Skip to content
Cisco NX-OS Vulnerabilities Enable Unauthenticated RCE Attacks

Cisco NX-OS Vulnerabilities Enable Unauthenticated RCE Attacks

First seen 9 Oct 2026, 17:38 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 9, 2026 at 18:40 UTC

Cisco disclosed three critical vulnerabilities (CVE-2026-76485, CVE-2026-76486, CVE-2026-76501) in its NX-OS software on October 7, 2026, allowing unauthenticated remote code execution across Nexus 3000 and 9000 switches. All three CVEs have a CVSS score of 9.8, indicating a critical severity level. The vulnerabilities stem from stack-based buffer overflows due to improper input validation when the NGOAM feature is enabled. Attackers can exploit these flaws by sending crafted packets to an IP interface on the affected devices. Cisco's advisory states there are no workarounds available, and the vulnerabilities affect NX-OS versions 9.2 through 10.6. The advisory emphasizes that the only requirement for exploitation is having NGOAM enabled. The vulnerabilities are particularly concerning due to their potential for widespread impact on network infrastructure. As of now, there are no reports of in the wild.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-07
Cisco discloses NX-OS vulnerabilities
Cisco announced three critical vulnerabilities allowing unauthenticated RCE in NX-OS software affecting Nexus switches.
Tech.Yahoo
2026-10-07
CVE-2026-76486 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-07
CVE-2026-76501 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-07
CVE-2026-76485 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (2)

Following this threat?

Track CVE-2026-76485 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of NX-OS are affected?
NX-OS versions 9.2 through 10.6 are affected, specifically on Nexus 3000 and 9000 switches.
Are these vulnerabilities being exploited?
Currently, there are no reports of active exploitation in the wild.
What should organizations do now?
Organizations should review their configurations to determine if NGOAM is enabled and apply necessary security measures.