DEV Community

Anoymask
Anoymask

Posted on

Cisco NX-OS: Four Critical Advisories Cover 11 CVEs, Including Root RCE and DoS

1. Basic Information

  • Article Title: Cisco Advance Notification for Publication of October 7, 2026, Security Advisories
  • Publisher: Cisco PSIRT
  • Publication Date: September 30, 2026 (Initial publication: September 30, 2026; updated / individual advisories published: October 7, 2026)
  • Original Source: Cisco PSIRT
  • Related Sources: NX-OS hardening release, MPLS OAM RCE, NGOAM RCE, NX-API RCE
  • Related Malware and Threat Groups: None specified
  • Related CVEs: CVE-2026-76453, CVE-2026-76455, CVE-2026-76456, CVE-2026-76457, CVE-2026-76458, CVE-2026-76459, CVE-2026-76465, CVE-2026-76471, CVE-2026-76485, CVE-2026-76486, CVE-2026-76501
  • Affected Products: Cisco NX-OS, Nexus 3000, Nexus 7000, Nexus 9000 (Standalone / ACI mode), MDS 9000, UCS Fabric Interconnect
  • Severity: Critical

2. Executive Summary

Cisco has published four critical advisories covering a total of 11 CVEs for NX-OS. Severity levels, authentication requirements, and configuration conditions vary by CVE and product, with some vulnerabilities potentially leading to pre-authentication root code execution or denial of service.

3. Attack Flow

RCE and DoS by Configuration

  1. An attacker reaches an affected NX-OS device and an enabled feature.
  2. The attacker sends a crafted HTTP request to NX-API, an echo-request to MPLS OAM, or a crafted IP packet to NGOAM.
  3. Successful exploitation may allow arbitrary code execution with root privileges or cause a process crash, depending on the vulnerability and the exploitation outcome.
  4. A process crash may cause a device reload and DoS. Successful code execution could enable subsequent changes to device configuration or interference with traffic. Cisco PSIRT reports no known malicious exploitation of these vulnerabilities.

4. Attacker Positioning and Execution Location

  • A remote attacker capable of sending packets to the management plane or the OAM/data plane. For UCS 6300, the attack routes through the UCS Manager XML API and requires valid low-privileged credentials.

5. Visibility for Victims and Administrators

  • Users: May experience network disruptions, packet loss, or service unavailability.
  • Administrators: Can observe abnormal NX-API requests, OAM packets, process crashes, core dumps, and switch reloads.

6. Success and Failure Conditions

Success Conditions

  • The common condition is using an affected product release described in each advisory and being able to reach the attack vector.
  • The six hardening CVEs affect target products regardless of device configuration. Individual bugs are not treated as uniform pre-authentication network RCEs.
  • CVE-2026-76465: MPLS OAM must be enabled on the target Nexus 3000 or 9000 standalone device.
  • CVE-2026-76485: NGOAM must be enabled on the target model.
  • CVE-2026-76486: SRv6 or NV Overlay must be enabled in addition to NGOAM. For the NV Overlay path, VNI mapping to the NVE interface and the learning of at least one peer VTEP are also required.
  • CVE-2026-76501: Both NGOAM and SRv6 must be enabled. The Nexus 3000 does not support SRv6.
  • CVE-2026-76471: NX-API must be enabled on Nexus 3000 or 9000 standalone devices. For UCS 6300, the attack routes through the UCS Manager XML API and requires valid low-privileged credentials.

Failure Conditions and Mitigations

  • The permanent remediation is updating to a fixed release. While official workarounds are not available, disabling unnecessary MPLS OAM and NGOAM features, as well as applying Live Protect shields that meet the conditions for MPLS OAM, NGOAM, and NX-API, are offered as temporary mitigations. Check each advisory for product and release conditions as well as operational impacts.
  • Minimize reachability to the management and OAM planes, and restrict exposure using ACLs and segmentation.

7. What Happens Upon Success

  • Arbitrary code execution with root privileges.
  • Process crashes, device reloads, and network denial of service.
  • Potential subsequent impacts on switch configuration, traffic visibility, and segmentation.

8. Observable Logs

The following items are candidates for investigation within your organization and do not necessarily mean all of them were observed in this incident:

  • Email: No email vectors specific to this issue have been confirmed.
  • Proxy / SWG / DNS: Check for abnormal HTTP requests to NX-API and management access logs.
  • Endpoint / EDR: Check for NX-OS process crashes, core dumps, reloads, and unexpected configuration changes.
  • Identity / IdP: Check for unusual logins, token and credential usage, permission changes, and service account operations.
  • SaaS / Cloud: Check management APIs, audit logs, repository and cloud resource access, and large downloads.
  • Network: Check for abnormal packets and control-plane spikes related to MPLS echo, NGOAM, and SRv6/NVE.

9. Determining Attack Success

Confirmed in Public Information

  • Cisco PSIRT states that it is not aware of any exploitation in the targeted advisories. This is not a report of observed attack attempts or successful compromises.

