Seven critical CVEs across two product lines. None exploited yet. No workarounds exist. Here's the fast triage.
NX-OS NGOAM — 3 × CVSS 9.8 Unauthenticated RCE
CVE-2026-76485, CVE-2026-76486, CVE-2026-76501
Affects: Cisco Nexus 3000 and 9000 Series switches
The NGOAM (VXLAN OAM) feature has improper input validation on IP traffic. Crafted packets → root code execution, no auth required. Each CVE has slightly different feature prerequisites:
| CVE | Requires |
|---|---|
| CVE-2026-76485 | NGOAM + SRv6 OR NV Overlay |
| CVE-2026-76486 | NGOAM + NV Overlay + at least one peer VTEP |
| CVE-2026-76501 | NGOAM + SRv6 (Nexus 9000 only — 3000 doesn't support SRv6) |
Check your exposure right now:
bash
show feature | include ngoam
show feature | include nve
show feature | include srv6
Top comments (0)