Cisco Nexus 9000 ACI contract bypass flaw fixed (CVE-2026-20038)
At a glance
| Severity | HIGH |
|---|---|
| In CISA KEV (exploited) | No |
| Vendor | Cisco |
| CVE IDs | CVE-2026-20032, CVE-2026-20038, CVE-2026-20173, CVE-2026-76453, CVE-2026-76455, CVE-2026-76456 |
Cisco has fixed a Cisco Nexus 9000 ACI contract bypass vulnerability (CVE-2026-20038) that lets an unauthenticated remote attacker slip past endpoint group (EPG) contracts on Nexus 9000 Series Fabric Switches in ACI mode. Cisco rates it Medium (CVSS 5.8), says there are no workarounds, and lists no exploitation or CISA KEV status in the material we reviewed.
It was published on October 7, 2026 alongside a larger NX-OS batch that includes Critical remote code execution flaws, so most teams running Nexus gear should treat this as one item in a wider patch cycle.
What happened
The flaw sits in the EPG contract function of Nexus 9000 fabric switches running in ACI mode. Cisco attributes it to improper control of EPG contracts (CWE-284, improper access control).
An attacker can send IPv4 or IPv6 packets that use UDP source and destination ports assigned to DHCP traffic. A successful attempt bypasses the configured EPG contracts on the device. Cisco’s description says the switches program implicit DHCPv4 and DHCPv6 rules at initialization. These rules always permit DHCP-related traffic and rank above user-defined contract rules.
Am I affected? Nexus 9000 ACI models
- Affected: Cisco Nexus 9000 Series Fabric Switches in ACI mode, regardless of device configuration.
- Not affected, per Cisco: Nexus 9000 Series Switches in standalone NX-OS mode, Nexus 3000 and 7000 Series, MDS 9000, UCS 6300/6400/6500/6600 Fabric Interconnects, and several Firepower and Secure Firewall lines.
- Fixed releases: listed in the Fixed Software section of the Cisco advisory; we have not reproduced them here.
Technical details
- CVE: CVE-2026-20038; Cisco bug ID CSCwr18270
- CVSS 3.1 base score 5.8: network vector, low complexity, no privileges, no user interaction, changed scope, low integrity impact, no confidentiality or availability impact
- Weakness: CWE-284
- Exploitation, KEV listing and EPSS: none reported in the source data
- Workarounds: none
Why this matters (analysis)
This section is our analysis, not new vendor facts. The impact score is integrity-only, but contracts are the segmentation control in ACI. Traffic that should be denied between EPGs may be allowed, and the changed-scope rating reflects that the effect lands beyond the switch itself.
The exposure depends on your design. A fabric that relies on contracts to isolate production, management or regulated workloads has more to lose than one with flat, permissive contracts. Because no configuration avoids the flaw and no workaround exists, patching is the only fix.
The wider October 7 Cisco batch
Cisco’s advance notification lists related NX-OS advisories published the same day. Rows below are from that notice.
| Advisory | CVE | Rating | CVSS |
|---|---|---|---|
| Nexus 3000/9000 MPLS OAM remote code execution | CVE-2026-76465 | Critical | 9.8 |
| NX-API remote code execution | CVE-2026-76471 | Critical | 9.8 |
| NX-OS Security Hardening Release: October 2026 | CVE-2026-76453, -76455, -76456, -76457, -76458, -76459 | Critical | 9.8 |
| Control plane denial of service | CVE-2026-20173 | Medium | 5.8 |
| Python sandbox escape | CVE-2026-20032 | Medium | 4.4 |
For the MPLS OAM flaw, Cisco says the feature is disabled by default and can be checked with show feature | include mpls_oam. Cisco states the hardening-release issues were found internally and are not known to be actively exploited; the source data does not give exploitation status for the other advisories.
How to fix CVE-2026-20038 and what to do
- Inventory Nexus 9000 switches and identify which run in ACI mode.
- Look up your release in the Fixed Software section of the Cisco advisory and schedule the upgrade.
- Review the Critical NX-OS advisories above in the same change window, since they may apply to the same hardware in other modes.
- Hunt for unexpected flows between EPGs, particularly UDP traffic on DHCP ports (67/68 and 546/547 are the standard DHCP ports) that does not match a real DHCP exchange, in fabric flow logs.
- Re-check contract design so that critical segments do not depend on a single enforcement point until patched.
Cisco says it strongly recommends upgrading to the fixed software indicated in each advisory.
Sources
- Cisco: Nexus 9000 ACI EPG Contract Bypass Vulnerability
- Cisco: Advance Notification for October 7, 2026 Security Advisories
- Cisco: Nexus 3000 and 9000 MPLS OAM Remote Code Execution
- Cisco: NX-API Remote Code Execution
- Cisco: NX-OS Security Hardening Release October 2026
- NVD: CVE-2026-20038
Related free tool: planning network segmentation or access rules for exposed devices? Our Subnet Calculator shows network ranges, masks and usable hosts for any CIDR block.
