securityonline.info 7 Oct 2026, 17:17 UTC

Cisco Patches Critical NX-OS Flaws That Could Crash Nexus Switches

Cisco Patches Critical NX-OS Flaws That Could Crash Nexus Switches
CyberSIXT Evidence Panel
CISA KEV Not in KEV
Patch Patch Status Unknown

CISCO has issued patches for four critical vulnerabilities within the OAM features of NX-OS on Nexus 3000 and 9000 series switches, each rated 9.8 on CVSSv3. The flaws could allow an unauthenticated remote attacker to run arbitrary code with root privileges or cause a device reload, potentially disrupting traffic. Cisco notes that there is no confirmed exploitation at this time, and advisories point admins to the Software Checker for fixed releases, with temporary mitigations available.

Two clusters of flaws affect NGOAM (Next Generation OAM) while the fourth concerns MPLS OAM. The NGOAM issues stem from improper input validation of IP traffic when NGOAM is enabled, allowing crafted packets to escalate to remote code execution or crash the switch, depending on the specific CVE. CVE-2026-76485 requires NGOAM to be enabled; CVE-76486 adds requirements such as an active VXLAN EVPN peer or SRv6/NV Overlay in some configurations; CVE-76501 requires NGOAM plus SRv6. The MPLS OAM flaw, CVE-76465, arises from improper validation while processing MPLS echo-request packets and could trigger code execution or a reload.

Affected devices are Nexus 3000 and 9000 NX-OS systems with the relevant features enabled; many platforms (including certain NX-OS variants and non-Nexus lines) are not exposed. Cisco recommends disabling NGOAM or MPLS OAM if not needed, applying Live Protect shields as temporary mitigation, and using the Cisco Software Checker to identify the first fixed NX-OS release for each platform.

View full article

Article by CyberSIXT