Cisco’s scheduled first-Wednesday release landed on October 7, and most of it is about the switches in your data center. Four critical NX-OS advisories, each scored 9.8, describe ways an unauthenticated attacker could run code as root on Nexus gear. One batch applies no matter how the switch is configured. The other three depend on features many shops never turn on. So before you book the outage, spend ten minutes finding out which ones you actually run.
Nobody is exploiting these yet. That’s what makes this a scheduled patch and not a 2 a.m. call. Keep it that way.
What happened
At 16:00 GMT on October 7 (noon ET), Cisco published the bundle it had pre-announced on September 30. The NX-OS portion includes:
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
- NX-OS Security Hardening Release: October 2026. These are internally found bugs grouped by weakness class into six CVEs (CVE-2026-76453, -76455, -76456, -76457, -76458, -76459). The top score is 9.8 for improper access control and out-of-bounds write. They affect MDS 9000, Nexus 3000, Nexus 7000, Nexus 9000 in ACI and standalone mode, and UCS 6300/6400/6500/6600 and 9108 100G fabric interconnects, regardless of configuration. Cisco says frontier AI models helped find some of them.
- NX-API remote code execution (CVE-2026-76471). A crafted HTTP request to NX-API can run code as root on Nexus 3000 and standalone Nexus 9000. NX-API is off by default on those switches. On UCS 6300 fabric interconnects the same bug needs low-privileged credentials, so Cisco rates it High there.
- NGOAM remote code execution (CVE-2026-76485, -76486, -76501). Crafted packets to an IP interface can run code as root when Next Generation OAM is enabled. CVE-2026-76485 needs only NGOAM. The other two also need SRv6 or a live VXLAN EVPN overlay.
- MPLS OAM remote code execution (CVE-2026-76465). A crafted MPLS echo-request can run code as root when MPLS OAM is enabled. It’s off by default, and Nexus 9000 switches with Silicon One ASICs can’t run it at all.
The same release covered Cisco APIC (a critical hardening release) and Cisco License On-Prem, formerly Smart Software Manager On-Prem. On License On-Prem, CVE-2026-20328 lets an unauthenticated attacker reset any account’s password, admins included, and CVE-2026-76454 allows unauthenticated file writes through an API. Both score 9.1 and are fixed in 10-202608. Cisco says it is not aware of exploitation or public announcements for any of these.
Why it matters
Core switches are the gear everyone means to patch and nobody wants to reboot. A root-level bug in NX-OS means control of the box that carries everything else. The feature-gated bugs are less scary if you never enabled NX-API, NGOAM or MPLS OAM. But “I don’t think we use that” isn’t the same as checking, and VXLAN EVPN fabrics are exactly where NGOAM tends to get switched on.
License On-Prem is the quieter risk. It’s a web app, often reachable from more places than it should be, and an unauthenticated password reset is the kind of bug that gets weaponized fast once someone reads the fix.
What to do first
- On every Nexus 3000/9000 in standalone mode, run
show feature | include nxapi,show feature | include ngoamandshow feature | include mpls_oam. If you find NGOAM, also checknveandsrv6. - If a feature isn’t needed, turn it off. Cisco lists
no feature ngoamandno feature mpls oamas mitigations. Test first, as Cisco advises. - Put each platform’s release into the Cisco Software Checker and plan to the “Combined First Fixed” release so one upgrade clears all four advisories. For the hardening release on Nexus 3000/9000 standalone, the first fixed releases are 10.3(10), 10.4(8), 10.5(6) and 10.6(4).
- Where you can’t upgrade soon, Cisco has published Live Protect shields for the NX-API, NGOAM and MPLS OAM bugs as a temporary bridge.
- Upgrade Cisco License On-Prem to 10-202608 or later, and keep its web interface off general user networks.
Forward this
For whoever owns our data-center network: Cisco released critical NX-OS fixes on October 7 for Nexus 3000/7000/9000, MDS and UCS fabric interconnects. Nothing is exploited yet. Please check whether NX-API, NGOAM or MPLS OAM is enabled, and get an upgrade window on the calendar.
Details
- Published: October 7, 2026, 16:00 GMT (Cisco risk-based disclosure schedule: first and third Wednesday each month).
- Hardening release fixed versions: Nexus 3000/9000 standalone 10.3(10), 10.4(8), 10.5(6), 10.6(4); Nexus 7000 8.4(14); MDS 9000 9.4(5a); Nexus 9000 ACI 16.0(9h), 16.1(6g), 16.2(3g); UCS fabric interconnects 4.3(6j) / 6.0(2e) in UCS Manager mode. Older trains: migrate.
- NX-API (CVE-2026-76471): CVSS 9.8; Nexus 3000, Nexus 9000 standalone, UCS 6300 FI (High, needs creds). NX-API disabled by default on Nexus. UCS 6300 fix: 4.3(6j).
- NGOAM (CVE-2026-76485, -76486, -76501): CVSS 9.8; Nexus 3000 and Nexus 9000 standalone with NGOAM enabled (plus SRv6 or NV Overlay for the latter two).
- MPLS OAM (CVE-2026-76465): CVSS 9.8; Nexus 3000 and Nexus 9000 standalone with MPLS OAM enabled (disabled by default; not on Silicon One).
- License On-Prem: CVE-2026-20328 (unauthenticated password reset) and CVE-2026-76454 (unauthenticated API file write / DoS), both CVSS 9.1; fixed in 10-202608.
- Not affected by the feature-gated bugs: Nexus 7000, Nexus 9000 in ACI mode, MDS 9000, Firepower and Secure Firewall lines (per each advisory’s list).
- Exploitation: None known, per Cisco PSIRT.
Hunt / verify
- Pull
show featureoutput from every switch into one sheet. One unexplained “enabled” line is worth an afternoon. - Look for unexpected reloads or process crashes in switch logs. Cisco notes that failed exploitation can crash processes and reload the device.
- Confirm NX-API, if used, is reachable only from management networks.
- After upgrading, re-run the Software Checker against the new release to make sure all October 7 advisories show as fixed.
Slack paste: Cisco Oct 7 bundle: four critical (9.8) NX-OS advisories (hardening release for any config, plus NX-API, NGOAM, MPLS OAM if enabled) on Nexus 3000/7000/9000, MDS, UCS FIs. Not exploited. Check show feature, disable what you don’t use, plan to Combined First Fixed. License On-Prem to 10-202608 (unauth password reset).
Sources
- Cisco: Advance Notification for Publication of October 7, 2026, Security Advisories
- Cisco: NX-OS Software Security Hardening Release: October 2026
- Cisco: NX-OS Software NX-API Remote Code Execution Vulnerability
- Cisco: Nexus 3000 and 9000 Series Switches NGOAM Remote Code Execution Vulnerabilities
- Cisco: Nexus 3000 and 9000 Series Switches MPLS OAM Remote Code Execution Vulnerability
- Cisco: License (Smart Software Manager) On-Prem Vulnerabilities
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.