Skip to content
ThreatCluster

Cisco Patches Critical RCE Vulnerabilities in NX-OS Software

First seen 7 Oct 2026, 21:33 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 7, 2026 at 21:34 UTC
  • •Cisco patched five critical CVEs (CVSS 9.8) in NX-OS software on October 7, 2026.
  • •Vulnerabilities allow unauthenticated remote code execution or denial of service.
  • •No workarounds are available; immediate patching is recommended.

On October 7, 2026, Cisco released advisories addressing five critical vulnerabilities (CVSS 9.8) in NX-OS software affecting Nexus 3000 and 9000 switches. These vulnerabilities allow unauthenticated remote attackers to execute arbitrary code with root privileges or cause denial of service (DoS) conditions. The flaws include CVE-2026-76465, CVE-2026-76485, CVE-2026-76486, CVE-2026-76501, and CVE-2026-76471, with specific attack vectors involving crafted MPLS echo-requests and HTTP requests to the NX-API. Cisco has confirmed that there are no workarounds available and has released fixed NX-OS software. The NX-API feature is disabled by default on Nexus 3000 and 9000 switches, but exploitation on UCS 6300 Series Fabric Interconnects requires valid low-privileged user credentials. Cisco's PSIRT has not reported any public exploitation or malicious use of these vulnerabilities.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-07
Cisco releases advisories for NX-OS vulnerabilities
Cisco published advisories addressing five critical vulnerabilities in NX-OS software affecting Nexus 3000 and 9000 switches.
Sec.Cloudapps.Cisco
2026-10-07
Critical CVEs published
CVE-2026-76465, CVE-2026-76485, CVE-2026-76486, CVE-2026-76501, and CVE-2026-76471 were published, all rated CVSS 9.8.
X
2026-10-07
CVE-2026-76501 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-07
CVE-2026-76485 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-07
CVE-2026-76465 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-07
CVE-2026-76486 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-10-07
CVE-2026-76471 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (3)

Following this threat?

Track CVE-2026-76465 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which products are affected?
The vulnerabilities affect Cisco Nexus 3000 and 9000 Series switches, as well as UCS 6300 Series Fabric Interconnects.
Are there any workarounds available?
No, Cisco has stated that there are no workarounds for these vulnerabilities.
What should organizations do now?
Organizations should apply the available patches for NX-OS software immediately to mitigate the risks.