Cisco warns of critical flaws allowing Nexus switch takeover
Cisco disclosed five critical NX-OS flaws that can give root code execution on Nexus 3000 and 9000 switches.
Cisco disclosed five critical NX-OS flaws that could let an attacker run arbitrary code as root on standalone Nexus 3000 and Nexus 9000 switches, or crash processes and force a reload. The bugs, CVE-2026-76471, CVE-2026-76485, CVE-2026-76486, CVE-2026-76501, and CVE-2026-76465, require NX-API, NGOAM, or MPLS OAM to be enabled. Cisco found them internally and said it knew of no malicious exploitation. Separate Cisco License issues include CVE-2026-76482 at CVSS 10.0 and CVE-2026-76480 at CVSS 9.8, fixed in release 10-202609.
82