A critical (CVSS 9.8) vulnerability in the SRv6 OAM feature of Cisco NX-OS Software lets an unauthenticated, remote attacker run arbitrary code as root or cause a denial of service by sending crafted packets.
What Is It
CVE-2026-76501 affects the Segment Routing over IPv6 (SRv6) Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM. It comes from improper input validation of IP traffic when both the NGOAM and SRv6 features are enabled. Cisco classifies the weakness as CWE-121 (stack-based buffer overflow).
An attacker can exploit it by sending crafted packets to an IP interface on an affected device. A successful exploit could let the attacker execute arbitrary code with root privileges. It could also crash processes, causing the device to reload and creating a DoS condition.
Why It Matters
- CVSS 3.1: 9.8 Critical (
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) - No authentication or user interaction required, and attack complexity is low over the network.
- Exploitation status: The cited sources do not report any active exploitation.
Root-level code execution on data center switching infrastructure would give an attacker full control of the device. The attack needs no credentials and only crafted packets sent to an IP interface. That low barrier means it could be exploited widely once working exploit details are available.
What's Vulnerable
The flaw affects Cisco NX-OS Software only when both NGOAM and SRv6 are enabled. The affected versions listed in the NVD record are:
- 9.3 train: 9.3(3) through 9.3(17), including 9.3(5w), 9.3(7a), and 9.3(7k)
- 10.3 train: 10.3(1) through 10.3(9), including variants such as 10.3(3o/p/q/r/w/x), 10.3(4a/g/h), 10.3(99w), and 10.3(99x)
- 10.4 train: 10.4(1) through 10.4(7), including 10.4(4g)
- 10.5 train: 10.5(1) through 10.5(5), including 10.5(3e/o/p/s/t)
- 10.6 train: 10.6(1), 10.6(1s), 10.6(2), 10.6(2n), 10.6(2s), 10.6(3), and 10.6(3s)
Patch Status
The NVD record was published on 2026-10-07 and is in "Received" status. It does not list fixed releases or workarounds.
Administrators should:
- Check the Cisco Security Advisory (cisco-sa-ngoam-rce-LWKQ4BU) for fixed software releases and any mitigation guidance.
- Find NX-OS devices running affected versions that have both NGOAM and SRv6 enabled, and patch those first.