As reported by BleepingComputer, Cisco has disclosed five critical vulnerabilities in its NX-OS data center operating system that could allow attackers to execute arbitrary code with root privileges on Nexus 3000 and 9000 series switches. The vulnerabilities cluster around three features — NX-API, Next Generation OAM (NGOAM), and MPLS OAM — each representing a distinct attack surface that, if enabled, exposes core network infrastructure to compromise.
Vulnerability Summary
| CVE | Feature Required | Additional Conditions | Impact |
|---|---|---|---|
| CVE-2026-76471 | NX-API | Disabled by default | RCE / DoS |
| CVE-2026-76485 | NGOAM | — | RCE / DoS |
| CVE-2026-76486 | NGOAM | SRv6 or NV Overlay with EVPN/VTEP | RCE / DoS |
| CVE-2026-76501 | NGOAM + SRv6 | Select Nexus 9000 models only | RCE / DoS |
| CVE-2026-76465 | MPLS OAM | Disabled by default; excludes Silicon One ASICs | RCE / DoS |
All five are rated Critical. No active exploitation in the wild has been reported at time of disclosure. Patches are available, and Cisco's Live Protect temporary shields offer interim coverage for switches that cannot be immediately upgraded and rebooted.
Who Is at Risk
Why This Matters
Network switches are the backbone of data center operations. A root-level compromise on a Nexus switch is not merely a server breach — it grants the attacker a persistent vantage point for traffic interception, lateral movement, VLAN manipulation, and silent denial-of-service. The fact that three of the five flaws require NGOAM — a feature increasingly enabled in modern data center deployments for observability — expands the realistic attack surface beyond what the "disabled by default" framing might suggest.
The critical nuance: these are not hypothetical edge-case features. NGOAM and NV overlays are standard in production data center fabrics, meaning many environments that assume they're "not using the vulnerable features" may actually be exposed.
The NX-API vulnerability (CVE-2026-76471) deserves particular attention for environments that have programmatically enabled it for automation, orchestration, or monitoring integrations. Any reachable NX-API endpoint becomes a network-accessible RCE vector against the switch itself.
Attack Chain Considerations
While these vulnerabilities require network access to exploit (crafted packets to an IP interface or HTTP request to NX-API), they do not require authentication. In environments where management or OAM VLANs are not properly segmented from user traffic — a common finding in network audits — the effective exploitability increases significantly. An attacker who has achieved any foothold in the network, including a compromised endpoint or IoT device, could pivot to switch-level compromise.
Shield53 Recommendations
Immediate Actions
- Inventory and assess: Identify all Nexus 3000/9000 switches running standalone NX-OS. Use
show featureto confirm which of NX-API, NGOAM, and MPLS OAM are enabled. - Patch priority: Apply fixed NX-OS releases to all exposed switches. Use Cisco's Software Checker to identify the correct patched version for each model. Schedule maintenance windows for reboot-impacting upgrades.
- Disable where unused: If NX-API, NGOAM, or MPLS OAM are not operationally required, disable them entirely to eliminate the attack vector. This is the single most effective interim mitigation.
- Apply Live Protect shields: For switches that cannot be immediately patched and rebooted, enable Cisco Live Protect temporary protections for all five CVEs as a stopgap.
- Segment management and OAM planes: Ensure NX-API (if retained for automation) is reachable only from dedicated management jump hosts or orchestration systems via ACLs — never from general user VLANs.
- Monitor for exploitation indicators: Watch for unexpected process crashes or device reloads on Nexus switches (potential DoS exploitation) and unusual HTTP sessions to NX-API endpoints. Correlate with NetFlow/IPFIX for crafted packet detection on OAM-targeted interfaces.
- Validate ACI-mode switches: Confirm Nexus 9000 switches intended to run in ACI mode are not inadvertently configured in standalone NX-OS mode, which would unexpectedly place them in scope.
Broader Posture
This disclosure reinforces a recurring pattern: network infrastructure features designed for operational convenience (APIs, OAM protocols) become high-value attack surfaces when left enabled without compensating controls. Organizations should treat every enabled network feature as an attack surface requiring explicit justification, segmentation, and monitoring — not just server and endpoint assets.