Cisco has disclosed five critical vulnerabilities in its NX-OS data center network operating system that could allow attackers to take control of Nexus switches. The flaws, detailed in security advisories released by the company, could be exploited to execute arbitrary code with root privileges on affected devices. If remote code execution is not achieved, the same flaws could be used to crash processes and force a device reload, creating a denial-of-service condition.

The vulnerabilities affect the NX-API, Next Generation OAM, and MPLS OAM features in Nexus 3000 and Nexus 9000 Series switches running in standalone NX-OS mode. Exploitation depends on at least one of those three features being active on the target device. All five issues stem from a validation failure, according to Cisco.

Some of the flaws carry additional conditions. CVE-2026-76486 also requires either Segment Routing over IPv6 or Network Virtualization Overlay to be enabled. Cisco's advisory states that NV Overlay additionally requires a VXLAN EVPN Network Identifier mapped to a Network Virtualization Endpoint interface with at least one peer VXLAN Tunnel Endpoint learned, such as through BGP EVPN or an ingress-replication static peer. CVE-2026-76501 is exploitable when SRv6 is turned on, a feature supported only on some Nexus 9000 models.

For CVE-2026-76465, MPLS OAM must be explicitly activated because it is disabled by default. Nexus 9000 switches with Silicon One ASICs do not support the feature and are not affected by that flaw. Cisco noted that Nexus 7000 switches and Nexus 9000 switches running in ACI mode are not affected by any of the five vulnerabilities.

Cisco recommends upgrading NX-OS releases to a fixed version identified through its Software Checker tool. The company also advises disabling NGOAM, NX-API, or MPLS OAM when those features are not needed, which eliminates the attack vector. For switches that cannot yet be upgraded and rebooted, Cisco is providing temporary Live Protect shields covering all five flaws.

All five vulnerabilities were found during internal security testing. Cisco said it was not aware of public announcements or malicious exploitation at the time the advisories were published.

Separately, Cisco released security hardening updates for Cisco License, formerly known as Smart Software Manager. Those issues include missing authentication for critical functions tracked as CVE-2026-76480 with a CVSS score of 9.8, improper cryptographic signature verification tracked as CVE-2026-76482 with a CVSS score of 10.0, insufficiently protected credentials tracked as CVE-2026-76483 with a CVSS score of 9.1, and code injection tracked as CVE-2026-76484 with a CVSS score of 8.8. Affected releases are vulnerable regardless of configuration, and Cisco recommends upgrading to version 10-202609, with no workarounds available. Older releases branded as Smart Software Manager will not receive a patch, and Cisco recommends migrating to a supported release in those cases.

More company and startup news from TechManNews.