Security · October 10, 2026

Cisco fixes 14 vulnerabilities in NX-OS, half rated critical

woman in black top using Surface laptop
Christina @ wocintechchat.com M / Unsplash

Cisco Systems has released a security update after multiple vulnerabilities were found in its network operating system, Cisco NX-OS Software. Some of these vulnerabilities are considered severe.

On October 7, 2026, local time, the company published seven security advisories related to this operating system, mentioning 14 vulnerabilities based on CVE. Among these advisories, four are rated as critical, while three are rated as medium.

The critical advisories include three vulnerabilities that could allow remote code execution. These vulnerabilities were identified mainly in the switches of the Cisco Nexus 3000 and Cisco Nexus 9000 series, affecting network operation monitoring features like NGOAM and MPLS OAM, as well as the management interface NX-API.

Upon reviewing the individual vulnerabilities in these advisories, seven were evaluated with a base score of 9.0 or higher according to the Common Vulnerability Scoring System (CVSSv3.1).

CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501 are linked to input validation issues in the operational maintenance functionality, NGOAM. These could potentially lead to code execution with root privileges or denial of service due to crafted IP packets, with some conditions depending on configurations like SRv6 or NV Overlay.