# Cisco Nexus 3000/9000 NX-OS and Cisco License (Smart Software Manager On-Prem) critical flaws enabling switch takeover (CVE-2026-76471, CVE-2026-76480, CVE-2026-76482 and others)

> Cisco disclosed unauthenticated remote code execution flaws in the NX-API, NGOAM and MPLS OAM features of Nexus 3000/9000 switches in standalone NX-OS mode (CVSS 9.8), plus four critical/high flaws in Cisco License On-Prem (formerly Smart Software Manager On-Prem) with CVSS up to 10.0. Cisco PSIRT is not aware of public announcements or malicious exploitation.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-09T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3082
- **ID:** TL-2026-3082
- **Severity:** CRITICAL (CVSS 10)
- **Category:** VULNERABILITY
- **Status:** TRACKING
- **Detections:** 9 · **IOCs:** 6 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-76471, CVE-2026-76485, CVE-2026-76486, CVE-2026-76501, CVE-2026-76465, CVE-2026-76480, CVE-2026-76482, CVE-2026-76483, CVE-2026-76484

## Description

On 7 October 2026 Cisco published advisories covering two product families. The first set affects Cisco Nexus 3000 Series and Nexus 9000 Series switches running standalone NX-OS (Nexus 7000 and Nexus 9000 in ACI mode are not affected). CVE-2026-76471 (cisco-sa-napi-rce-r2shwu2j, CWE-122 heap-based buffer overflow) lets an unauthenticated remote attacker send crafted HTTP requests to NX-API, which is disabled by default, to execute arbitrary code as root or crash the device. The same advisory lists UCS 6300 Series Fabric Interconnects, where the XML API is enabled by default and exploitation requires low-privileged credentials; fixed in release 4.3(6j), and release 4.2 and earlier must migrate to a fixed release.

CVE-2026-76485, CVE-2026-76486 and CVE-2026-76501 (cisco-sa-ngoam-rce-LWKQ4BU, CWE-121 stack-based buffer overflow) stem from improper input validation of IP traffic in the NGOAM (Operation, Administration, and Maintenance) feature. CVE-2026-76485 requires only NGOAM enabled; CVE-2026-76486 requires NGOAM plus SRv6 or NV Overlay with VXLAN EVPN VNI; CVE-2026-76501 requires NGOAM plus SRv6. An unauthenticated attacker sending crafted packets can obtain root-level code execution or cause denial of service. CVE-2026-76465 (cisco-sa-moam-rce-uBTzYV7, CWE-590) is in the MPLS OAM feature (disabled by default): a crafted MPLS echo-request sent to an IP address on the device can yield root code execution or DoS. All four NX-OS advisories carry CVSS 3.1 base score 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). No permanent workarounds exist; disabling the features (no feature ngoam, no feature mpls oam) mitigates, and Cisco offers Live Protect shields as temporary mitigation. Fixed releases are determined with the Cisco Software Checker.

The second set, cisco-sa-hardening-ssm-Ph77wdhf, covers Cisco License On-Prem (formerly Smart Software Manager On-Prem), versions 9-202601 and earlier and 10-202608 and earlier: CVE-2026-76480 (9.8, CWE-306 missing authentication), CVE-2026-76482 (10.0, CWE-347 improper cryptographic signature verification), CVE-2026-76483 (9.1, CWE-522 insufficiently protected credentials) and CVE-2026-76484 (8.8, CWE-94 code injection). The first fixed release on the 10.x line is 10-202609; 9-202601 and earlier must migrate. No workarounds exist. Cisco states the issues were found during an internal security review using existing testing processes as well as frontier AI models.

Cisco PSIRT reports it is not aware of public announcements or malicious use of any of these vulnerabilities, and no public PoC or attribution has been reported. A switch or license-server takeover would give an attacker root on core network infrastructure or control of the licensing platform, so exposure of the NX-API, NGOAM and MPLS OAM features and the License On-Prem management interface should be reviewed and patching prioritised.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1552 Unsecured Credentials
- T1553 Subvert Trust Controls
- T1499.004 Application or System Exploitation

## Sources

- [Cisco warns of critical flaws allowing Nexus switch takeover](https://www.bleepingcomputer.com/news/security/cisco-warns-of-critical-flaws-allowing-nexus-switch-takeover/)
- [Cisco NX-OS Software NX-API Remote Code Execution Vulnerability (cisco-sa-napi-rce-r2shwu2j)](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-napi-rce-r2shwu2j)
- [Cisco Nexus 3000/9000 NGOAM Remote Code Execution Vulnerabilities (cisco-sa-ngoam-rce-LWKQ4BU)](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ngoam-rce-LWKQ4BU)
- [Cisco NX-OS MPLS OAM Remote Code Execution Vulnerability (cisco-sa-moam-rce-uBTzYV7)](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-moam-rce-uBTzYV7)
- [Cisco License On-Prem (Smart Software Manager On-Prem) Vulnerabilities (cisco-sa-hardening-ssm-Ph77wdhf)](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ssm-Ph77wdhf)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3082
