Before you book the Nexus upgrade, check which of Cisco’s four critical NX-OS advisories actually apply to your switches

By George Bailey   Published: 10/08/26   5 min read

Cisco’s scheduled first-Wednesday release landed on October 7, and most of it is about the switches in your data center. Four critical NX-OS advisories, each scored 9.8, describe ways an unauthenticated attacker could run code as root on Nexus gear. One batch applies no matter how the switch is configured. The other three depend on features many shops never turn on. So before you book the outage, spend ten minutes finding out which ones you actually run.

Nobody is exploiting these yet. That’s what makes this a scheduled patch and not a 2 a.m. call. Keep it that way.

What happened

At 16:00 GMT on October 7 (noon ET), Cisco published the bundle it had pre-announced on September 30. The NX-OS portion includes:

The same release covered Cisco APIC (a critical hardening release) and Cisco License On-Prem, formerly Smart Software Manager On-Prem. On License On-Prem, CVE-2026-20328 lets an unauthenticated attacker reset any account’s password, admins included, and CVE-2026-76454 allows unauthenticated file writes through an API. Both score 9.1 and are fixed in 10-202608. Cisco says it is not aware of exploitation or public announcements for any of these.

Why it matters

Core switches are the gear everyone means to patch and nobody wants to reboot. A root-level bug in NX-OS means control of the box that carries everything else. The feature-gated bugs are less scary if you never enabled NX-API, NGOAM or MPLS OAM. But “I don’t think we use that” isn’t the same as checking, and VXLAN EVPN fabrics are exactly where NGOAM tends to get switched on.

License On-Prem is the quieter risk. It’s a web app, often reachable from more places than it should be, and an unauthenticated password reset is the kind of bug that gets weaponized fast once someone reads the fix.

What to do first

Forward this

For whoever owns our data-center network: Cisco released critical NX-OS fixes on October 7 for Nexus 3000/7000/9000, MDS and UCS fabric interconnects. Nothing is exploited yet. Please check whether NX-API, NGOAM or MPLS OAM is enabled, and get an upgrade window on the calendar.

Details

Hunt / verify

Slack paste: Cisco Oct 7 bundle: four critical (9.8) NX-OS advisories (hardening release for any config, plus NX-API, NGOAM, MPLS OAM if enabled) on Nexus 3000/7000/9000, MDS, UCS FIs. Not exploited. Check show feature, disable what you don’t use, plan to Combined First Fixed. License On-Prem to 10-202608 (unauth password reset).

Sources

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.