Release Notes for NX-OS Live Protect Shield

Available Languages

Download Options

  • PDF
    (187.2 KB)
    View with Adobe Reader on a variety of devices
Updated:October 7, 2026

Bias-Free Language

The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. Learn more about how Cisco is using Inclusive Language.

Available Languages

Download Options

  • PDF
    (187.2 KB)
    View with Adobe Reader on a variety of devices
Updated:October 7, 2026

Table of Contents

 

 

Live Protect Shield

Cisco has released Live Protect shields for the following CVEs to temporarily mitigate the vulnerabilities in Cisco NX-OS Software.

Shield ID

CVE

Title

lp00031

CVE-2026-20212

Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability

lp00030

CVE-2026-20032

Cisco NX-OS Software Python Sandbox Escape Vulnerability

lp00035

CVE-2026-76485 

Cisco Nexus 3000 and 9000 Series Switches VXLAN OAM (NGOAM) Remote Code Execution Vulnerability

lp00036

CVE-2026-76501 

Cisco Nexus 9000 Series Switches SRv6 OAM (NGOAM) Remote Code Execution Vulnerability

lp00037

CVE-2026-76465 

Cisco Nexus 3000 and 9000 Series Switches MPLS OAM Remote Code Execution Vulnerability

lp00071

CVE-2026-76486 

Cisco Nexus 3000 and 9000 Series Switches VXLAN OAM (NGOAM) Remote Code Execution Vulnerability

lp00074

CVE-2026-76471 

Cisco NX-OS Software NX-API Remote Code Execution Vulnerability

 

For information about Live Protect for Cisco NX-OS Software, see Cisco Nexus 9000 Series NX-OS Security Configuration Guide.

Note: Live Protect shield is a temporary mitigation to bridge the gap until software updates can be scheduled. To fully remediate this vulnerability, upgrade to a fixed software release, which can be found using the Cisco Software Checker.

Release Notes

Release notes for the Live Protect Shields are available in the following links.

Shield ID

Release

lp00030

Cisco NX-OS Release10.6(3)

lp00031

Cisco NX-OS Release 10.6(3)

lp00031

Cisco NX-OS Release 10.6(3s)

lp00035

Cisco NX-OS Release 10.6(3)

lp00036

Cisco NX-OS Release 10.6(3)

lp00037

Cisco NX-OS Release 10.6(3)

lp00071

Cisco NX-OS Release 10.6(3)

lp00074

Cisco NX-OS Release 10.6(3)

Reference

For detailed installation steps about Live Protect for Cisco NX-OS Software, see Cisco Nexus 9000 Series NX-OS Security Configuration Guide.

Documentation Feedback

To provide technical feedback on this document, or to report an error or omission, please send your comments to nexus9k-docfeedback@cisco.com. We appreciate your feedback.

Legal Information

Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: https://www.cisco.com/c/en/us/about/legal/trademarks.html. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1721R)

Any Internet Protocol (IP) addresses and phone numbers used in this document are not intended to be actual addresses and phone numbers. Any examples, command display output, network topology diagrams, and other figures in the document are shown for illustrative purposes only. Any use of actual IP addresses or phone numbers in illustrative content is unintentional and coincidental.

© 2026 Cisco Systems, Inc. All rights reserved.

Learn more