RC RANDOM CHAOS

Cisco warns of five NX-OS bugs that reach root

Cisco patched five critical NX-OS flaws allowing root code execution on Nexus 3000 and 9000 switches, plus regardless-of-config Cisco License bugs.

· 3 min read
Cisco warns of five NX-OS bugs that reach root

Cisco published advisories for five critical vulnerabilities in NX-OS that let an attacker run arbitrary code as root on Nexus 3000 and Nexus 9000 switches in standalone NX-OS mode. Where full code execution isn’t reachable, the same bugs crash the target process and force the switch to reload, so the worst case if you escape remote code execution is still a denial of service on your data center fabric.

All five share one root cause: a validation failure in one of three features. The attack surface only exists if NX-API, Next Generation OAM (NGOAM), or MPLS OAM is active on the box, which is the good news here. A default-configured switch with none of these turned on has nothing to exploit.

The five CVEs and what each one needs

CVE-2026-76471 is insufficient input validation in NX-API, triggered by a crafted HTTP request. NX-API is disabled by default, so this one only matters where someone has deliberately enabled the programmatic interface.

CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501 all come from improper validation of IP traffic and fire on crafted packets sent to an IP interface. All three require NGOAM to be enabled. Two of them carry extra conditions on top of that. CVE-2026-76486 also needs either Segment Routing over IPv6 (SRv6) or Network Virtualization (NV) Overlay enabled, and NV Overlay in turn needs a VXLAN EVPN VNI mapped to an NVE interface with at least one peer VTEP learned (Cisco’s example is BGP EVPN or an ingress-replication static peer). CVE-2026-76501 needs SRv6, which only some Nexus 9000 models support.

CVE-2026-76465 abuses improperly validated MPLS echo-request packets sent to an affected device’s IP address and requires MPLS OAM, which is also disabled by default. Nexus 9000 switches with Silicon One ASICs don’t support MPLS OAM at all and aren’t affected by this flaw.

Nexus 7000 switches and Nexus 9000 switches running in ACI mode are not affected by any of the five.

What to do about them

The fix is a fixed NX-OS release, and the version you need depends on your current branch and platform, so run your image through Cisco’s Software Checker rather than guessing. If upgrading means a reboot window you can’t take yet, Cisco is shipping temporary Live Protect shields for all five flaws to cover switches that can’t be upgraded and rebooted immediately.

The cheaper mitigation, where it applies, is to turn off the feature that opens the hole. If you aren’t running NGOAM, NX-API, or MPLS OAM, disabling them removes the attack vector entirely. Given that NX-API and MPLS OAM are off by default, the practical question for most operators is whether NGOAM is enabled, since it gates three of the five bugs.

Cisco found all five during internal security testing and says it was unaware of any public disclosure or malicious exploitation when the advisories went out. That is worth doing the patch on your own schedule rather than a fire drill, but the root-level code execution on offer means the schedule should be short.

The Cisco License flaws in the same batch

Alongside the Nexus advisories, Cisco shipped hardening updates for Cisco License (formerly Smart Software Manager), and these are arguably the more urgent item. They cover missing authentication for a critical function (CVE-2026-76480, CVSS 9.8), improper cryptographic signature verification (CVE-2026-76482, CVSS 10.0), insufficiently protected credentials (CVE-2026-76483, CVSS 9.1), and code injection (CVE-2026-76484, CVSS 8.8).

Unlike the Nexus bugs, the License flaws hit affected releases regardless of configuration, and there are no workarounds. The fix is version 10-202609. Older installations still branded Smart Software Manager will not get a patch, so if you’re on one of those the only remediation Cisco offers is migrating to a supported release.

Share

Keep Reading

Latest on the Wire

Full wire →

New signal daily · RSS

Stay in the loop

New writing delivered when it's ready. No schedule, no spam.