Cisco · Exploits

Three Unauthenticated Root RCEs Hit Cisco Nexus 3000 and 9000: Check Which Feature Is On

Three Cisco Nexus feature doors NGOAM, MPLS OAM, NX-API all lead to root, each CVSS 9.8, no exploitation known
JT

Malware researcher · Updated Oct 7, 2026, 9:53 PM EDT

Cisco's NGOAM, MPLS OAM and NX-API flaws on Nexus 3000/9000 all score CVSS 9.8. Each needs a feature enabled; here's how to check.

Cisco published three critical advisories on 7 October 2026 for NX-OS on Nexus 3000 and 9000 switches. CVE-2026-76485 (NGOAM), CVE-2026-76465 (MPLS OAM) and CVE-2026-76471 (NX-API) each let an unauthenticated remote attacker run code as root or crash the device, and each scores CVSS 9.8. Every one needs a specific feature to be enabled, and Cisco says it knows of no exploitation.

What happened

Cisco PSIRT released three separate advisories, all version 1.0 Final, on 7 October 2026 as part of its October NX-OS bundle. Cisco says all three were found during internal security testing and that it is not aware of public announcements or malicious use. None of the three IDs appeared in CISA's Known Exploited Vulnerabilities catalog when we checked on 8 October, though the catalog version we could read (2026.10.04) predates the disclosure. NVD has the records but had not yet analysed them (status "Received").

All three carry the same score, CVSS 3.1 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), assigned by Cisco. CISA's enrichment (SSVC) exists so far for CVE-2026-76465 and CVE-2026-76471, and lists exploitation as "none", automatable as "yes" and technical impact as "total". It was not yet present for CVE-2026-76485 when we checked.

Timeline (7 October 2026, UTC): Cisco advisories 16:00; NVD records 17:16 to 17:17; CISA SSVC data 17:44 to 17:46.

Who is exposed

Each bug sits behind a feature, so exposure depends on configuration, not on the model alone.

CVEFeatureCause (NVD CWE)Default stateCheck
CVE-2026-76485NGOAM (VXLAN OAM)Improper input validation of IP traffic (CWE-121, stack overflow)Not stated in the advisoryshow feature | include ngoam
CVE-2026-76465MPLS OAMCrafted MPLS echo-request (CWE-590)Disabledshow feature | include mpls_oam
CVE-2026-76471NX-APICrafted HTTP request (CWE-122, heap overflow)Disabledshow feature | include nxapi

Affected platforms are Nexus 3000 and Nexus 9000 in standalone NX-OS mode. For MPLS OAM, Nexus 9000 models with a Silicon One ASIC cannot enable the feature and are not affected. The NX-API advisory also lists UCS 6300 Series Fabric Interconnects.

Cisco lists these as not affected across the advisories: Firepower 1000, 2100, 4100 and 9300; MDS 9000; Nexus 7000; Nexus 9000 in ACI mode; Secure Firewall 200, 1200, 3100, 4200 and 6100; UCS 6400, 6500 and 6600; and UCS X-Series Direct Fabric Interconnect 9108 100G. UCS 6300 is excluded only for the NGOAM and MPLS OAM bugs.

Note the wording: the NGOAM advisory says "NGOAM enabled and specific features configured" for two sibling bugs (see below), but for CVE-2026-76485 the only condition beyond the platform and a vulnerable release is that NGOAM is enabled.

Affected releases

Cisco's machine-readable (CSAF) advisories list the known-affected releases. For all three CVEs that is every listed release in the NX-OS 9.3, 10.3, 10.4, 10.5 and 10.6 trains, up to 10.6(3) on Nexus 3000 and 10.6(3s) on Nexus 9000. CVE-2026-76485 and CVE-2026-76471 also list 9.2(1) to 9.2(4). The advisories name no fixed NX-OS release; get the first fixed release for your train from Cisco's Software Checker. Releases not listed (such as 10.1 and 10.2) are not confirmed safe; they are simply not listed.

Technical details

All three are memory-safety or input-validation faults reachable over the network without credentials. The NGOAM bug is triggered by crafted IP traffic sent to an interface on the switch. The MPLS OAM bug is triggered by a crafted MPLS echo-request sent to an IP address on the device. The NX-API bug is triggered by a crafted HTTP request to the NX-API service. The advisories give no ports.

Cisco describes the outcome as arbitrary code execution as root or a denial of service, and notes that a process crash can reload the device. The advisories do not say which outcome depends on which condition.

The UCS 6300 case is different. There, exploitation needs valid low-privileged credentials through the UCS Manager XML API, which is on by default and cannot be turned off without losing functionality. Cisco therefore rates the impact High, not Critical, on UCS 6300, and Critical on Nexus.

What defenders should do

  1. Find out if you are exposed. On each Nexus 3000 and standalone Nexus 9000, run the three show feature checks above. A line ending in enabled means the feature is on.
  2. Patch. Every current NX-OS train through 10.6(3) is listed as affected, and the advisories name no fixed release for Nexus. Get the first fixed release for your train from Cisco's Software Checker, linked from the advisories below. For UCS 6300 on release 4.3, the first fixed releases are 4.3(6j) (UCS Manager managed) and 4.3(6.260049) (Intersight managed). UCS 6300 on 4.2 or earlier must migrate to a fixed release.
  3. If you cannot patch yet, remove the feature where you can. Cisco says there is no workaround for the NGOAM and MPLS OAM flaws, but states that no feature ngoam and no feature mpls oam remove the attack vector (tested in a test environment). Cisco offers no workaround at all for NX-API. Check that you do not depend on the feature before removing it.
  4. Consider Live Protect. Cisco says Live Protect shields have been released for all three CVEs. Review Cisco's documentation for support on your platform.
  5. Limit who can reach management and OAM interfaces. This is general hardening, not Cisco guidance for these CVEs: keep NX-API and any OAM-reachable addresses off untrusted networks.

Network infrastructure bugs of this class have drawn quick attention before. We covered the Cisco SD-WAN zero-day that was exploited by a sophisticated actor, which shows why a "not exploited yet" status on edge and fabric gear should not be read as a reason to wait. (We also covered the Cisco ISE zero-day, the Interlock attacks on Cisco FMC and the SD-WAN Manager auth bypass.)

What is still unclear

  • The first fixed NX-OS release for each train. The advisories do not name one; Cisco's Software Checker is the source.
  • Whether root code execution or denial of service is the likelier result in practice, and under what conditions.
  • Whether NGOAM is on by default. The advisory does not say.
  • Whether anyone will exploit these. Cisco's finding came from internal testing. CISA lists two of the three as automatable, which is our reason to treat quick scanning as plausible once details emerge; that is inference, not a Cisco statement.
  • NVD has not finished its analysis, so its fields may change.

The NGOAM advisory also covers two sibling flaws, both CVSS 9.8 and CWE-121 in NVD. CVE-2026-76486 needs NGOAM plus either SRv6 or NV Overlay, with an EVPN VNI mapped to an NVE interface and at least one peer VTEP learned. CVE-2026-76501 needs NGOAM plus SRv6, so in practice it affects only some Nexus 9000s, because Nexus 3000 has no SRv6. Cisco says no feature ngoam mitigates all three NGOAM CVEs and that Live Protect shields exist for all three. This article stays on the three headline CVEs.

Sources