Cisco published fixes on 7 October 2026 for a critical NX-OS flaw, CVE-2026-76471. An unauthenticated attacker who can reach NX-API can run code as root or crash the switch into a reload. CVSS is 9.8.
What happened
The bug is a heap buffer overflow from weak validation of data sent to NX-API. A crafted HTTP request is enough. NX-API is disabled by default on Nexus 3000 and Nexus 9000 switches in standalone NX-OS mode. It is commonly turned on for automation. UCS 6300 fabric interconnects are also affected, but exploitation there needs a valid low-privilege login, so Cisco rates that case High rather than Critical.
Cisco's PSIRT said it was not aware of public exploit code or malicious use when the advisory went out. There is no configuration workaround. A Live Protect shield exists as a bridge until you can upgrade and reboot. Check status with show feature | include nxapi.
The same disclosure cycle includes four more unauthenticated NX-OS issues that also need a feature enabled. CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501 need NGOAM. CVE-2026-76465 needs MPLS OAM, which is off by default. Nexus 7000 and Nexus 9000 in ACI mode are not affected by these five.
Who is affected
Nexus 3000 and Nexus 9000 switches in standalone NX-OS mode with NX-API, NGOAM, or MPLS OAM enabled. Data-center and campus cores that expose management APIs beyond a dedicated admin network are the ones that matter. ACI-mode 9000s and Nexus 7000s are out of scope for this set.
- CVE-2026-76471: NX-API, CVSS 9.8, no login, root or device reload.
- NGOAM set: three more remote code bugs if that feature is on.
- MPLS OAM: CVE-2026-76465, only if the feature was explicitly enabled.
- Cisco also shipped License On-Prem fixes the same day, including unauthenticated issues. Older Smart Software Manager builds will not be patched. Migrate them.
What to do now
Run the feature check on every Nexus 3000 and 9000, disable NX-API and MPLS OAM if you do not use them, and schedule the fixed NX-OS release. Use Cisco's Software Checker for the first-fixed version rather than guessing a train. Keep the management plane off the internet. Live Protect is a temporary shield, not the fix.
Source: Cisco security advisory cisco-sa-napi-rce-r2shwu2j, first published 7 October 2026, NX-API remote code execution.
Also on the blog
- FBI seizes 7 Flax Typhoon domains used for Microscan and FishHub
- CVE-2026-104286: FortiMail unauthenticated file write, CVSS 9.8
- ASOS breach: stolen employee login exposed customer contacts
- Red Lion N-Tron 700: seven flaws, upgrade to firmware 3.11.1
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.