PatchesCritical

Cisco patches over a dozen critical flaws, including Nexus switch root takeover bugs

Cisco fixed 35 vulnerabilities, including critical NX-OS flaws that allow unauthenticated root code execution on Nexus 3000 and 9000 switches and CVSS 10 bugs in License On-Prem.

Cisco patches over a dozen critical flaws, including Nexus switch root takeover bugs

At a glance

  • SecurityWeek reports 35 fixes across Cisco products, more than a dozen of them rated critical.
  • Five NX-OS flaws in NX-API, NGOAM and MPLS OAM can give unauthenticated attackers root code execution on Nexus 3000/9000 switches.
  • License On-Prem flaws rated up to CVSS 10.0 have no workarounds; older Smart Software Manager releases will not be patched.
  • Cisco says it is not aware of exploitation in the wild; feature-disabling workarounds and Live Protect shields are available for NX-OS.

Cisco has released security updates for 35 vulnerabilities across its product portfolio, more than a dozen of them rated critical, including flaws that can let unauthenticated attackers run code as root on Nexus 3000 and 9000 data center switches, SecurityWeek and BleepingComputer reported. The advisories, published on October 7 according to BleepingComputer, also cover License On-Prem, the Application Policy Infrastructure Controller (APIC), Meraki and Finesse. Cisco said it is not aware of any of the flaws being exploited in the wild, but the severity of the bugs and the role of the affected devices make prompt patching important.

What happened

According to SecurityWeek, NX-OS received fixes for 14 vulnerabilities, seven of them critical. License On-Prem received fixes for eight bugs, five of them critical, while APIC received three critical CVEs. A Meraki security hardening release groups multiple memory bugs under seven CVEs, the most severe being CVE-2026-76464. Finesse received a fix for a high-severity server-side request forgery flaw, CVE-2026-20362, which SecurityWeek said has been publicly disclosed.

Technical details

BleepingComputer detailed five critical NX-OS flaws that affect Nexus 3000 and 9000 switches running in standalone NX-OS mode. All stem from input validation failures and can allow arbitrary code execution with root privileges; if code execution fails, an attacker can crash processes and force a reload. CVE-2026-76471 affects NX-API and is exploited with a crafted HTTP request. CVE-2026-76485, CVE-2026-76486 and CVE-2026-76501 involve Next Generation OAM (NGOAM) and are triggered by crafted packets sent to an IP interface; CVE-2026-76486 additionally requires SRv6 or NV Overlay, and CVE-2026-76501 requires SRv6. CVE-2026-76465 affects MPLS OAM and is exploited with a crafted MPLS echo-request. NX-API and MPLS OAM are disabled by default. Cisco found all five flaws during internal security testing.

For Cisco License, BleepingComputer listed CVE-2026-76480 (missing authentication, CVSS 9.8), CVE-2026-76482 (improper cryptographic signature verification, CVSS 10.0), CVE-2026-76483 (insufficiently protected credentials, CVSS 9.1) and CVE-2026-76484 (code injection, CVSS 8.8). These releases are vulnerable regardless of configuration, and there are no workarounds. SecurityWeek said the APIC flaws CVE-2026-76498, CVE-2026-76499 and CVE-2026-76500 involve improper access control, OS command injection and memory issues.

Who is affected

Nexus 7000 switches and Nexus 9000 switches in ACI mode are not affected by the five NX-OS flaws, and Nexus 9000 models with Silicon One ASICs are not affected by the MPLS OAM bug, according to BleepingComputer. Older licensing releases branded as Smart Software Manager will not receive a patch.

What to do

Cisco recommends upgrading NX-OS to a fixed release, which can be identified with its Software Checker tool. Where NX-API, NGOAM or MPLS OAM are not needed, disabling them removes the attack vector, and Cisco offers temporary Live Protect shields for switches that cannot yet be upgraded and rebooted. Cisco License users should upgrade to version 10-202609, and customers on older Smart Software Manager releases should migrate to a supported version. Administrators should also review the APIC, Meraki and Finesse advisories on Cisco's security portal.

Related CVEs

Sources

This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.