Critical Cisco Nexus Flaws Let Unauthenticated Attackers Execute Code With Root Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


Cisco has released security updates for three critical vulnerabilities in Nexus 3000 and 9000 Series switches that could let remote attackers run code with root privileges without logging in.

The flaws affect the Next Generation Operation, Administration, and Maintenance feature, known as NGOAM, in Cisco NX-OS Software. Successful attacks could also crash processes, force switches to reload, and disrupt network services.

Published on October 7, 2026, Cisco’s security advisory covers CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501. The advisory carries a CVSS base score of 9.8.

Cisco found the vulnerabilities during internal security testing and said its Product Security Incident Response Team was not aware of public announcements or malicious use when the advisory was released.

The flaws stem from improper validation of incoming IP traffic when NGOAM is enabled. An attacker can send crafted packets to an IP interface on an affected switch.

If exploitation succeeds, those packets could trigger code execution with root privileges, giving the attacker control at the operating system’s highest privilege level. The same attack path could cause a denial-of-service condition through process crashes and device reloads.

NGOAM supports network checks and troubleshooting. Its VXLAN functions help detect and address loops. In contrast, its Segment Routing over IPv6, or SRv6, functions help operators check connectivity and locate forwarding problems.

However, the exposure differs across the three vulnerabilities, so administrators must check both software versions and enabled features rather than treating every Nexus switch as affected.

Cisco Nexus Flaws

Cisco’s security advisory applies to Nexus 3000 and Nexus 9000 Series switches operating in standalone NX-OS mode. CVE-2026-76485 requires only NGOAM to be enabled.

CVE-2026-76486 requires NGOAM alongside either SRv6 or a qualifying Network Virtualization Overlay configuration. For the overlay path, a VXLAN EVPN network identifier must be mapped to an NVE interface with at least one learned peer tunnel endpoint.

CVE-2026-76501 requires both NGOAM and SRv6. Nexus 3000 switches do not support SRv6, and only some Nexus 9000 models support it. Cisco confirmed that Nexus 9000 switches running in ACI mode, Nexus 7000 switches, and MDS 9000 multilayer switches are not affected.

Administrators can check NGOAM with the show feature | include ngoam, overlay status with the show feature | include nve, and SRv6 with the show feature | include srv6. Overlay checks also require reviewing show running-config | begin "interface nve", show nve vni, and show nve peers to establish whether the required configuration exists.

Cisco says no workarounds address the vulnerabilities, but turning off an unneeded NGOAM feature removes the attack vector. Administrators can use the no feature ngoam command in global configuration mode after assessing the effect on network operations. Cisco has also released Live Protect shields as temporary protection, not a replacement for patched software.

Organizations should use the Cisco Software Checker to identify the fixed release for their platform. CybersecurityNews previously covered a separate Nexus 9000 root-code-execution flaw, CVE-2026-20212, affecting Silicon One models.

That issue had different exposure conditions; administrators should assess this NGOAM advisory independently and schedule the appropriate NX-OS upgrade.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post Critical Cisco Nexus Flaws Let Unauthenticated Attackers Execute Code With Root Privileges appeared first on Cyber Security News.