On 7 October 2026 Cisco published critical advisories for Nexus 3000 and Nexus 9000 switches in standalone NX-OS mode. Five vulnerabilities each score CVSS 9.8. An unauthenticated remote attacker can run code as root or crash the device into a reload. Cisco said it was not aware of malicious use when the advisories went out. BleepingComputer reported the set on 8 October.
What happened
The bugs are input-validation failures. Three sit in Next Generation OAM (NGOAM): CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501. One is in NX-API, CVE-2026-76471, triggered by a crafted HTTP request. One is in MPLS OAM, CVE-2026-76465, triggered by a crafted MPLS echo request. There are no workarounds. Cisco also shipped temporary Live Protect shields, which are not a substitute for a fixed release.
Who is affected
Nexus 3000 and Nexus 9000 in standalone NX-OS mode, and only when the matching feature is enabled. Nexus 7000 and Nexus 9000 in ACI mode are not affected by these five.
- CVE-2026-76485 needs NGOAM enabled.
- CVE-2026-76486 needs NGOAM plus Segment Routing over IPv6 or Network Virtualization Overlay.
- CVE-2026-76501 needs NGOAM and SRv6.
- CVE-2026-76471 needs NX-API, which is disabled by default.
- CVE-2026-76465 needs MPLS OAM, which is disabled by default.
What to do now
On every Nexus 3000 and 9000 in standalone mode, check whether NGOAM, NX-API, or MPLS OAM is enabled, then upgrade to a fixed NX-OS release from Cisco's Software Checker. If a feature is on and the management or OAM plane is reachable beyond the management VRF, treat that switch as exposed until it is patched. Do not leave a Live Protect shield in place as the permanent fix.
Source: Cisco security advisory cisco-sa-ngoam-rce-LWKQ4BU, 7 October 2026, NGOAM remote code execution. NX-API advisory: cisco-sa-napi-rce-r2shwu2j.
Also on the blog
- FBI seizes 7 Flax Typhoon domains used for Microscan and FishHub
- Citrix NetScaler CVE-2026-107406 scores 9.5 on SAML deployments
- ARTEX AI pentest agent used in South Korean bank data theft
- Japan web data leaks hit 119 in 2026, 81 since July
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.