Cisco issued security advisories regarding five critical vulnerabilities in the NX-OS network operating system, which is used in data center switches from the Nexus 3000 and Nexus 9000 series. The vulnerabilities could allow an attacker to execute arbitrary code with root privileges, or crash system processes and force the device to reload, resulting in a denial-of-service condition.
The issues do not affect all devices in the same way; exploitation requires at least one of the NX-API, Next Generation OAM (NGOAM), or MPLS OAM features to be enabled. The switches must also be operating in standalone NX-OS mode to be within the affected scope. Cisco said the vulnerabilities were discovered during internal security testing and that it was unaware of any public exploitation or exploitation in real-world attacks when the advisories were published.
Vulnerability Details and Exploitation Requirements
- CVE-2026-76471: An input-validation flaw that can be exploited through a specially crafted HTTP request to NX-API, a feature that is disabled by default.
- CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501: Errors in IP traffic validation that can be exploited through specially crafted packets when NGOAM is enabled.
- CVE-2026-76465: A flaw in the validation of MPLS echo-request packets, requiring MPLS OAM to be enabled, a feature that is disabled by default.
Exploitation of CVE-2026-76486 also requires Segment Routing over IPv6 (SRv6) or Network Virtualization (NV) Overlay to be enabled. CVE-2026-76501 requires SRv6 to be enabled, which is supported on only certain Nexus 9000 models. Nexus 7000 switches and Nexus 9000 switches operating in ACI mode are not affected by any of the five vulnerabilities. In addition, Nexus 9000 switches equipped with Silicon One chips do not support MPLS OAM and are therefore not affected by CVE-2026-76465.
What Should Network Administrators Do?
Cisco recommends upgrading NX-OS versions to patched releases using its Software Checker tool. If updating and rebooting the switch immediately is not possible, the company provides temporary protection called Live Protect for all five vulnerabilities. Cisco also recommends disabling NX-API, NGOAM, or MPLS OAM when they are not operationally required, to remove the associated attack paths.
Additional Vulnerabilities in Cisco License
The security updates also included four issues in Cisco License, formerly known as Smart Software Manager. The issues include a lack of authentication for critical functions in CVE-2026-76480, with a CVSS score of 9.8; weak validation of cryptographic signatures in CVE-2026-76482, with a score of 10.0; insufficient protection of credentials in CVE-2026-76483, with a score of 9.1; and code injection in CVE-2026-76484, with a score of 8.8.
The affected versions are impacted regardless of their configuration, and no temporary workarounds are available for them. Cisco recommends upgrading to version 10-202609. Older versions bearing the Smart Software Manager name will not receive a fix, requiring migration to a supported version.
The practical significance of the advisory is that exploitability does not depend solely on the presence of a single flaw in a public-facing interface, but on specific operational combinations that may be necessary in data center environments. Network administrators therefore need to match enabled features and the NX-OS version against Cisco's guidance, rather than assuming that disabling NX-API alone addresses all cases.