Trusence Every claim has a source
Last updated 8 October 2026 Search Türkçe
← All stories
Security

Cisco patches five critical NX-OS flaws that could let attackers take over Nexus switches

The bugs can also force switch reloads, and Cisco says some Nexus 7000 and ACI-mode systems are not affected.

Cisco has patched five critical NX-OS bugs that could let an attacker take over Nexus 3000 and Nexus 9000 switches with root privileges, or at minimum crash the device and force a reload. The flaws sit in NX-API, NGOAM, and MPLS OAM, and exploitation depends on those features being enabled; one issue also needs SRv6 or NV Overlay, while another only affects platforms that support MPLS OAM. Cisco says Nexus 7000 and Nexus 9000 systems in ACI mode are not affected, and it has published fixed NX-OS releases plus temporary Live Protect shields for devices that cannot be upgraded immediately. The company says it found the bugs internally and had no evidence of public disclosure or active exploitation when it issued the advisories. Cisco also issued fixes for Cisco License, including four high-severity problems, and recommends upgrading to version 10-202609 because older Smart Software Manager releases will not be patched.

Why it matters

For operators of Nexus 3000 and Nexus 9000 switches in standalone NX-OS mode, the patch closes a path to root-level compromise or service disruption. Cisco says the issues were found internally and were not known to be publicly disclosed or actively exploited, which gives teams some room to move, but not to delay. The advisories also separate affected from unaffected deployments, which matters for deciding where urgent upgrades are needed.

Sources

  • BleepingComputer