Critical Cisco Nexus NX-OS Flaws Allow Unauthenticated Root Code Execution; MPLS OAM RCE and ACI Contract Bypass Also Disclosed
Cisco disclosed CVSS 9.8 NGOAM flaws (CVE-2026-76485, CVE-2026-76486, CVE-2026-76501) enabling unauthenticated root code execution on Nexus 3000/9000 standalone switches, plus a separate MPLS OAM root-execution flaw and an ACI endpoint-group contract bypass;…
Cisco on 2026-10-07 disclosed three separate sets of unauthenticated vulnerabilities affecting Nexus switches. The NGOAM flaws, identified in 2026-10-08 reports from Cyber Security News and GBHackers as CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501 (each scored CVSS 9.8, in advisory cisco-sa-ngoam-rce-LWKQ4BU), stem from improper validation of IP traffic when NGOAM is enabled on Nexus 3000 and 9000 Series switches running standalone NX-OS; GBHackers characterizes them as CWE-121 stack overflows. Unauthenticated remote attackers sending crafted IP packets can execute arbitrary code with root privileges or cause process crashes and device reloads. CVE-2026-76485 requires only NGOAM to be enabled, while the other two CVEs also require SRv6 or a qualifying VXLAN EVPN overlay; Cyber Security News states that Nexus 9000 in ACI mode, Nexus 7000, and MDS 9000 are unaffected (GBHackers lists ACI-mode Nexus 9000 and Nexus 7000 but does not mention MDS 9000). Fixed releases are available, and Cisco reported no known malicious use or public exploitation; the reports state there is no workaround, citing only disabling unneeded NGOAM and, per GBHackers, Live Protect as interim measures. A separate Cisco advisory covers the MPLS OAM feature of NX-OS on Nexus 3000 and 9000 switches, where improper validation of crafted MPLS echo-request packets sent to an IP address on an affected device allows an unauthenticated remote attacker to execute arbitrary code as root or cause a denial of service; that advisory states no CVE identifiers, fixes, or workarounds, and does not report confirmed exploitation. A third advisory covers Nexus 9000 Series Fabric Switches in ACI mode, where unauthenticated remote attackers can bypass endpoint-group contracts by sending IPv4 or IPv6 packets using UDP source and destination ports assigned to DHCP; Cisco has released software updates and states there are no workarounds. Cyber Security News notes that CVE-2026-20212 is a separate, previously reported issue. The sources do not conflict on impact or on the absence of reported exploitation; the October 8 reports add specificity about the NGOAM CVEs relative to the October 7 advisories.
- Cisco advisory cisco-sa-ngoam-rce-LWKQ4BU covers CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501, each scored CVSS 9.8 and classified by GBHackers as CWE-121 stack overflows.
- Unauthenticated attackers sending crafted IP packets to NGOAM on Nexus 3000 and 9000 switches running standalone NX-OS can execute arbitrary code with root privileges or cause process crashes and device reloads.
Coverage timelineoldest first · each row is one article
- · 1d agoCisco Nexus 9000 Series Fabric Switches in ACI Mode Endpoint Group Contract Bypass Vulnerability
Cisco Security Advisories· 64
Cisco Nexus 9000 ACI switches allow unauthenticated bypass of EPG contracts via DHCP UDP ports.
- · 1d agoCisco Nexus 3000 and 9000 Series Switches NGOAM Remote Code Execution Vulnerabilities
Cisco Security Advisories· 74
Cisco warns NGOAM flaws in NX-OS on Nexus 3000 and 9000 switches allow unauthenticated remote root code execution.
- · 1d agoCisco Nexus 3000 and 9000 Series Switches MPLS OAM Remote Code Execution Vulnerability
Cisco Security Advisories· 76
Vulnerabilities in this storyAll →
- CVE-2026-202129.8<1%Unauthenticated RCE in Cisco Nexus 9000 Switches with Silicon One Integrationpublished · Cisco Nexus 9000 Series Switches with Silicon One integration
- CVE-2026-764859.8—Unauthenticated root RCE in Cisco NX-OS NGOAMpublished · Cisco NX-OS Software (NGOAM / VXLAN OAM)