Critical Cisco Nexus Switch Vulnerabilities Allow Unauthenticated Attackers to Execute Code as Root
Cisco disclosed three critical unauthenticated root code-execution flaws in Nexus 3000 and 9000 switches.
Cisco advisory cisco-sa-ngoam-rce-LWKQ4BU describes three critical NGOAM stack overflows in NX-OS on Nexus 3000 and 9000 Series switches running standalone mode. CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501 are each scored CVSS 9.8 (CWE-121) and can be triggered by unauthenticated crafted IP packets, leading to root code execution or a device reload. CVE-2026-76485 needs only NGOAM; the others also require VXLAN EVPN overlay or SRv6, and ACI-mode Nexus 9000 plus Nexus 7000 are unaffected. Cisco says there is no workaround and no known exploitation, and recommends fixed releases, with disabling NGOAM or Live Protect shields only as interim measures.