Cisco Patches Five CVSS 9.8 Flaws in NX-OS
Cisco issued advisories for five critical NX-OS vulnerabilities, all CVSS 9.8, enabling unauthenticated remote code execution with root on Nexus data center switches.

Five critical vulnerabilities in Cisco NX-OS. All CVSS 9.8. All allow an unauthenticated remote attacker to execute arbitrary code as root on Nexus data center switches. Cisco published patches October 7, 2026.
No active exploitation confirmed. CISA has not added any of these to the Known Exploited Vulnerabilities catalog as of this publication.
The vulnerabilities
Three of the five affect protocol-handling features in NX-OS running on Nexus 3000 and 9000 series switches.
CVE-2026-76471 is in the NX-API feature. Sending a crafted HTTP or HTTPS request to the NX-API listener is sufficient for an unauthenticated attacker to gain root code execution or crash the service. NX-API is a common management interface in data center deployments; it must be explicitly enabled, but many operators turn it on for automation. Cisco advisory.
CVE-2026-76501 is in the NGOAM feature, which implements Operation, Administration, and Maintenance for Cisco’s Segment Routing over IPv6 (SRv6) stack. Crafted SRv6 OAM packets can trigger unauthenticated root RCE. Cisco advisory.
CVE-2026-76465 is in the MPLS OAM feature, again for Nexus 3000 and 9000 series. Same class of vulnerability: unauthenticated network-accessible RCE as root through crafted OAM packets. Cisco advisory.
Two more round out the critical-severity set.
CVE-2026-76500 targets the Cisco Application Policy Infrastructure Controller (APIC). Cisco’s own APIC engineering team found it during a proactive internal security review. The advisory does not describe external discovery or known proof-of-concept code. CVSS 9.8. Cisco advisory.
CVE-2026-20328, CVSS 9.1, is in the web-based management interface of Cisco License On-Prem, which Cisco previously shipped as Smart Software Manager On-Prem (SSM On-Prem). An unauthenticated remote attacker can use a flaw in the web UI to gain unauthorized access. This affects on-premises software license management infrastructure, not NX-OS directly. Cisco advisory.
Scope and exposure
Nexus 3000 and 9000 series switches are deployed heavily in enterprise and service-provider data centers. NX-API is a standard REST/JSON management interface used in automation-heavy environments. MPLS OAM and SRv6 NGOAM are more narrowly deployed but present wherever operators run MPLS or SRv6 transport networks.
Cisco’s October advisory round also includes medium-severity issues: CVE-2026-20038, a contract bypass in Nexus 9000 ACI mode (CVSS 5.8), and CVE-2026-20173, a denial-of-service condition in NX-OS (CVSS 5.8). Full list of affected versions and fixed releases is in each individual advisory.
Confidence flags
Active exploitation: not confirmed. CISA KEV addition: not as of publication. Internal discovery (CVE-2026-76500): suggests limited external exposure so far, unconfirmed.
Patch status
Cisco has released fixed NX-OS software versions for all five. Consult each linked advisory for the affected release train, the fixed version, and any workaround (such as disabling NX-API if patching is not immediately possible).
Previous Cisco security coverage: SD-WAN Manager auth bypass under active exploitation, ISE zero-day at CVSS 10.0, Email Gateway SQLi giving root access.
- [ CRITICAL ]CVE-2026-76471Cisco NX-OS NX-API unauthenticated root RCE
- [ CRITICAL ]CVE-2026-76501Cisco NX-OS SRv6 NGOAM unauthenticated root RCE
Found this useful? Share it.


