Cisco NX-OS flaws let attackers take over Nexus switches

Cisco NX-OS flaws let attackers take over Nexus switches

Cisco has published advisories for five critical vulnerabilities in NX-OS, the network operating system that runs its Nexus data center switches. An attacker who exploits them could execute arbitrary code with root privileges on affected devices.

If code execution fails, the same flaws can still be used to crash processes and force the switch to reload. That results in a denial-of-service condition, which can disrupt traffic in the data center.

The vulnerabilities affect Nexus 3000 and Nexus 9000 Series switches running in standalone NX-OS mode. Not every deployment is exposed. Exploitation depends on at least one of three features being active: NX-API, Next Generation OAM (NGOAM) or MPLS OAM. OAM stands for Operations, Administration and Maintenance, a set of tools used to monitor and troubleshoot network paths.

Five flaws, one root cause

All five issues come down to validation failures. Each one is reached through a different feature:

  • CVE-2026-76471 is an insufficient input validation bug. It can be triggered with a crafted HTTP request sent to NX-API, which is disabled by default.
  • CVE-2026-76485, CVE-2026-76486 and CVE-2026-76501 stem from improper validation of IP traffic. An attacker can exploit them by sending crafted packets to an IP interface, but only if NGOAM is enabled.
  • CVE-2026-76465 involves improper validation of MPLS echo-request packets. It can be exploited with a crafted request sent to the device's IP address.

Some of these bugs need additional conditions. CVE-2026-76486 also requires either Segment Routing over IPv6 (SRv6) or Network Virtualization (NV) Overlay to be turned on. According to Cisco's advisory, NV Overlay in turn needs a VXLAN EVPN network identifier mapped to a Network Virtualization Endpoint interface, with at least one peer VXLAN Tunnel Endpoint learned, for example through BGP EVPN or an ingress-replication static peer.

CVE-2026-76501 can only be exploited if SRv6 is active. That feature is supported on only some Nexus 9000 models.

For CVE-2026-76465, MPLS OAM must be switched on explicitly, since it ships disabled. Nexus 9000 switches built on Silicon One ASICs do not support the feature at all and are not affected by this bug.

Which devices are safe

Cisco says Nexus 7000 switches are not affected by any of the five flaws. The same applies to Nexus 9000 switches operating in ACI mode, Cisco's Application Centric Infrastructure setup.

The vulnerabilities were found during Cisco's own internal security testing. At the time the advisories were published, the company said it was not aware of any public disclosure or malicious exploitation.

Patches, workarounds and Live Protect

Cisco recommends upgrading NX-OS to a fixed release. Administrators can use the vendor's Software Checker tool to find the right version for their hardware.

Where NGOAM, NX-API or MPLS OAM are not needed, Cisco advises disabling them. This removes the attack vector entirely.

For switches that cannot be upgraded and rebooted right away, Cisco offers temporary Live Protect shields for all five vulnerabilities. Live Protect is a protection mechanism meant to cover devices until a proper update can be applied.

Cisco License flaws, no workarounds

Alongside the Nexus advisories, Cisco also released security hardening updates for Cisco License, the product formerly known as Smart Software Manager. Four vulnerabilities were addressed:

  • CVE-2026-76480 (CVSS 9.8): missing authentication for critical functions
  • CVE-2026-76482 (CVSS 10.0): improper verification of cryptographic signatures
  • CVE-2026-76483 (CVSS 9.1): insufficiently protected credentials
  • CVE-2026-76484 (CVSS 8.8): code injection

These flaws are more urgent from a configuration standpoint. Affected releases are vulnerable no matter how they are set up, and there are no workarounds. Cisco recommends upgrading to version 10-202609.

Older releases still branded as Smart Software Manager will not get a fix. Customers running them are advised to migrate to a supported release.

Our Take

The Nexus flaws are serious on paper, but the real exposure depends heavily on configuration. Several of the affected features are off by default, and some bugs need fairly specific setups such as SRv6 or VXLAN EVPN. This suggests that many organizations may not be exposed, but network teams should verify that rather than assume it. Data center switches are often configured once and rarely reviewed again.

The Cisco License issues look more pressing. A CVSS 10.0 signature verification flaw, no workarounds and no patch for older branded releases leave little room to wait.

Network infrastructure has been a steady target. Recent cases such as the compromise of Fortinet devices and the Citrix NetScaler zero-day show how quickly attackers move on edge and core devices once details are public. No exploitation of these Cisco flaws has been reported so far. It is worth watching whether that changes as researchers study the patches, and whether Live Protect gets used as a long-term substitute for updates rather than a short bridge.