Criteria for Internal Determination

  • Assess suspicious packets and requests against the target model, release, and configuration to determine attack attempts.
  • Confirm crashes, core dumps, and reloads as evidence of availability impacts. Do not assume root code execution based on these events alone.
  • Determine code execution by correlating evidence of unauthorized process or command execution with requests and packets.
  • Collate requests, processes, authentication, data access, and outbound transmissions to distinguish between attack attempts and successes.
  • Do not infer a successful compromise not present in public information based solely on HTTP status codes or a single alert.

10. Investigation Playbook

  • Starting Point of Investigation: Begin with abnormal NX-API requests, OAM packets, process crashes, and switch reloads.
  • Initial Verification: Verify the target product, version, configuration, external reachability, exposure duration, and update or containment timestamps.
  • Endpoint / Server Investigation: Check feature states, running configurations, crashinfo, core files, syslogs, AAA, and configuration archives.
  • Authentication / Cloud Investigation: Check for suspicious accounts, tokens, and API usage, privilege changes, unusual source connections, and resource access.
  • Subsequent Operations: Track credential access, lateral movement, additional downloads, outbound transmissions, and account creation following the initial event.
  • Containment: Restrict access to the affected plane, switch to redundant systems, and update to a fixed release.
  • Determination Categories: Separate reconnaissance and attack attempts, initial execution, successful authentication, information theft, and subsequent compromises.

11. Defense and Detection Ideas

  • Single Event: Detect abnormal NX-API requests, OAM parser crashes, and unexpected reloads.
  • Chronological Correlation: Correlate crafted traffic -> process crash or root action -> configuration change or reload -> network impact.
  • Threat Hunting: Search all Nexus, MDS, and UCS models, releases, feature states, and historical crashes.
  • Log Limitations: Payload visibility is limited by encrypted management traffic and hardware forwarding. Device telemetry is required.
  • Priority Mitigations: Prioritize fixed releases, management plane ACLs, feature minimization, redundancy, and configuration backups.

12. Facts, Inferences, and Hypotheses

Facts

  • The four NX-OS advisories rated Critical in Cisco's October 7, 2026, publication cover 11 CVE IDs, with a maximum CVSS v3.1 score of 9.8.
  • CVE-2026-76465 in MPLS OAM can lead to pre-authentication root RCE or DoS via crafted MPLS echo-requests when the feature is enabled.
  • Three CVEs in NGOAM can lead to pre-authentication root RCE or DoS via crafted IP packets when the feature and, in some cases, SRv6 or NV Overlay are enabled.
  • CVE-2026-76471 in NX-API allows pre-authentication root RCE or DoS via crafted HTTP requests when the feature is enabled on Nexus devices. UCS 6300 requires low-privileged credentials.
  • The hardening advisory groups six CWE classes into six CVEs, and affected products are impacted regardless of configuration.
  • The permanent remediation is updating to a fixed release. While official workarounds are not available, disabling unnecessary MPLS OAM and NGOAM features, as well as applying Live Protect shields that meet the conditions, are offered as temporary mitigations. At publication, Cisco PSIRT stated that it was not aware of public announcements or malicious use of the vulnerabilities described in these advisories.

Inference

  • Because data and OAM plane packets, as well as management APIs, serve as attack surfaces, evaluate reachability not only from internet exposure but also from adjacent networks and tenants.
  • Avoid combining 11 CVEs into a single version check; inventory feature states, models, and modes to determine patch priorities.

Hypotheses

No additional hypotheses. Unverified items are listed in "Open Questions and Further Investigation."

13. MITRE ATT&CK Mappings

ID Technique Confidence Basis
T1190 Exploit Public-Facing Application medium Conditional mapping for initial access through an internet-facing vulnerable service, such as NX-API. Network reachability alone does not establish applicability. No exploitation has been reported by Cisco PSIRT.
T1499.004 Endpoint Denial of Service: Application or System Exploitation high Process crashes, device reloads, and DoS are included in the official impacts.

14. Open Questions and Further Investigation

  • Triggers for individual underlying bugs, public PoCs, and confirmation of active exploitation.
  • Network compatibility and maintenance impacts resulting from upgrades to each fixed release.
  • The specific scope to which AI-assisted internal testing contributed to the discovery and verification of each CVE.

15. Impact on SOCs and Organizations

Organizations using Nexus switches in data centers or campus cores face wide-scale communication outages if a switch takeover or reload occurs. Use show feature to check for NX-API, MPLS OAM, NGOAM, SRv6, and NVE. For the NV Overlay path in CVE-2026-76486, verify VNI mappings and peer VTEPs in NVE rather than relying solely on show feature. Determine the fixed versions for each model and release using the Cisco Software Checker.

16. Summary by Audience

  • For SOCs: Monitor management HTTP, MPLS echo, NGOAM/SRv6 packets, process crashes, reloads, and configuration changes.
  • For Administrators: Inventory models, modes, and feature states, and update to the Cisco-specified fixed releases. Until updates can be applied, consider disabling unnecessary features or deploying Live Protect shields where supported and applicable to the device and release.
  • For Users: No user actions are required. Report network disruptions to administrators.

Top comments (1)

Some comments may only be visible to logged-in visitors. Sign in to view all comments.