Cisco discloses critical NX-OS vulnerabilities in Nexus switches

Cisco has disclosed five critical vulnerabilities in its NX-OS data center operating system. If exploited, they could allow root-level code execution on Nexus 3000 and 9000 switches, or cause crashes and reloads. The bugs involve NX-API, NGOAM, and MPLS OAM features, and Cisco advises upgrading to fixed NX-OS releases.
Cisco published advisories about five severe NX-OS flaws affecting Nexus 3000 and 9000 switches in standalone mode. Attackers might gain root-level execution, or force processes to fail and devices to reboot, causing outages. The bugs arise from inadequate validation and need NX-API, NGOAM, or MPLS OAM enabled.
One flaw, CVE-2026-76471, involves crafted HTTP requests to NX-API. Three NGOAM flaws are reached through crafted IP packets, while CVE-2026-76465 uses MPLS echo-request packets. Certain conditions require SRv6 or NV Overlay. Cisco recommends patched releases, turning off unused features, or Live Protect shields.
Data center operators, cloud providers, and enterprises relying on Nexus switches may face service disruptions if flaws are exploited. Root-level access could let attackers alter network traffic or disrupt connectivity, potentially affecting downstream users and digital services. Because features must be enabled, exposure may be limited, but unpatched or misconfigured systems could remain at risk. Organizations may need emergency maintenance, increasing operational burden.