
Cisco fixes critical flaws in Nexus 3000 and 9000 switches
Three of the five CVEs score 9.8 and could allow code execution as root; fixed versions exist and Cisco says no attacks are known.
Cisco published a security advisory on Oct. 7 about three critical flaws in the NGOAM feature of NX-OS, the operating system of its Nexus 3000 and Nexus 9000 switches in standalone mode. They are CVE-2026-76485, CVE-2026-76486 and CVE-2026-76501, and the company rated them 9.8 out of 10. A patch exists, though it is not yet known which exact versions carry it: the advisory does not list them and points to Cisco's Software Checker tool.
Nexus switches are data center equipment for companies and carriers, not home networks, so the decision to update belongs to administrators. Cisco says it found the flaws in internal testing and has no record of public announcements or malicious use. According to BleepingComputer, Nexus 7000 and Nexus 9000 in ACI mode are not affected.
Which conditions trigger each flaw
A code-execution flaw lets an attacker run instructions on the device. According to BleepingComputer, these can grant root access, the highest level of control, or, if the attack fails, crash processes and reboot the switch. Exposure depends on configuration:
| CVE | Condition to be affected | Score |
|---|---|---|
| CVE-2026-76485 | NGOAM enabled | 9.8 |
| CVE-2026-76486 | NGOAM, plus SRv6 or NV Overlay | 9.8 |
| CVE-2026-76501 | NGOAM and SRv6, which only some Nexus 9000 support | 9.8 |
NGOAM bundles diagnostic tools for the VXLAN networks used in data centers. SRv6 and NV Overlay route and virtualize traffic on those networks. The internal bug identifiers are CSCwu19785, CSCwu19823 and CSCwu57455.
For anyone who cannot update right away, Cisco offers temporary protections called Live Protect, which the advisory says are not a substitute for updating. The company also says disabling NGOAM with the command `no feature ngoam` removes the attack path for all three flaws.
Two more flaws in the same batch
The batch includes two others, each with its own advisory, according to BleepingComputer: CVE-2026-76471 affects NX-API and CVE-2026-76465 affects MPLS OAM. Neither feature is enabled by default, and the outlet does not give their scores. Separately, the company warned of four CVEs rated 8.8 to 10.0 in its licensing tool, formerly called Smart Software Manager. The fix is in version 10-202609; earlier versions will go unpatched.
Still pending: the affected and fixed NX-OS versions, which must be checked in Cisco's Software Checker. No information was found on how many of these devices operate in Mexico. This report does not describe how to exploit the flaws.



