Cisco NX-OS CVE-2026-76471: root on Nexus, CVSS 9.8
Five unauthenticated NX-OS flaws on Nexus 3000 and 9000 if NX-API, NGOAM, or MPLS OAM is on

Cisco NX-OS CVE-2026-76471: root on Nexus, CVSS 9.8

On 7 October 2026 Cisco published fixes for five critical flaws in NX-OS on Nexus 3000 and Nexus 9000 switches running standalone mode. Each scores 9.8. An unauthenticated attacker who can reach the right feature can run code as root, or crash the box into a reload.

What happened

Cisco found the bugs in internal testing and said it was not aware of public exploit code or malicious use when the advisories went out. There is no configuration workaround that closes the bugs while the feature stays on. Disable the unused feature, or upgrade.

The five issues split across three features:

Who is affected

Nexus 3000 and Nexus 9000 in standalone NX-OS mode, only if the matching feature is enabled. Nexus 7000 and Nexus 9000 in ACI mode are not affected by these five. UCS 6300 fabric interconnects are a narrower case on CVE-2026-76471: exploitation there needs a low-privilege login.

In the same drop, Cisco License On-Prem (formerly Smart Software Manager On-Prem) has a separate CVSS 10 signature-verification flaw, CVE-2026-76482, plus authentication and credential issues. Fixed in 10-202609. Older SSM On-Prem builds will not be patched; Cisco says migrate.

What to do now

On every Nexus 3000 and 9000, run show feature | include nxapi, confirm whether NGOAM and MPLS OAM are on, and upgrade to the first fixed release from Cisco Software Checker. If a reboot cannot happen this week, Cisco has published temporary Live Protect shields. Those are a bridge, not the fix. License On-Prem should move to 10-202609.

Source: BleepingComputer, 8 October 2026. Vendor advisory: cisco-sa-napi-rce-r2shwu2j.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

Midnight Mimosa: preinstalled Android malware in 150 countries
firmware system app on cheap MediaTek Android phones