AI analysis
CVE-2026-76486 is a critical stack-based buffer overflow (CWE-121) in the VXLAN Operation, Administration, and Maintenance feature of Cisco NX-OS Software, also known as NGOAM. When NGOAM is enabled, the software does not properly validate IP traffic, so an unauthenticated remote attacker can trigger the flaw by sending crafted packets to an IP interface on the device. A successful exploit can run arbitrary code with root privileges or crash the process, forcing a reload and a denial of service. Only Cisco NX-OS devices that have NGOAM enabled and are reachable on an IP interface are affected; specific version ranges are not stated in the supplied data. It is not listed in CISA KEV, and no public proof-of-concept is known.
What to do: Treat devices with the NGOAM (VXLAN OAM) feature enabled as critical: apply Cisco's NX-OS fix as soon as it is published for your release, and until then disable NGOAM if it is not required. Restrict which hosts can reach IP interfaces on affected switches and monitor for unexpected NGOAM process crashes or reloads. No fixed version range is identified in the supplied advisory data, so confirm affected releases and patches directly with Cisco PSIRT.
Affected
| Cisco NX-OS Software (NGOAM / VXLAN OAM feature) | — |
Estimated exposure
moderatelow thousands to tens of thousands of NGOAM-enabled, network-reachable Nexus devices (estimate) — Cisco NX-OS is widely used on Nexus data-center switches, but NGOAM is an optional feature and these devices are usually kept off the public internet, so only the subset with NGOAM enabled and a reachable IP interface is exposed.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a Denial-of-Service (DoS) on an affected device. This vulnerability is due to improper input validation of IP traffic when the NGOAM feature is enabled. An attacker could exploit this vulnerability by sending crafted packets to an IP interface on an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes resulting in a reload and DoS condition.