AI analysis
Cisco NX-OS Software has a critical flaw in the Segment Routing over IPv6 (SRv6) Operation, Administration, and Maintenance feature known as NGOAM. Improper input validation of IP traffic (CWE-121, stack-based buffer overflow) allows an unauthenticated remote attacker to send crafted packets to an IP interface on a device where both NGOAM and SRv6 are enabled. A successful attack can execute arbitrary code with root privileges or crash processes, causing a reload and a denial of service. Only NX-OS devices running that feature pair are affected; specific fixed version ranges were not included in the source data. The issue is scored CVSS 3.1 9.8, is not in CISA KEV, and no public proof-of-concept is known.
What to do: Install the fixed Cisco NX-OS release listed in Cisco's advisory for CVE-2026-76501 for your platform as soon as it is available. Until then, disable NGOAM if SRv6 OAM is not required, and block untrusted networks from sending IP packets to interfaces on devices where both features are enabled. Check whether NGOAM and SRv6 are on, and review logs for unexpected process crashes or reloads.
Affected
| Cisco NX-OS Software (SRv6 NGOAM) | — |
Estimated exposure
nicheLikely thousands of configured devices, not the full NX-OS installed base — Estimate from deployment pattern only: NX-OS runs on Cisco Nexus data-center and service-provider switches, but the flaw applies solely when both NGOAM and SRv6 are enabled and an IP interface is reachable; no install counts or public scan…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A vulnerability in the Segment Routing over IPv6 (SRv6) Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) on an affected device. This vulnerability is due to improper input validation of IP traffic when the NGOAM and SRv6 features are enabled. An attacker could exploit this vulnerability by sending crafted packets to an IP interface on an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes resulting in a reload and DoS condition.