Cisco Patches Critical RCE Vulnerabilities in NX-OS Software
Article Content
- •Cisco patched five critical CVEs (CVSS 9.8) in NX-OS software on October 7, 2026.
- •Vulnerabilities allow unauthenticated remote code execution or denial of service.
- •No workarounds are available; immediate patching is recommended.
On October 7, 2026, Cisco released advisories addressing five critical vulnerabilities (CVSS 9.8) in NX-OS software affecting Nexus 3000 and 9000 switches. These vulnerabilities allow unauthenticated remote attackers to execute arbitrary code with root privileges or cause denial of service (DoS) conditions. The flaws include CVE-2026-76465, CVE-2026-76485, CVE-2026-76486, CVE-2026-76501, and CVE-2026-76471, with specific attack vectors involving crafted MPLS echo-requests and HTTP requests to the NX-API. Cisco has confirmed that there are no workarounds available and has released fixed NX-OS software. The NX-API feature is disabled by default on Nexus 3000 and 9000 switches, but exploitation on UCS 6300 Series Fabric Interconnects requires valid low-privileged user credentials. Cisco's PSIRT has not reported any public exploitation or malicious use of these vulnerabilities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2026-76465 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which products are affected?
Are there any workarounds available?
What should organizations do now?
Continue Reading
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…