Cisco NX-OS CVE-2026-76471 and four more flaws score 9.8
Nexus 3000 9000 unauthenticated root via NX-API NGOAM MPLS OAM

Cisco NX-OS CVE-2026-76471 and four more flaws score 9.8

On 7 October 2026 Cisco published critical advisories for Nexus 3000 and Nexus 9000 switches in standalone NX-OS mode. Five vulnerabilities each score CVSS 9.8. An unauthenticated remote attacker can run code as root or crash the device into a reload. Cisco said it was not aware of malicious use when the advisories went out. BleepingComputer reported the set on 8 October.

What happened

The bugs are input-validation failures. Three sit in Next Generation OAM (NGOAM): CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501. One is in NX-API, CVE-2026-76471, triggered by a crafted HTTP request. One is in MPLS OAM, CVE-2026-76465, triggered by a crafted MPLS echo request. There are no workarounds. Cisco also shipped temporary Live Protect shields, which are not a substitute for a fixed release.

Who is affected

Nexus 3000 and Nexus 9000 in standalone NX-OS mode, and only when the matching feature is enabled. Nexus 7000 and Nexus 9000 in ACI mode are not affected by these five.

What to do now

On every Nexus 3000 and 9000 in standalone mode, check whether NGOAM, NX-API, or MPLS OAM is enabled, then upgrade to a fixed NX-OS release from Cisco's Software Checker. If a feature is on and the management or OAM plane is reachable beyond the management VRF, treat that switch as exposed until it is patched. Do not leave a Live Protect shield in place as the permanent fix.

Source: Cisco security advisory cisco-sa-ngoam-rce-LWKQ4BU, 7 October 2026, NGOAM remote code execution. NX-API advisory: cisco-sa-napi-rce-r2shwu2j.

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

ARTEX AI pentest agent used in South Korean bank data theft
CrowdStrike ARTEX Claude Code Korean financial firm intrusions