Cisco 7 Oct batch: five unauthenticated code-execution-as-root flaws (each CVSS 9.8) in Nexus 3000 and 9000 switches through NGOAM, MPLS OAM and NX-API, plus Critical hardening releases for NX-OS and the ACI controller (APIC); no exploitation known
Cisco published its scheduled October 2026 batch at 16:00 UTC on 7 October (midnight 8 October Perth). The headline items are three advisories for Nexus 3000 and Nexus 9000 switches running standalone NX-OS. Next Generation OAM (NGOAM), the VXLAN and SRv6 diagnostics feature, carries three flaws (CVE-2026-76485, CVE-2026-76486, CVE-2026-76501) where crafted IP packets sent to any IP interface let a remote attacker with no login run code as root or crash and reload the switch. MPLS OAM has the same outcome from a crafted MPLS echo-request (CVE-2026-76465). The NX-API management interface has a third path, a crafted HTTP request (CVE-2026-76471). All five score 9.8. Exposure depends on features: CVE-2026-76485 needs only NGOAM enabled, CVE-2026-76486 also needs SRv6 or NV Overlay with a VXLAN peer learned, CVE-2026-76501 also needs SRv6, and MPLS OAM and NX-API are both off by default. On UCS 6300 fabric interconnects the NX-API bug is reachable through the UCS Manager XML API with a low-privileged login, so Cisco rates it High there. In the same release Cisco grouped internally found bugs into Critical 'security hardening' advisories: NX-OS (six CVEs, top score 9.8 for CVE-2026-76455), APIC, the controller for Nexus 9000 in ACI mode (CVE-2026-76498, -76499 and -76500, each 9.8), and Meraki (seven CVEs, top 9.6). It also fixed a Finesse SSRF (CVE-2026-20362, 7.2) that Cisco says has been publicly described, and medium-rated NX-OS, APIC and ACI bugs. Cisco's own engineers found the switch flaws, and PSIRT knows of no public disclosure or malicious use of them. For Australian operators, these are core data-centre and campus switches, so treat the OAM and NX-API advisories as the priority on any switch where those features are on.
- Product
- Cisco Nexus 3000 and Nexus 9000 Series Switches (standalone NX-OS mode); UCS 6300 Series Fabric Interconnects (NX-API flaw only); Cisco APIC and Meraki (hardening releases)
- Versions
- Vulnerable NX-OS releases with NGOAM, MPLS OAM or NX-API enabled (check with 'show feature'). Nexus 9000 with a Silicon One ASIC cannot enable MPLS OAM. Not affected by the five RCEs: Nexus 7000, MDS 9000, Nexus 9000 in ACI mode, Firepower and Secure Firewall, UCS 6400/6500/6600 and UCS X-Series Direct fabric interconnects.
- CVSS
- (CVE-2026-76485, CVE-2026-76486, CVE-2026-76501, CVE-2026-76465, CVE-2026-76471); NX-OS hardening up to 9.8 (CVE-2026-76455); APIC hardening 9.8 (CVE-2026-76498/76499/76500); Meraki hardening up to 9.6 (CVE-2026-76464); Finesse 7.2 (CVE-2026-20362)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (NGOAM, MPLS OAM AND NX-API ON NEXUS) - Exploited in Australia?
- unknown
- Patch to
- Run each switch's NX-OS release through the Cisco Software Checker and move to the first fixed release it lists for all 7 October advisories. Until then: if NGOAM or MPLS OAM is not needed, 'no feature ngoam' and 'no feature mpls oam' remove the attack path (Cisco's stated mitigation); for NX-API there is no workaround, but Cisco has a temporary Live Protect shield for NX-OS 10.6(3), and NX-API should stay off or be reachable only from management networks. Patch APIC and Meraki to the releases named in their hardening advisories.
Primary: Cisco Security Advisory — Nexus 3000 and 9000 Series Switches NGOAM Remote Code Execution Vulnerabilities, cisco-sa-ngoam-rce-LWKQ4BU (7 Oct 2026) · Vendor: Cisco — Advance Notification for Publication of October 7, 2026, Security Advisories (full list of the batch) · CVE: CVE-2026-76485, CVE-2026-76486, CVE-2026-76501, CVE-2026-76465, CVE-2026-76471, CVE-2026-76455, CVE-2026-76498, CVE-2026-20362 · Cisco Security Advisory — NX-OS Software NX-API Remote Code Execution Vulnerability, cisco-sa-napi-rce-r2shwu2j (7 Oct 2026)
