On 7 October 2026 Cisco published fixes for five critical flaws in NX-OS on Nexus 3000 and Nexus 9000 switches running standalone mode. Each scores 9.8. An unauthenticated attacker who can reach the right feature can run code as root, or crash the box into a reload.
What happened
Cisco found the bugs in internal testing and said it was not aware of public exploit code or malicious use when the advisories went out. There is no configuration workaround that closes the bugs while the feature stays on. Disable the unused feature, or upgrade.
The five issues split across three features:
- CVE-2026-76471: crafted HTTP to NX-API. NX-API is off by default.
- CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501: crafted IP packets when NGOAM is enabled. Two of these also need SRv6 or an NV overlay.
- CVE-2026-76465: crafted MPLS echo-request when MPLS OAM is on. That feature is off by default.
Who is affected
Nexus 3000 and Nexus 9000 in standalone NX-OS mode, only if the matching feature is enabled. Nexus 7000 and Nexus 9000 in ACI mode are not affected by these five. UCS 6300 fabric interconnects are a narrower case on CVE-2026-76471: exploitation there needs a low-privilege login.
In the same drop, Cisco License On-Prem (formerly Smart Software Manager On-Prem) has a separate CVSS 10 signature-verification flaw, CVE-2026-76482, plus authentication and credential issues. Fixed in 10-202609. Older SSM On-Prem builds will not be patched; Cisco says migrate.
What to do now
On every Nexus 3000 and 9000, run show feature | include nxapi, confirm whether NGOAM and MPLS OAM are on, and upgrade to the first fixed release from Cisco Software Checker. If a reboot cannot happen this week, Cisco has published temporary Live Protect shields. Those are a bridge, not the fix. License On-Prem should move to 10-202609.
Source: BleepingComputer, 8 October 2026. Vendor advisory: cisco-sa-napi-rce-r2shwu2j.
Also on the blog
- CVE-2026-107406: NetScaler SAML RCE at CVSS 9.5
- AhsayCBS CVE-2026-105134: SYSTEM RCE, 5 organizations hit
- FBI seizes 7 Flax Typhoon domains used for Microscan and FishHub
- .gh .sl .as registry hijacks minted 12 Google certificates
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.