Build1 publisherNot yet confirmed elsewhere2 min readPublished
Five of Cisco's 11 new NX-OS flaws depend on NX-API or OAM being switched on
Cisco's four critical NX-OS advisories cover 11 CVEs across Nexus, MDS and UCS Fabric Interconnect hardware. Five need NX-API, MPLS OAM or NGOAM enabled while six apply in any configuration, so every affected switch still needs the fixed release.
The Engineer · Build desk
What happened
- Cisco PSIRT posted advance notice on September 30, 2026, and published the individual advisories on October 7.
- An attack reaches NX-API as a specially built HTTP request, MPLS OAM as an echo-request, or NGOAM as a specially built IP packet, and it can end with the switch crashing and reloading or with code running as root.
- Cisco lists no official workaround; a fixed release is the permanent remedy, with feature disabling and Live Protect shields offered as temporary mitigations.
- Cisco PSIRT reports no known malicious exploitation of these vulnerabilities.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- decision Exposure requires both an affected release and a reachable attack vector. Matching on version alone overstates exposure to the five gated CVEs on switches that have those features off.
- constraint Disabling the feature is listed as a mitigation only for MPLS OAM and NGOAM. A team that relies on NX-API for automation has to choose between a Live Protect shield and the upgrade.
- exposure Anyone who can send packets to the management plane or the OAM and data plane fits the attacker model. Any segment that can reach OAM traffic without filtering adds to the set of hosts that can reach these bugs.
Each of the five gated CVEs has its own precondition, according to a dev.to summary of Cisco's PSIRT notice [21]. CVE-2026-76465 requires MPLS OAM enabled on a Nexus 3000 or 9000 in standalone mode [8]. NX-API is the gate for CVE-2026-76471 on the same two platforms [12]. CVE-2026-76485 needs only NGOAM on the target model [9]. For CVE-2026-76501, NGOAM and SRv6 must both be on, and the Nexus 3000 does not support SRv6 [11].
CVE-2026-76486 has the most preconditions. It needs NGOAM plus either SRv6 or NV Overlay [10]. On the overlay path it also needs a VNI mapped to the NVE interface and at least one learned peer VTEP [10]. That is specific enough to rule a switch in or out from its configuration and its peer table, and Cisco deserves credit for writing it down. A VXLAN leaf in a running fabric meets the condition, while a switch staged with the features on and no learned peers does not [10].
Authentication requirements vary by CVE and product [5]. The summary says some of the bugs can potentially lead to pre-authentication root code execution [5]. It also says the individual bugs should not be treated as uniform pre-authentication network RCEs [6]. The UCS 6300 Fabric Interconnect shows the difference. Its path to the NX-API bug goes through the UCS Manager XML API and needs valid low-privileged credentials [12]. The summary does not set out the authentication requirement for each remaining CVE.
Disabling an unneeded OAM feature removes the precondition for four of the five gated CVEs: 76465 on MPLS OAM, and 76485, 76486 and 76501 on NGOAM [22]. For the six hardening CVEs, the remedy in the summary is the fixed release [7][14]. Successful code execution could let an attacker change device configuration or interfere with traffic [19]. The summary advises limiting reachability to the management and OAM planes with ACLs and segmentation [15].
Administrators can watch for abnormal NX-API requests, OAM packets, process crashes, core dumps and switch reloads [17]. The summary's hunting checklist also includes an email row. It reports that no email vector specific to these bugs has been confirmed [18].
What to watch
- The fixed-release tables in Cisco's four October 7 advisories, broken out by platform and NX-OS train.
- Any change to Cisco PSIRT's statement that it knows of no malicious exploitation of the 11 CVEs.
- Per-CVE authentication requirements in the full advisories, confirming which bugs are reachable before login.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Cisco published four critical advisories covering a total of 11 CVEs for NX-OS.
- [2]
Affected products are Cisco NX-OS, Nexus 3000, Nexus 7000, Nexus 9000 (standalone and ACI mode), MDS 9000 and UCS Fabric Interconnect.
- [3]
Cisco PSIRT published an advance notification on September 30, 2026; the individual advisories were published October 7, 2026.
- [4]
An attacker sends a crafted HTTP request to NX-API, an echo-request to MPLS OAM, or a crafted IP packet to NGOAM; successful exploitation may allow arbitrary code execution with root privileges or cause a process crash, and a crash may cause a device reload and denial of service.
- [5]
Severity levels, authentication requirements and configuration conditions vary by CVE and product, with some vulnerabilities potentially leading to pre-authentication root code execution or denial of service.
- [6]
Individual bugs are not treated as uniform pre-authentication network RCEs.
- [7]
The six hardening CVEs affect target products regardless of device configuration.
- [8]
CVE-2026-76465 requires MPLS OAM to be enabled on the target Nexus 3000 or 9000 standalone device.
- [9]
CVE-2026-76485 requires NGOAM to be enabled on the target model.
- [10]
CVE-2026-76486 requires SRv6 or NV Overlay to be enabled in addition to NGOAM; for the NV Overlay path, VNI mapping to the NVE interface and the learning of at least one peer VTEP are also required.
- [11]
CVE-2026-76501 requires both NGOAM and SRv6 to be enabled; the Nexus 3000 does not support SRv6.
- [12]
CVE-2026-76471 requires NX-API to be enabled on Nexus 3000 or 9000 standalone devices; for UCS 6300, the attack routes through the UCS Manager XML API and requires valid low-privileged credentials.
- [13]
The attacker is a remote attacker capable of sending packets to the management plane or the OAM/data plane.
- [14]
The permanent remediation is updating to a fixed release; official workarounds are not available, but disabling unnecessary MPLS OAM and NGOAM features and applying Live Protect shields that meet the conditions for MPLS OAM, NGOAM and NX-API are offered as temporary mitigations.
- [15]
The summary advises minimizing reachability to the management and OAM planes and restricting exposure using ACLs and segmentation.
- [16]
Cisco PSIRT reports no known malicious exploitation of these vulnerabilities.
- [17]
Administrators can observe abnormal NX-API requests, OAM packets, process crashes, core dumps and switch reloads.
- [18]
No email vectors specific to this issue have been confirmed.
- [19]
Successful code execution could enable subsequent changes to device configuration or interference with traffic.
- [20]
The common condition is using an affected product release described in each advisory and being able to reach the attack vector.
- [21]
Five of the 11 CVEs are feature-gated: CVE-2026-76465, 76471, 76485, 76486 and 76501.
- [22]
MPLS OAM or NGOAM is the precondition for four of the five gated CVEs; NX-API gates the fifth.
Sources
1 independent publisher whose own reporting we read for this story.
- dev.toCisco NX-OS: Four Critical Advisories Cover 11 CVEs, Including Root RCE and DoS
1 article · October 8, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.