Skip to content
TECH CEO Daily
CybersecuritySecurity Alert

Cisco discloses five critical Nexus switch flaws that could allow remote root takeover

The NX-OS bugs sit in the NX-API, NGOAM and MPLS OAM features and could let attackers run code as root or crash Nexus 3000 and 9000 switches.

By · Editor

· 2 min read · Fact-checked

The 60-second brief

  • 1Cisco disclosed five critical NX-OS flaws affecting Nexus 3000 and 9000 switches in standalone mode.
  • 2Three of the flaws carry a 9.8 severity score, according to public vulnerability records.
  • 3Cisco said it was not aware of public announcements or malicious exploitation when it published the advisories.

The news

Cisco Systems (CSCO) has disclosed five critical vulnerabilities in NX-OS, the operating system on its Nexus switches, that could let a remote attacker take over the devices, according to BleepingComputer. Public vulnerability records date the disclosure of several of the flaws to October 7, 2026.

The Cisco Nexus switch vulnerabilities affect Nexus 3000 and 9000 Series switches running in standalone NX-OS mode, BleepingComputer reported. They are tracked as CVE-2026-76465, CVE-2026-76471, CVE-2026-76485, CVE-2026-76486 and CVE-2026-76501.

All five stem from failures to properly check incoming data in three features: NX-API, the programming interface used to automate switch configuration; Next Generation OAM (NGOAM), a set of network troubleshooting tools; and MPLS OAM. Successful attacks could allow remote code execution with root privileges, or a denial of service by crashing processes and reloading the device, according to BleepingComputer.

Several of the flaws can be triggered without logging in. Vulnerability records describe CVE-2026-76485 and CVE-2026-76486 as NGOAM flaws in VXLAN setups that an unauthenticated remote attacker could exploit, each scored 9.8 out of 10. CVE-2026-76501, also rated 9.8, affects switches with both NGOAM and SRv6 (Segment Routing over IPv6) enabled, according to TheHackerWire. CVE-2026-76471 affects NX-API.

Cisco said it had no awareness of public announcements or malicious exploitation of the flaws when it published the advisories, BleepingComputer reported. The company listed workarounds that include disabling unused NX-API, NGOAM or MPLS OAM features and applying temporary Live Protect shields to systems that cannot be updated right away.

BleepingComputer also reported that Cisco disclosed companion flaws in its licensing software, with severity scores ranging from 8.8 to 10.0.

The numbers

Critical NX-OS flaws
5
Highest Nexus flaw score
9.8 out of 10
Affected lines
Nexus 3000 and 9000 (standalone NX-OS)
Known exploitation at disclosure
None, per Cisco

Why CEOs should care

Nexus 9000 switches sit at the core of many corporate data centers, so a root-level takeover is not a single-device problem. An attacker who controls a core switch can watch, redirect or cut off traffic for everything behind it. CISOs and infrastructure leaders should confirm which Nexus 3000 and 9000 devices run standalone NX-OS and which of the three affected features are turned on.

The fastest risk reduction may not be a patch. If NX-API, NGOAM or MPLS OAM is enabled but unused, turning it off removes the exposure, according to the workarounds Cisco listed. For features that are needed, restrict who can reach them with access control lists and keep management interfaces off general networks, then schedule an update window using Cisco's advisories for the fixed releases.

CIOs and boards should ask a simple question: how long does it take us to patch core network gear? No exploitation was known at disclosure, which gives defenders a head start, but network devices have been a favorite target for attackers once technical details become public.

The bigger picture

Network equipment from Cisco and its rivals has become a steady source of critical security advisories, and attackers increasingly go after edge and infrastructure devices that lack endpoint security tools. Data center switches have historically been treated as stable plumbing that is rarely touched; flaws that allow remote root access argue for treating them on a patch cycle closer to servers.

What’s next

Teams should read Cisco's individual advisories for each CVE to find fixed NX-OS releases, apply workarounds where updates must wait, and watch for any change in Cisco's exploitation status.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

CiscoNexusNX-OSVulnerabilities

Earlier coverage of Cisco

All Cisco coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.