Cisco warns of five NX-OS bugs that reach root
Cisco patched five critical NX-OS flaws allowing root code execution on Nexus 3000 and 9000 switches, plus regardless-of-config Cisco License bugs.
Cisco published advisories for five critical vulnerabilities in NX-OS that let an attacker run arbitrary code as root on Nexus 3000 and Nexus 9000 switches in standalone NX-OS mode. Where full code execution isn’t reachable, the same bugs crash the target process and force the switch to reload, so the worst case if you escape remote code execution is still a denial of service on your data center fabric.
All five share one root cause: a validation failure in one of three features. The attack surface only exists if NX-API, Next Generation OAM (NGOAM), or MPLS OAM is active on the box, which is the good news here. A default-configured switch with none of these turned on has nothing to exploit.
The five CVEs and what each one needs
CVE-2026-76471 is insufficient input validation in NX-API, triggered by a crafted HTTP request. NX-API is disabled by default, so this one only matters where someone has deliberately enabled the programmatic interface.
CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501 all come from improper validation of IP traffic and fire on crafted packets sent to an IP interface. All three require NGOAM to be enabled. Two of them carry extra conditions on top of that. CVE-2026-76486 also needs either Segment Routing over IPv6 (SRv6) or Network Virtualization (NV) Overlay enabled, and NV Overlay in turn needs a VXLAN EVPN VNI mapped to an NVE interface with at least one peer VTEP learned (Cisco’s example is BGP EVPN or an ingress-replication static peer). CVE-2026-76501 needs SRv6, which only some Nexus 9000 models support.
CVE-2026-76465 abuses improperly validated MPLS echo-request packets sent to an affected device’s IP address and requires MPLS OAM, which is also disabled by default. Nexus 9000 switches with Silicon One ASICs don’t support MPLS OAM at all and aren’t affected by this flaw.
Nexus 7000 switches and Nexus 9000 switches running in ACI mode are not affected by any of the five.
What to do about them
The fix is a fixed NX-OS release, and the version you need depends on your current branch and platform, so run your image through Cisco’s Software Checker rather than guessing. If upgrading means a reboot window you can’t take yet, Cisco is shipping temporary Live Protect shields for all five flaws to cover switches that can’t be upgraded and rebooted immediately.
The cheaper mitigation, where it applies, is to turn off the feature that opens the hole. If you aren’t running NGOAM, NX-API, or MPLS OAM, disabling them removes the attack vector entirely. Given that NX-API and MPLS OAM are off by default, the practical question for most operators is whether NGOAM is enabled, since it gates three of the five bugs.
Cisco found all five during internal security testing and says it was unaware of any public disclosure or malicious exploitation when the advisories went out. That is worth doing the patch on your own schedule rather than a fire drill, but the root-level code execution on offer means the schedule should be short.
The Cisco License flaws in the same batch
Alongside the Nexus advisories, Cisco shipped hardening updates for Cisco License (formerly Smart Software Manager), and these are arguably the more urgent item. They cover missing authentication for a critical function (CVE-2026-76480, CVSS 9.8), improper cryptographic signature verification (CVE-2026-76482, CVSS 10.0), insufficiently protected credentials (CVE-2026-76483, CVSS 9.1), and code injection (CVE-2026-76484, CVSS 8.8).
Unlike the Nexus bugs, the License flaws hit affected releases regardless of configuration, and there are no workarounds. The fix is version 10-202609. Older installations still branded Smart Software Manager will not get a patch, so if you’re on one of those the only remediation Cisco offers is migrating to a supported release.
Keep Reading
fortinet86,644 FortiGate boxes still take the old password
The FBI says FortiBleed is still active, using 86,644 Fortinet credentials harvested months ago to plant admin accounts and feed ransomware crews.
AI securityDeepSeek 4.1 Flash Looks Boring
DeepSeek 4.1 Flash matters because cheap long coding sessions change agent governance more than they introduce a new exploit.
TelegramTelegram Desktop File Theft Bug
Telegram Desktop 7.2.9 fixed a link-triggered file theft bug that could expose local session files without a passcode.
Latest on the Wire
Full wire →- AI Development Shifts Undermine Low-Level Coding ExpertiseHacker News
- AI Security Gaps: Third-Party Agents Evade ControlThe Hacker News
- AI Uncovers Historical Secrets in 400-Year-Old ArchivesHacker News
- Anthropic AI Agents Target Government WebsiteSimon Willison
New signal daily · RSS
Stay in the loop
New writing delivered when it's ready. No schedule, no spam.