Cyber & AI intelligence
Wasteland.
Briefs indexed3048
Issues31
Published Mondays07:30 CT
CVE · Critical CVE-2026-76501 2026-10-07

Cisco NX-OS NGOAM Flaw CVE-2026-76501 Allows Unauthenticated Root Code Execution via SRv6

"A critical (CVSS 9.8) vulnerability in the SRv6 OAM feature of Cisco NX-OS Software lets an unauthenticated, remote attacker run arbitrary code as root or cause a denial of service by sending crafted packets."

A critical (CVSS 9.8) vulnerability in the SRv6 OAM feature of Cisco NX-OS Software lets an unauthenticated, remote attacker run arbitrary code as root or cause a denial of service by sending crafted packets.

What Is It

CVE-2026-76501 affects the Segment Routing over IPv6 (SRv6) Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM. It comes from improper input validation of IP traffic when both the NGOAM and SRv6 features are enabled. Cisco classifies the weakness as CWE-121 (stack-based buffer overflow).

An attacker can exploit it by sending crafted packets to an IP interface on an affected device. A successful exploit could let the attacker execute arbitrary code with root privileges. It could also crash processes, causing the device to reload and creating a DoS condition.

Why It Matters

Root-level code execution on data center switching infrastructure would give an attacker full control of the device. The attack needs no credentials and only crafted packets sent to an IP interface. That low barrier means it could be exploited widely once working exploit details are available.

What's Vulnerable

The flaw affects Cisco NX-OS Software only when both NGOAM and SRv6 are enabled. The affected versions listed in the NVD record are:

Patch Status

The NVD record was published on 2026-10-07 and is in "Received" status. It does not list fixed releases or workarounds.

Administrators should: - Check the Cisco Security Advisory (cisco-sa-ngoam-rce-LWKQ4BU) for fixed software releases and any mitigation guidance. - Find NX-OS devices running affected versions that have both NGOAM and SRv6 enabled, and patch those first.

Sources