure to the five gated CVEs on switches that have those features off.
  • constraint Disabling the feature is listed as a mitigation only for MPLS OAM and NGOAM. A team that relies on NX-API for automation has to choose between a Live Protect shield and the upgrade.
  • exposure Anyone who can send packets to the management plane or the OAM and data plane fits the attacker model. Any segment that can reach OAM traffic without filtering adds to the set of hosts that can reach these bugs.

Each of the five gated CVEs has its own precondition, according to a dev.to summary of Cisco's PSIRT notice [21]. CVE-2026-76465 requires MPLS OAM enabled on a Nexus 3000 or 9000 in standalone mode [8]. NX-API is the gate for CVE-2026-76471 on the same two platforms [12]. CVE-2026-76485 needs only NGOAM on the target model [9]. For CVE-2026-76501, NGOAM and SRv6 must both be on, and the Nexus 3000 does not support SRv6 [11].

CVE-2026-76486 has the most preconditions. It needs NGOAM plus either SRv6 or NV Overlay [10]. On the overlay path it also needs a VNI mapped to the NVE interface and at least one learned peer VTEP [10]. That is specific enough to rule a switch in or out from its configuration and its peer table, and Cisco deserves credit for writing it down. A VXLAN leaf in a running fabric meets the condition, while a switch staged with the features on and no learned peers does not [10].

Authentication requirements vary by CVE and product [5]. The summary says some of the bugs can potentially lead to pre-authentication root code execution [5]. It also says the individual bugs should not be treated as uniform pre-authentication network RCEs [6]. The UCS 6300 Fabric Interconnect shows the difference. Its path to the NX-API bug goes through the UCS Manager XML API and needs valid low-privileged credentials [12]. The summary does not set out the authentication requirement for each remaining CVE.

Disabling an unneeded OAM feature removes the precondition for four of the five gated CVEs: 76465 on MPLS OAM, and 76485, 76486 and 76501 on NGOAM [22]. For the six hardening CVEs, the remedy in the summary is the fixed release [7][14]. Successful code execution could let an attacker change device configuration or interfere with traffic [19]. The summary advises limiting reachability to the management and OAM planes with ACLs and segmentation [15].

Administrators can watch for abnormal NX-API requests, OAM packets, process crashes, core dumps and switch reloads [17]. The summary's hunting checklist also includes an email row. It reports that no email vector specific to these bugs has been confirmed [18].

What to watch

  • The fixed-release tables in Cisco's four October 7 advisories, broken out by platform and NX-OS train.
  • Any change to Cisco PSIRT's statement that it knows of no malicious exploitation of the 11 CVEs.
  • Per-CVE authentication requirements in the full advisories, confirming which bugs are reachable before login.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence55
Adoption
Insufficient
Hype gap+5
Incentives
Insufficient
Confidence55
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Cisco published four critical advisories covering a total of 11 CVEs for NX-OS.

    ReportedSupportedSource: dev.to summary of Cisco PSIRT advisoriesView cited source
  2. [2]

    Affected products are Cisco NX-OS, Nexus 3000, Nexus 7000, Nexus 9000 (standalone and ACI mode), MDS 9000 and UCS Fabric Interconnect.

    ReportedSupportedSource: dev.to summary of Cisco PSIRT advisoriesView cited source
  3. [3]

    Cisco PSIRT published an advance notification on September 30, 2026; the individual advisories were published October 7, 2026.

    ReportedSupportedSource: dev.to summary of Cisco PSIRT advisoriesView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. dev.to

    1 article · October 8, 2026

    Cisco NX-OS: Four Critical Advisories Cover 11 CVEs, Including Root RCE and DoS

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

  • Network infrastructure vulnerabilitiesFollow
  • Vendor Security AdvisoriesFollow

Entities

Loading related stories