Cisco has disclosed five critical vulnerabilities in NX-OS that could allow unauthenticated remote attackers to execute arbitrary code with root privileges on affected Nexus data center switches.
The flaws affect certain Cisco Nexus 3000 and Nexus 9000 switches operating in standalone NX-OS mode. Exploitation depends on optional management or network-diagnostic features being enabled, but successful attacks could give an adversary control of critical switching infrastructure or force devices to reload, disrupting network availability.
Cisco has released fixed software and temporary Live Protect shields. The company says it is not aware of malicious exploitation or public exploit disclosures.
THE FIVE CRITICAL VULNERABILITIES
Cisco assigned a maximum CVSS score of 9.8 to three related security advisories covering five CVEs:
CVE-2026-76471 affects the NX-API feature. An unauthenticated attacker could send a crafted HTTP request to execute code as root or crash the affected process. It affects Nexus 3000 and standalone Nexus 9000 switches when NX-API is enabled. Certain UCS 6300 Fabric Interconnects are also affected, although exploitation there requires valid low-privilege credentials. sec.cloudapps.cisco.com
CVE-2026-76485, CVE-2026-76486 and CVE-2026-76501 affect Next Generation Operation, Administration and Maintenance, or NGOAM. Crafted packets sent to a switch interface could produce root-level code execution or a denial-of-service condition. All three require NGOAM, while two require additional configurations involving SRv6 or VXLAN Network Virtualization Overlay. sec.cloudapps.cisco.com
CVE-2026-76465 affects MPLS OAM. A crafted MPLS echo-request sent to an affected device could execute code with root privileges or trigger a device reload. Nexus 9000 switches equipped with Silicon One ASICs do not support the vulnerable feature and are not affected by this flaw. sec.cloudapps.cisco.com
EXPOSURE DEPENDS ON ENABLED FEATURES
The vulnerabilities do not affect every Nexus deployment automatically.
NX-API and MPLS OAM are disabled by default on the affected Nexus switches. The three NGOAM vulnerabilities require that administrators have explicitly enabled NGOAM, with some flaws also dependent on SRv6 or particular VXLAN EVPN configurations.
Cisco Nexus 7000 switches and Nexus 9000 switches operating in Application Centric Infrastructure mode are not affected by these five vulnerabilities.
That narrower exposure does not eliminate the risk. The affected functions are legitimate operational capabilities that may be enabled in production data centers for automation, diagnostics, overlay networking or service-provider routing. Security teams should verify actual switch configurations rather than assuming default settings remain in place.

