AI analysis
CVE-2026-76485 is a critical flaw (CVSS 9.8, CWE-121) in the VXLAN Operation, Administration, and Maintenance feature of Cisco NX-OS Software, also called NGOAM. When NGOAM is enabled, the software does not properly validate IP traffic, so an unauthenticated remote attacker can trigger the bug by sending crafted packets to an IP interface on the device. A successful attack can run arbitrary code with root privileges or crash the process, forcing a reload and a denial of service. Only Cisco NX-OS devices with NGOAM enabled are in scope; exact version ranges were not included in the advisory data. It is not listed in CISA KEV, and no public proof-of-concept is known.
What to do: Treat this as critical on any NX-OS device where NGOAM (VXLAN OAM) is enabled: apply Cisco's fixed NX-OS release as soon as it is published for your train, and until then disable NGOAM if the feature is not required. Restrict which hosts can send IP traffic to interfaces that process NGOAM, and review logs for unexpected NGOAM process crashes or device reloads.
Affected
| Cisco NX-OS Software (NGOAM / VXLAN OAM) | — |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a Denial-of-Service (DoS) on an affected device. This vulnerability is due to improper input validation of IP traffic when the NGOAM feature is enabled. An attacker could exploit this vulnerability by sending crafted packets to an IP interface on an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes resulting in a reload and DoS condition.