Cisco Issues Advisories for Five Critical NX-OS Flaws
The flaws affect NX-API, NGOAM and MPLS OAM features on Nexus 3000 and Nexus 9000 Series switches and could allow root-level code execution.
Cisco has released security advisories for five critical vulnerabilities in its NX-OS data center network operating system, according to bleepingcomputer.com. The flaws affect NX-API, Next Generation OAM (NGOAM) and MPLS OAM features on Nexus 3000 and Nexus 9000 Series switches.
The vulnerabilities could allow attackers to run arbitrary code with root privileges on the switches, or cause a denial-of-service condition by forcing a reload. They were tracked as CVE-2026-76471, CVE-2026-76485, CVE-2026-76486, CVE-2026-76501 and CVE-2026-76465.
Cisco said it was unaware of public announcements or malicious exploitation at the time the advisories were published.
Separately, Cisco released security hardening updates for Cisco License. Those updates address missing authentication, improper cryptographic signature verification, insufficiently protected credentials and code injection.
Quick answers
Which Cisco switches are affected by the NX-OS vulnerabilities?
The advisories cover Nexus 3000 Series and Nexus 9000 Series switches, specifically the NX-API, Next Generation OAM (NGOAM) and MPLS OAM features.
What are the CVE IDs for the five critical NX-OS flaws?
Cisco tracked them as CVE-2026-76471, CVE-2026-76485, CVE-2026-76486, CVE-2026-76501 and CVE-2026-76465.
Did Cisco say the flaws were being exploited?
Cisco said it was unaware of public announcements or malicious exploitation at the time of publishing the advisories.