Canadian Cyber Security Journal
SOCIAL:
Filed under: TechTalk

Five Critical Cisco NX-OS Flaws Allow Root Code Execution on Nexus Switches: What Canadian Network Teams Must Check

What Happened

Cisco published advisories for five critical flaws in NX-OS, the operating system on Nexus switches. BleepingComputer reports an attacker gains arbitrary code execution as root. When code execution fails, the flaws crash processes and force a reload, which causes denial of service.

The flaws affect Nexus 3000 and Nexus 9000 switches in standalone NX-OS mode. Each depends on a feature being active. CVE-2026-76471 hits NX-API through a crafted HTTP request, and NX-API is off by default. CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501 hit NGOAM through crafted IP packets. CVE-2026-76465 hits MPLS OAM through crafted echo-request packets. Nexus 7000 switches and Nexus 9000 switches in ACI mode are not affected. Cisco found the flaws in internal testing and knows of no exploitation.

Why This Matters for Canadian Organizations

Nexus switches carry traffic in data centres across enterprises, carriers, and government networks. Root access on a core switch lets an attacker watch or redirect traffic between systems. Teams often leave NGOAM switched on for troubleshooting, so a default-off rating gives limited comfort without a configuration check.

Federally regulated institutions face OSFI Guideline B-13 expectations on patching and vulnerability management. Critical infrastructure operators should expect the same questions under Bill C-26. Cisco also fixed four flaws in Cisco License, formerly Smart Software Manager, including CVE-2026-76482 with a CVSS score of 10.0. The fix is version 10-202609, and no workaround exists.

What to Do

Inventory every Nexus 3000 and 9000 switch and confirm the mode. Run Cisco’s Software Checker to find the fixed release. Disable NGOAM, NX-API, and MPLS OAM wherever you do not need them. Apply Cisco’s Live Protect shields to switches awaiting upgrades. Upgrade Cisco License to 10-202609 or migrate off unsupported releases. See more in our TechTalk coverage and daily briefs.

Enjoy this article? Don’t forget to share.