A critical (CVSS 9.8) flaw in the VXLAN OAM (NGOAM) feature of Cisco NX-OS Software, tracked as CVE-2026-76486, could allow an unauthenticated, remote attacker to run arbitrary code as root or to crash and reload an affected device.
What Is It
CVE-2026-76486 is in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software. Cisco calls this feature NGOAM. The flaw comes from improper input validation of IP traffic when NGOAM is enabled. An attacker could exploit it by sending crafted packets to an IP interface on an affected device. The weakness is classified as CWE-121 (stack-based buffer overflow).
A successful exploit could allow the attacker to run arbitrary code with root privileges. It could also crash processes and cause the device to reload, resulting in a denial-of-service (DoS) condition.
Why It Matters
- Severity: CVSS 3.1 base score 9.8 (CRITICAL), vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. - No barriers to attack: The attack works over the network, has low complexity, and needs no privileges or user interaction.
- Potential full device compromise: Successful exploitation could give an attacker root-level code execution on network infrastructure.
- CISA SSVC assessment: According to the CVE.org record, CISA's coordinator rated exploitation as "none," automatable as "yes," and technical impact as "total."
- KEV status: No CISA KEV entry was supplied for this CVE. KEV does not confirm active exploitation at the time of writing.
What's Vulnerable
Cisco NX-OS Software is affected when the NGOAM feature is enabled. The affected versions listed in the NVD record are:
- 9.3 train: 9.3(3) through 9.3(17), including 9.3(5w), 9.3(7a), and 9.3(7k)
- 10.3 train: 10.3(1) through 10.3(9), including variant builds such as 10.3(3o/p/q/r/w/x), 10.3(4a/g/h), 10.3(99w), and 10.3(99x)
- 10.4 train: 10.4(1) through 10.4(7), including 10.4(4g)
- 10.5 train: 10.5(1) through 10.5(5), including 10.5(3e/o/p/s/t)
- 10.6 train: 10.6(1), 10.6(1s), 10.6(2), 10.6(2n), 10.6(2s), 10.6(3), and 10.6(3s)
The supplied data lists no affected CPEs. The NVD record status is "Received" (published 2026-10-07).
Patch Status
The supplied NVD data does not list fixed software releases or workarounds, and there is no CISA KEV required action or due date. Administrators should:
- Use the Cisco Security Advisory (cisco-sa-ngoam-rce-LWKQ4BU) to find fixed releases and any mitigations.
- Check whether NGOAM is enabled on NX-OS devices running affected versions. The vulnerable path can only be reached when the feature is on.