Summary
- Cisco’s October NX-OS hardening release covers six CVEs.
- Two vulnerability classes carry maximum CVSS 3.1 scores of 9.8.
- Cisco says no workarounds are available and exploitation is not known.
Cisco has released an October security hardening update for NX-OS addressing six CVEs across vulnerability classes that include access control failures, memory corruption and command or argument injection.
The 7 October advisory carries an overall critical rating and a maximum CVSS 3.1 base score of 9.8. Cisco says there are no workarounds for the vulnerabilities and recommends moving affected systems to the fixed software releases identified for each product family.
Affected hardware includes MDS 9000 multilayer switches, several Nexus switch families and multiple UCS Fabric Interconnect products. The vulnerabilities apply when those devices run an affected NX-OS release regardless of configuration, according to Cisco.
CVE-2026-76455 covers improper access control and carries a highest assigned score of 9.8, while CVE-2026-76459 covers an out-of-bounds write vulnerability class with the same maximum score. Four further CVEs address improper neutralisation, input validation, out-of-bounds reads and exceptional-condition handling.
Cisco has grouped multiple internally discovered defects by their underlying Common Weakness Enumeration category, so each CVE represents a vulnerability class rather than one universal exploit affecting every device in an identical way. The 9.8 score reflects the most severe underlying weakness within the relevant class.
That distinction is important when assessing practical exposure because the existence of six CVEs does not mean they form a single attack chain. Individual defects can have different prerequisites, affected components and consequences even where they share the same NX-OS release.
NX-OS sits within network infrastructure responsible for moving traffic between critical systems, giving software changes an operational dimension beyond ordinary application patching. Core switches and fabric interconnects may require maintenance windows, redundancy checks and compatibility testing before software can be changed safely.
The absence of workarounds narrows the available choices for environments that cannot immediately upgrade. Compensating controls may reduce exposure to particular management paths, but Cisco does not identify a configuration change that removes the documented vulnerabilities themselves.
Older software branches create an additional lifecycle issue because several affected products must migrate to a supported fixed release rather than receiving a correction on the branch they currently use. A security remediation can therefore require a larger platform upgrade than applying an isolated patch.
Cisco says the vulnerabilities were identified during internal security testing using established processes and frontier AI models. Its Product Security Incident Response Team is not aware of public malicious use or announcements concerning the flaws.
That status keeps the October release in the vulnerability-management category rather than an active incident response cycle. The combination of high potential severity, central network placement and the lack of workarounds nevertheless gives organisations a concrete reason to establish which NX-OS products and branches they operate.
The fixed versions vary across Nexus, MDS and UCS product families, so remediation depends on matching each device to Cisco’s release tables rather than applying one common NX-OS version across the estate.




