Cisco Nexus switch flaws could give attackers root control
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Friday, October 9th, 2026.
Cisco has fixed five critical weaknesses that could allow remote attackers to run code with root privileges or force affected Nexus switches to reload. The issues affect certain Nexus 3000 and 9000 switches running in standalone NX-OS mode when specific features are enabled. Nexus 7000 switches and Nexus nine thousand devices operating in ACI mode are not affected. Cisco said it was not aware of malicious exploitation when the advisories were published.
A successful attack could compromise a core network device or disrupt connectivity through a denial of service. Leaders should treat data center switches as high-impact assets because many services depend on their availability and integrity. Defenders should identify affected configurations, upgrade to fixed NX-OS releases, and disable unneeded NX-A P I, NGOAM, or MPLS OAM features. Cisco also provides temporary Live Protect shields for systems that can’t yet be upgraded and rebooted.
The immediate priority is to check Nexus configurations and either patch or disable each affected feature according to Cisco’s guidance.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.