Critical Cisco Nexus Switch Vulnerabilities Allow Unauthenticated Attackers to Execute Code as Root
Cisco disclosed three critical unauthenticated root code-execution flaws in Nexus 3000 and 9000 switches.
Cisco advisory cisco-sa-ngoam-rce-LWKQ4BU describes three critical NGOAM stack overflows in NX-OS on Nexus 3000 and 9000 Series switches running standalone mode. CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501 are each scored CVSS 9.8 (CWE-121) and can be triggered by unauthenticated crafted IP packets, leading to root code execution or a device reload. CVE-2026-76485 needs only NGOAM; the others also require VXLAN EVPN overlay or SRv6, and ACI-mode Nexus 9000 plus Nexus 7000 are unaffected. Cisco says there is no workaround and no known exploitation, and recommends fixed releases, with disabling NGOAM or Live Protect shields only as interim measures.
- Three NGOAM stack overflows, CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501, score CVSS 9.8.
- Unauthenticated crafted IP packets can execute code as root or reload the switch.
- Nexus 3000 and 9000 in standalone NX-OS mode are affected; ACI mode is not.
- No workarounds; disabling NGOAM removes the vector, and Live Protect is temporary.
- Cisco PSIRT reports no public exploitation or announcements as of the advisory.
Vulnerabilities mentionedAll →
- CVE-2026-764859.8—Unauthenticated root RCE in Cisco NX-OS NGOAMpublished · Cisco NX-OS Software (NGOAM / VXLAN OAM)+2 related
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
CVE-2026-76485+2 related CVEs | Unauthenticated root RCE in Cisco NX-OS NGOAM CVE-2026-76485 is a critical flaw (CVSS 9.8, CWE-121) in the VXLAN Operation, Administration, and Maintenance feature of Cisco NX-OS Software, also called NGOAM. When NGOAM is enabled, the software does not properly validate IP traffic, so an unauthenticated remote attacker can trigger the bug by sending crafted packets to an IP interface on the device. A successful attack can run arbitrary code with root privileges or crash the process, forcing a reload and a denial of service. Only Cisco NX-OS devices with NGOAM enabled are in scope; exact version ranges were not included in the advisory data. It is not listed in CISA KEV, and no public proof-of-concept is known. |
Full article559 words · extracted from gbhackers.com · click to collapse
Cisco has disclosed three critical vulnerabilities in its Nexus 3000 and 9000 Series switches that could allow unauthenticated remote attackers to execute arbitrary code with root privileges.
Successful exploitation could crash processes, trigger device reloads, and cause denial of service, disrupting network availability.
Published on October 7, 2026, advisory cisco-sa-ngoam-rce-LWKQ4BU identifies three vulnerabilities: CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501.
Cisco has assigned these vulnerabilities a CVSS base score of 9.8 and lists CWE-121, which classifies them as stack-based buffer overflows.
The flaws affect the Next Generation Operation, Administration, and Maintenance feature, commonly known as NGOAM, in Cisco NX-OS Software. Cisco discovered these vulnerabilities during internal security testing and has released software updates to address them.
Cisco Nexus Switch Vulnerabilities
According to Cisco, these vulnerabilities arise from improper input validation of IP traffic when NGOAM is enabled. An attacker could exploit an affected switch by sending specially crafted packets to an IP interface.
Successful exploitation could lead to root-level code execution or cause process crashes that result in a device reload. The published CVSS vector indicates that exploitation can occur over the network with low attack complexity, requiring no privileges or user interaction.
NGOAM supports network diagnostics and troubleshooting. Its VXLAN functionality provides loop detection and mitigation, while SRv6 NGOAM uses IPv6 ping and path trace mechanisms to verify connectivity and isolate forwarding problems.
The vulnerabilities affect Nexus 3000 and Nexus 9000 Series switches operating in standalone NX-OS mode, but their configuration requirements differ:
- CVE-2026-76485: Requires only NGOAM to be enabled.
- CVE-2026-76486: Requires NGOAM plus either Segment Routing over IPv6 or NV Overlay. The overlay configuration must include a VXLAN EVPN VNI mapped to an NVE interface with at least one learned peer VTEP.
- CVE-2026-76501: Requires both NGOAM and SRv6 to be enabled.
Cisco notes that Nexus 3000 switches do not support SRv6, and only a subset of Nexus 9000 switches supports it. Additionally, Nexus 9000 switches operating in ACI mode and Nexus 7000 switches are confirmed to be unaffected.
Administrators can check the status of NGOAM using the command: `show feature | include ngoam`. Relevant checks for overlay and SRv6 can be done with the commands: `show feature | include nve` and `show feature | include srv6`.
For overlay exposure, Cisco additionally lists show running-config | begin "interface nve", show nve vni, and show nve peers to inspect the required configuration and peer state.
Cisco has stated that no workarounds exist for these vulnerabilities. However, disabling NGOAM when it is not necessary removes the attack vector for all three vulnerabilities. Administrators can execute the command `no feature ngoam` in global configuration mode after evaluating the operational consequences.
Additionally, Cisco has released Live Protect shields as temporary mitigations. These protections bridge the gap until administrators can schedule software upgrades and are not a replacement for installing a fixed release.
Organizations should use the Cisco Software Checker to identify affected releases and suitable upgrade targets. The advisory does not include a fixed-version table.
At the time of publication, Cisco’s PSIRT reported no known public announcements or malicious exploitation of these vulnerabilities. Nonetheless, this assessment does not eliminate the need to remediate affected switches.
Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.