CVE-2026-76485: Remote Code Execution in Cisco NX-OS VXLAN OAM (NGOAM)
Vulnerability ID: CVE-2026-76485
CVSS Score: 9.8
Published: 2026-10-07
CVE-2026-76485 is a critical stack-based buffer overflow vulnerability in the VXLAN OAM (NGOAM) parsing component of Cisco NX-OS Software. The flaw enables an unauthenticated, remote attacker to execute arbitrary code with root privileges or trigger a denial of service on affected Nexus switches. This vulnerability is triggered through crafted packets sent to an IP interface. No workarounds are currently available to mitigate the vulnerability while preserving the NGOAM functionality. Cisco has published software patches to address this flaw.
TL;DR
Unauthenticated remote code execution and denial of service vulnerability in Cisco NX-OS NGOAM feature due to improper input validation during packet parsing.
Technical Details
- CWE ID: CWE-121
- Attack Vector: Network (AV:N)
- CVSS v3.1: 9.8 (Critical)
- Exploit Status: None
- KEV Status: Not Listed
- Impact: Remote Code Execution / Denial of Service
Affected Systems
- Cisco Nexus 3000 Series Switches
- Cisco Nexus 9000 Series Switches
-
NX-OS Software: 9.2.x, 9.3.x, 10.3.x, 10.4.x, 10.5.x, 10.6.x (Fixed in:
Refer to Cisco Advisory)
Mitigation Strategies
- Configure Infrastructure Access Control Lists (iACLs) to drop unsolicited OAM/NGOAM packets.
- Implement Control Plane Policing (CoPP) on vulnerable nodes.
- Disable VXLAN OAM/NGOAM features if they are not operationally required.
Remediation Steps:
- Identify vulnerable Nexus switches running affected NX-OS versions.
- Download the verified patch release from the official Cisco Software Central.
- Apply the update according to standard maintenance window protocols.
References
Read the full report for CVE-2026-76485 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)