Threat reportVulnerabilityTL-2026-3082
Cisco Nexus 3000/9000 NX-OS and Cisco License (Smart Software Manager On-Prem) critical flaws enabling switch takeover (CVE-2026-76471, CVE-2026-76480, CVE-2026-76482 and others)
Cisco Nexus 3000/9000 NX-OS and Cisco License (Smart (TL-2026-3082), also tracked as cisco-sa-napi-rce-r2shwu2j, is a critical-severity software vulnerability scored CVSS 10, first published 2026-10-09. It has no confirmed attribution, affects Cisco Nexus 3000 Series Switches (NX-OS), references 9 CVEs (CVE-2026-76471, CVE-2026-76485, CVE-2026-76486), maps to 5 MITRE ATT&CK techniques (T1059, T1190, T1499.004), and is covered by 9 detection rules and 6 indicators of compromise.
- CVSS
- 10/10Critical
- CVEs
- 9Referenced vulnerabilities
- Techniques
- 5MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 6Indicators of compromise
Key facts for TL-2026-3082
- Threat ID
- TL-2026-3082
- Also known as
- cisco-sa-napi-rce-r2shwu2j, cisco-sa-ngoam-rce-LWKQ4BU, cisco-sa-moam-rce-uBTzYV7, cisco-sa-hardening-ssm-Ph77wdhf
- Severity
- CRITICAL
- CVSS
- 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
- Status
- TRACKING
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- telecoms, enterprise, data-center, dns service provider
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 6
Malware and tooling in Cisco Nexus 3000/9000 NX-OS and Cisco License (Smart
Malware and tooling: Nexus
How Cisco Nexus 3000/9000 NX-OS and Cisco License (Smart works
Cisco disclosed unauthenticated remote code execution flaws in the NX-API, NGOAM and MPLS OAM features of Nexus 3000/9000 switches in standalone NX-OS mode (CVSS 9.8), plus four critical/high flaws in Cisco License On-Prem (formerly Smart Software Manager On-Prem) with CVSS up to 10.0. Cisco PSIRT is not aware of public announcements or malicious exploitation.
On 7 October 2026 Cisco published advisories covering two product families. The first set affects Cisco Nexus 3000 Series and Nexus 9000 Series switches running standalone NX-OS (Nexus 7000 and Nexus 9000 in ACI mode are not affected). CVE-2026-76471 (cisco-sa-napi-rce-r2shwu2j, CWE-122 heap-based buffer overflow) lets an unauthenticated remote attacker send crafted HTTP requests to NX-API, which is disabled by default, to execute arbitrary code as root or crash the device. The same advisory lists UCS 6300 Series Fabric Interconnects, where the XML API is enabled by default and exploitation requires low-privileged credentials; fixed in release 4.3(6j), and release 4.2 and earlier must migrate to a fixed release.
CVE-2026-76485, CVE-2026-76486 and CVE-2026-76501 (cisco-sa-ngoam-rce-LWKQ4BU, CWE-121 stack-based buffer overflow) stem from improper input validation of IP traffic in the NGOAM (Operation, Administration, and Maintenance) feature. CVE-2026-76485 requires only NGOAM enabled; CVE-2026-76486 requires NGOAM plus SRv6 or NV Overlay with VXLAN EVPN VNI; CVE-2026-76501 requires NGOAM plus SRv6. An unauthenticated attacker sending crafted packets can obtain root-level code execution or cause denial of service. CVE-2026-76465 (cisco-sa-moam-rce-uBTzYV7, CWE-590) is in the MPLS OAM feature (disabled by default): a crafted MPLS echo-request sent to an IP address on the device can yield root code execution or DoS. All four NX-OS advisories carry CVSS 3.1 base score 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). No permanent workarounds exist; disabling the features (no feature ngoam, no feature mpls oam) mitigates, and Cisco offers Live Protect shields as temporary mitigation. Fixed releases are determined with the Cisco Software Checker.
The second set, cisco-sa-hardening-ssm-Ph77wdhf, covers Cisco License On-Prem (formerly Smart Software Manager On-Prem), versions 9-202601 and earlier and 10-202608 and earlier: CVE-2026-76480 (9.8, CWE-306 missing authentication), CVE-2026-76482 (10.0, CWE-347 improper cryptographic signature verification), CVE-2026-76483 (9.1, CWE-522 insufficiently protected credentials) and CVE-2026-76484 (8.8, CWE-94 code injection). The first fixed release on the 10.x line is 10-202609; 9-202601 and earlier must migrate. No workarounds exist. Cisco states the issues were found during an internal security review using existing testing processes as well as frontier AI models.
Cisco PSIRT reports it is not aware of public announcements or malicious use of any of these vulnerabilities, and no public PoC or attribution has been reported. A switch or license-server takeover would give an attacker root on core network infrastructure or control of the licensing platform, so exposure of the NX-API, NGOAM and MPLS OAM features and the License On-Prem management interface should be reviewed and patching prioritised.
