Threat reportVulnerabilityTL-2026-3082

Cisco Nexus 3000/9000 NX-OS and Cisco License (Smart Software Manager On-Prem) critical flaws enabling switch takeover (CVE-2026-76471, CVE-2026-76480, CVE-2026-76482 and others)

criticalTRACKING

Cisco Nexus 3000/9000 NX-OS and Cisco License (Smart (TL-2026-3082), also tracked as cisco-sa-napi-rce-r2shwu2j, is a critical-severity software vulnerability scored CVSS 10, first published 2026-10-09. It has no confirmed attribution, affects Cisco Nexus 3000 Series Switches (NX-OS), references 9 CVEs (CVE-2026-76471, CVE-2026-76485, CVE-2026-76486), maps to 5 MITRE ATT&CK techniques (T1059, T1190, T1499.004), and is covered by 9 detection rules and 6 indicators of compromise.

CVSS
10/10Critical
CVEs
9Referenced vulnerabilities
Techniques
5MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
6Indicators of compromise

Key facts for TL-2026-3082

Threat ID
TL-2026-3082
Also known as
cisco-sa-napi-rce-r2shwu2j, cisco-sa-ngoam-rce-LWKQ4BU, cisco-sa-moam-rce-uBTzYV7, cisco-sa-hardening-ssm-Ph77wdhf
Severity
CRITICAL
CVSS
10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Status
TRACKING
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
telecoms, enterprise, data-center, dns service provider
Target regions
Global
Detection rules
9
Indicators of compromise
6

Malware and tooling in Cisco Nexus 3000/9000 NX-OS and Cisco License (Smart

Malware and tooling: Nexus

How Cisco Nexus 3000/9000 NX-OS and Cisco License (Smart works

Cisco disclosed unauthenticated remote code execution flaws in the NX-API, NGOAM and MPLS OAM features of Nexus 3000/9000 switches in standalone NX-OS mode (CVSS 9.8), plus four critical/high flaws in Cisco License On-Prem (formerly Smart Software Manager On-Prem) with CVSS up to 10.0. Cisco PSIRT is not aware of public announcements or malicious exploitation.

On 7 October 2026 Cisco published advisories covering two product families. The first set affects Cisco Nexus 3000 Series and Nexus 9000 Series switches running standalone NX-OS (Nexus 7000 and Nexus 9000 in ACI mode are not affected). CVE-2026-76471 (cisco-sa-napi-rce-r2shwu2j, CWE-122 heap-based buffer overflow) lets an unauthenticated remote attacker send crafted HTTP requests to NX-API, which is disabled by default, to execute arbitrary code as root or crash the device. The same advisory lists UCS 6300 Series Fabric Interconnects, where the XML API is enabled by default and exploitation requires low-privileged credentials; fixed in release 4.3(6j), and release 4.2 and earlier must migrate to a fixed release.

CVE-2026-76485, CVE-2026-76486 and CVE-2026-76501 (cisco-sa-ngoam-rce-LWKQ4BU, CWE-121 stack-based buffer overflow) stem from improper input validation of IP traffic in the NGOAM (Operation, Administration, and Maintenance) feature. CVE-2026-76485 requires only NGOAM enabled; CVE-2026-76486 requires NGOAM plus SRv6 or NV Overlay with VXLAN EVPN VNI; CVE-2026-76501 requires NGOAM plus SRv6. An unauthenticated attacker sending crafted packets can obtain root-level code execution or cause denial of service. CVE-2026-76465 (cisco-sa-moam-rce-uBTzYV7, CWE-590) is in the MPLS OAM feature (disabled by default): a crafted MPLS echo-request sent to an IP address on the device can yield root code execution or DoS. All four NX-OS advisories carry CVSS 3.1 base score 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). No permanent workarounds exist; disabling the features (no feature ngoam, no feature mpls oam) mitigates, and Cisco offers Live Protect shields as temporary mitigation. Fixed releases are determined with the Cisco Software Checker.

The second set, cisco-sa-hardening-ssm-Ph77wdhf, covers Cisco License On-Prem (formerly Smart Software Manager On-Prem), versions 9-202601 and earlier and 10-202608 and earlier: CVE-2026-76480 (9.8, CWE-306 missing authentication), CVE-2026-76482 (10.0, CWE-347 improper cryptographic signature verification), CVE-2026-76483 (9.1, CWE-522 insufficiently protected credentials) and CVE-2026-76484 (8.8, CWE-94 code injection). The first fixed release on the 10.x line is 10-202609; 9-202601 and earlier must migrate. No workarounds exist. Cisco states the issues were found during an internal security review using existing testing processes as well as frontier AI models.

