Cyber & AI intelligence
Wasteland.
Briefs indexed3048
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-76486 2026-10-07

Cisco NX-OS NGOAM Flaw Allows Unauthenticated Root Code Execution

"A critical (CVSS 9.8) flaw in the VXLAN OAM (NGOAM) feature of Cisco NX-OS Software, tracked as CVE-2026-76486, could allow an unauthenticated, remote attacker to run arbitrary code as root or to crash and reload an…"

A critical (CVSS 9.8) flaw in the VXLAN OAM (NGOAM) feature of Cisco NX-OS Software, tracked as CVE-2026-76486, could allow an unauthenticated, remote attacker to run arbitrary code as root or to crash and reload an affected device.

What Is It

CVE-2026-76486 is in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software. Cisco calls this feature NGOAM. The flaw comes from improper input validation of IP traffic when NGOAM is enabled. An attacker could exploit it by sending crafted packets to an IP interface on an affected device. The weakness is classified as CWE-121 (stack-based buffer overflow).

A successful exploit could allow the attacker to run arbitrary code with root privileges. It could also crash processes and cause the device to reload, resulting in a denial-of-service (DoS) condition.

Why It Matters

What's Vulnerable

Cisco NX-OS Software is affected when the NGOAM feature is enabled. The affected versions listed in the NVD record are:

The supplied data lists no affected CPEs. The NVD record status is "Received" (published 2026-10-07).

Patch Status

The supplied NVD data does not list fixed software releases or workarounds, and there is no CISA KEV required action or due date. Administrators should:

Sources