Cisco's October 7 NX-OS Advisory Wave Fixes Five Unauthenticated Root Code-Execution Bugs in Nexus Switches — Plus a CVSS 10.0 License On-Prem Flaw That No Configuration Can Mitigate

Cisco's October 7 NX-OS Advisory Wave Fixes Five Unauthenticated Root Code-Execution Bugs in Nexus Switches — Plus a CVSS 10.0 License On-Prem Flaw That No Configuration Can Mitigate

Cisco's October 7 NX-OS Advisory Wave Fixes Five Unauthenticated Root Code-Execution Bugs in Nexus Switches — Plus a CVSS 10.0 License On-Prem Flaw That No Configuration Can Mitigate

Cisco published its October 7, 2026 security advisory wave on Wednesday, shipping fixes for 35 vulnerabilities across its portfolio — more than a dozen of them critical. The headline for data center teams: five NX-OS flaws that let an unauthenticated, remote attacker execute arbitrary code with root privileges or crash and reload Nexus 3000 and Nexus 9000 series switches running in standalone NX-OS mode.

Three of the five live in the Next Generation OAM (NGOAM) feature, tracked as CVE-2026-76485, CVE-2026-76486 and CVE-2026-76501 (all CVSS 9.8). They stem from improper validation of IP traffic when NGOAM is enabled and are triggered by crafted packets sent to an IP interface on an affected switch. The requirements scale with the CVE: 76485 needs only NGOAM enabled, 76486 additionally requires Segment Routing over IPv6 (SRv6) or an NV Overlay with a VXLAN EVPN VNI mapped to an NVE interface and a learned peer VTEP, and 76501 requires both NGOAM and SRv6 — a feature only a subset of Nexus 9000 models support. The other two are CVE-2026-76465, an MPLS OAM flaw exploited via a crafted MPLS echo-request (the feature is disabled by default, and Nexus 9000 switches with Silicon One ASICs don't support it), and CVE-2026-76471, an NX-API flaw exploited through a crafted HTTP request to the NX-API interface — also disabled by default. All five were found during Cisco's internal security testing, and Cisco says it is not aware of public exploit announcements or malicious exploitation. There are no workarounds; Cisco offers temporary Live Protect shields for switches that cannot be upgraded and rebooted immediately, and recommends disabling NGOAM, NX-API and MPLS OAM where they are not needed.

The wave didn't stop at switching. Cisco patched eight bugs in License On-Prem (formerly Smart Software Manager), including CVE-2026-76482, an improper cryptographic signature verification flaw rated CVSS 10.0, and CVE-2026-76480, a missing-authentication flaw rated 9.8 — issues Cisco says leave affected releases vulnerable regardless of configuration. The fix is release 10-202609; older releases branded Smart Software Manager will never be patched, so legacy customers are told to migrate. Elsewhere in the drop: a Meraki hardening release covering seven CVEs led by CVE-2026-76464 (CVSS 9.6, buffer overflows and out-of-bounds writes), three critical APIC bugs (CVE-2026-76498, CVE-2026-76499, CVE-2026-76500, CVSS 9.8), a publicly disclosed Finesse SSRF (CVE-2026-20362), and an NX-OS Python sandbox escape (CVE-2026-20032).

The scale is the point. Cisco now publishes advisories on the first and third Wednesday of each month under its risk-based disclosure process — a predictable cadence built, as Cisco frames it, for AI-accelerated vulnerability discovery. And management-plane gear has been under real attack pressure all quarter: three threat groups were recently observed chaining FMC flaws into web shells and Qilin ransomware deployments, and Cisco ISE's CVSS 10.0 authentication bypass was exploited in the wild within days of its disclosure.

What Should You Do?

  1. Inventory before you patch: run show feature | include ngoam, show feature | include srv6 and show feature | include nve on every Nexus 3000/9000 to learn which of the five CVEs actually apply to your configs, then upgrade through the Cisco Software Checker.
  2. Disable what you don't use: no feature ngoam, and NX-API or MPLS OAM turned off where not needed, removes the attack vector entirely — every one of the five flaws depends on an optional feature being enabled.
  3. Patch License On-Prem to 10-202609 now — the CVSS 10.0 flaw is configuration-independent, and legacy Smart Software Manager releases get no fix at all.
  4. Bridge with Live Protect on switches that can't be rebooted this week, and treat PSIRT Wednesdays as scheduled patch windows — attackers read the calendar too.

The WAF Angle

A WAF cannot sit in front of a switch's NGOAM listener — this is control-plane exposure, not HTTP traffic. But the pattern generalizes across everything this site covers: features left enabled by accident are the real attack surface, and NX-API's HTTP interface is the one component here a reverse proxy or WAF can meaningfully front — restrict it to trusted management networks and never expose it. Cisco's Live Protect shields are essentially virtual patching: the same trade-off a WAF gives an application team — block the exploit shape now, fix the software when the window allows. And with disclosure now on a public twice-monthly schedule, edge teams should expect exploit research to spike in the days after each PSIRT drop, the same race we've documented for Citrix, Atlassian and Fortinet advisories all year.

Sources