MITRE ATT&CK techniques used in TL-2026-3082
Execution
T1059 Command and Scripting Interpreter
Initial Access
T1190 Exploit Public-Facing Application
Impact
T1499.004 Application or System Exploitation
Credential Access
defense-impairment
Affected products and versions in Cisco Nexus 3000/9000 NX-OS and Cisco License (Smart
- Cisco — Nexus 3000 Series Switches (NX-OS)
Vulnerable versions: Standalone NX-OS mode with NX-API, NGOAM or MPLS OAM enabled
Fixed in: See Cisco Software Checker - Cisco — Nexus 9000 Series Switches (standalone NX-OS mode)
Vulnerable versions: Standalone NX-OS mode with NX-API, NGOAM or MPLS OAM enabled
Fixed in: See Cisco Software Checker - Cisco — UCS 6300 Series Fabric Interconnects
Vulnerable versions: 4.3 before 4.3(6j); 4.2 and earlier
Fixed in: 4.3(6j) - Cisco — Cisco License On-Prem (formerly Smart Software Manager On-Prem)
Vulnerable versions: 9-202601 and earlier; 10-202608 and earlier
Fixed in: 10-202609
Remediation for Cisco Nexus 3000/9000 NX-OS and Cisco License (Smart
Patches
- Upgrade Cisco NX-OS to the fixed release identified by the Cisco Software Checker
- Upgrade Cisco License On-Prem to 10-202609 or later
- Upgrade UCS 6300 Series Fabric Interconnects to 4.3(6j); migrate from 4.2 and earlier
Immediate actions
- Disable NGOAM (no feature ngoam), MPLS OAM (no feature mpls oam) and NX-API on Nexus 3000/9000 switches where not required
- Restrict network reachability of NX-API, NGOAM and MPLS OAM traffic and the Cisco License On-Prem management interface to trusted management networks
- Apply Cisco Live Protect shields as temporary protection on devices that cannot be upgraded immediately
Workarounds
- No workarounds exist for Cisco License On-Prem or NX-API
- Disabling NGOAM or MPLS OAM mitigates the respective flaws but is not an official workaround
Longer-term hardening
- Use the Cisco Software Checker to identify the fixed NX-OS release for each Nexus 3000/9000 and schedule upgrades
- Inventory Cisco License On-Prem (formerly SSM On-Prem) instances and migrate 9-202601 and earlier to a fixed release
CVEs associated with Cisco Nexus 3000/9000 NX-OS and Cisco License (Smart
CVE-2026-76471, CVE-2026-76485, CVE-2026-76486, CVE-2026-76501, CVE-2026-76465, CVE-2026-76480, CVE-2026-76482, CVE-2026-76483, CVE-2026-76484
Weaknesses (CWE) in Cisco Nexus 3000/9000 NX-OS and Cisco License (Smart
CWE-122, CWE-121, CWE-590, CWE-306, CWE-347, CWE-522, CWE-94
Timeline of Cisco Nexus 3000/9000 NX-OS and Cisco License (Smart
- Cisco PSIRT states it is not aware of public announcements or malicious exploitation of any of the flaws, which were found in internal testing that included frontier AI models
- Cisco publishes cisco-sa-hardening-ssm-Ph77wdhf for Cisco License On-Prem flaws CVE-2026-76480, CVE-2026-76482, CVE-2026-76483 and CVE-2026-76484 (CVSS up to 10.0); fixed in 10-202609
- Cisco publishes cisco-sa-moam-rce-uBTzYV7 for CVE-2026-76465, an MPLS OAM echo-request RCE/DoS flaw (CVSS 9.8)
- Cisco publishes cisco-sa-ngoam-rce-LWKQ4BU for NGOAM stack overflow flaws CVE-2026-76485, CVE-2026-76486 and CVE-2026-76501 (CVSS 9.8)
- Cisco publishes cisco-sa-napi-rce-r2shwu2j for CVE-2026-76471, an NX-API heap overflow RCE (CVSS 9.8) in NX-OS on Nexus 3000/9000 and UCS 6300
- BleepingComputer reports on the Nexus switch takeover flaws and Cisco License vulnerabilities
Sources cited for Cisco Nexus 3000/9000 NX-OS and Cisco License (Smart
- Cisco warns of critical flaws allowing Nexus switch takeover
- Cisco NX-OS Software NX-API Remote Code Execution Vulnerability (cisco-sa-napi-rce-r2shwu2j)
- Cisco Nexus 3000/9000 NGOAM Remote Code Execution Vulnerabilities (cisco-sa-ngoam-rce-LWKQ4BU)
- Cisco NX-OS MPLS OAM Remote Code Execution Vulnerability (cisco-sa-moam-rce-uBTzYV7)
- Cisco License On-Prem (Smart Software Manager On-Prem) Vulnerabilities (cisco-sa-hardening-ssm-Ph77wdhf)
Detection coverage for TL-2026-3082
As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3082 across Splunk SPL, Microsoft KQL and Sigma, covering 6 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.