Cisco PSIRT reports it is not aware of public announcements or malicious use of any of these vulnerabilities, and no public PoC or attribution has been reported. A switch or license-server takeover would give an attacker root on core network infrastructure or control of the licensing platform, so exposure of the NX-API, NGOAM and MPLS OAM features and the License On-Prem management interface should be reviewed and patching prioritised.

MITRE ATT&CK techniques used in TL-2026-3082

Execution

T1059 Command and Scripting Interpreter

Initial Access

T1190 Exploit Public-Facing Application

Impact

T1499.004 Application or System Exploitation

Credential Access

T1552 Unsecured Credentials

defense-impairment

T1553 Subvert Trust Controls

Affected products and versions in Cisco Nexus 3000/9000 NX-OS and Cisco License (Smart

  • Cisco — Nexus 3000 Series Switches (NX-OS)
    Vulnerable versions: Standalone NX-OS mode with NX-API, NGOAM or MPLS OAM enabled
    Fixed in: See Cisco Software Checker
  • Cisco — Nexus 9000 Series Switches (standalone NX-OS mode)
    Vulnerable versions: Standalone NX-OS mode with NX-API, NGOAM or MPLS OAM enabled
    Fixed in: See Cisco Software Checker
  • Cisco — UCS 6300 Series Fabric Interconnects
    Vulnerable versions: 4.3 before 4.3(6j); 4.2 and earlier
    Fixed in: 4.3(6j)
  • Cisco — Cisco License On-Prem (formerly Smart Software Manager On-Prem)
    Vulnerable versions: 9-202601 and earlier; 10-202608 and earlier
    Fixed in: 10-202609

Remediation for Cisco Nexus 3000/9000 NX-OS and Cisco License (Smart

Patches

  • Upgrade Cisco NX-OS to the fixed release identified by the Cisco Software Checker
  • Upgrade Cisco License On-Prem to 10-202609 or later
  • Upgrade UCS 6300 Series Fabric Interconnects to 4.3(6j); migrate from 4.2 and earlier

Immediate actions

  • Disable NGOAM (no feature ngoam), MPLS OAM (no feature mpls oam) and NX-API on Nexus 3000/9000 switches where not required
  • Restrict network reachability of NX-API, NGOAM and MPLS OAM traffic and the Cisco License On-Prem management interface to trusted management networks
  • Apply Cisco Live Protect shields as temporary protection on devices that cannot be upgraded immediately

Workarounds

  • No workarounds exist for Cisco License On-Prem or NX-API
  • Disabling NGOAM or MPLS OAM mitigates the respective flaws but is not an official workaround

Longer-term hardening

  • Use the Cisco Software Checker to identify the fixed NX-OS release for each Nexus 3000/9000 and schedule upgrades
  • Inventory Cisco License On-Prem (formerly SSM On-Prem) instances and migrate 9-202601 and earlier to a fixed release

CVEs associated with Cisco Nexus 3000/9000 NX-OS and Cisco License (Smart

CVE-2026-76471, CVE-2026-76485, CVE-2026-76486, CVE-2026-76501, CVE-2026-76465, CVE-2026-76480, CVE-2026-76482, CVE-2026-76483, CVE-2026-76484

Weaknesses (CWE) in Cisco Nexus 3000/9000 NX-OS and Cisco License (Smart

CWE-122, CWE-121, CWE-590, CWE-306, CWE-347, CWE-522, CWE-94

Timeline of Cisco Nexus 3000/9000 NX-OS and Cisco License (Smart

  • Cisco PSIRT states it is not aware of public announcements or malicious exploitation of any of the flaws, which were found in internal testing that included frontier AI models
  • Cisco publishes cisco-sa-hardening-ssm-Ph77wdhf for Cisco License On-Prem flaws CVE-2026-76480, CVE-2026-76482, CVE-2026-76483 and CVE-2026-76484 (CVSS up to 10.0); fixed in 10-202609
  • Cisco publishes cisco-sa-moam-rce-uBTzYV7 for CVE-2026-76465, an MPLS OAM echo-request RCE/DoS flaw (CVSS 9.8)
  • Cisco publishes cisco-sa-ngoam-rce-LWKQ4BU for NGOAM stack overflow flaws CVE-2026-76485, CVE-2026-76486 and CVE-2026-76501 (CVSS 9.8)
  • Cisco publishes cisco-sa-napi-rce-r2shwu2j for CVE-2026-76471, an NX-API heap overflow RCE (CVSS 9.8) in NX-OS on Nexus 3000/9000 and UCS 6300
  • BleepingComputer reports on the Nexus switch takeover flaws and Cisco License vulnerabilities

Sources cited for Cisco Nexus 3000/9000 NX-OS and Cisco License (Smart

Detection coverage for TL-2026-3082

As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3082 across Splunk SPL, Microsoft KQL and Sigma, covering 6 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
6 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats