CVE-2026-76485 CVE-2026-76486 CVE-2026-76501
Cisco Nexus 3000 and 9000 Series Switches NGOAM remote code execution vulnerabilities (CVE-2026-76485, CVE-2026-76486, CVE-2026-76501)
Unauthenticated remote attackers can execute code with root privileges or crash Cisco Nexus 3000 and 9000 switches when the NGOAM feature is enabled. Three CVEs rated 9.8 critical. Cisco states fixes are available; disable NGOAM if it is not required.
What happened
The Cisco NX-OS VXLAN Operation, Administration, and Maintenance feature, known as NGOAM, does not properly validate IP traffic when the feature is enabled. An attacker who can send crafted packets to an IP interface on an affected Nexus 3000 or 9000 Series switch could execute arbitrary code with root privileges, or crash processes and force a reload. The CVSS base score is 9.8 for each CVE; the attack is network-based, low complexity, and requires no credentials or user interaction.
CVE-2026-76501 involves the Segment Routing over IPv6 OAM implementation. It requires both NGOAM and SRv6 to be enabled on an affected Nexus 9000 Series switch.
Cisco PSIRT has stated that it is not aware of any public announcements or malicious use of these vulnerabilities. There is no CISA KEV entry for them.
Who is affected
Cisco NX-OS Software on Nexus 3000 and 9000 Series switches is affected when NGOAM is enabled.
- CVE-2026-76485 — Nexus 3000 and 9000 Series Switches, VXLAN OAM: NX-OS 9.2(3), 9.2(2v), 9.2(1), 9.2(2t), 9.2(3y), 9.3(2), 9.2(4), 9.3(1)
- CVE-2026-76486 — Nexus 3000 and 9000 Series Switches, VXLAN OAM: NX-OS 9.3(3), 9.3(4), 9.3(5), 9.3(6), 9.3(5w), 9.3(7), 9.3(7k), 9.3(7a)
- CVE-2026-76501 — Nexus 9000 Series Switches, SRv6 OAM: NX-OS 9.3(3), 9.3(4), 9.3(5), 9.3(6), 9.3(5w), 9.3(7), 9.3(7k), 9.3(7a)
What to do now
- Check whether NGOAM is required in your environment. If it is not required, disable it with the Cisco NX-OS CLI command
no feature ngoamin global configuration mode. Cisco states that this removes the attack vector but advises organisations to evaluate any impact in their own environment first. - If NGOAM is necessary, restrict which networks can reach the IP interfaces of affected switches until fixed releases can be applied.
- Apply Cisco's fixed releases. Cisco states fixes are available, but the specific release numbers are not reproduced in this advisory text; confirm the applicable fixed release for your NX-OS train in Cisco's security advisory.
- Monitor affected switches for unexpected reloads or process crashes after making changes.
How to detect it
Cisco has not published specific indicators of compromise for these vulnerabilities. Watch for unplanned reloads or NGOAM process crashes on affected switches, which the advisory describes as possible denial-of-service effects. Because successful exploitation can grant root code execution, also review for unexpected configuration changes or administrative actions.
Beyond the patch
These are network-facing switches that should not be reachable from untrusted networks. Virtual CISO Services (vCISO) can help map and reduce network exposure so an NGOAM-enabled switch is not left reachable without credentials. After attempted exploitation, root-level access leaves activity worth detecting; Managed Detection & Response (MDR) provides that detection and response capability.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| CVE-2026-76485 Cisco NX-OS Software | 9.2(3) 9.2(2v) 9.2(1) 9.2(2t) 9.2(3y) 9.3(2) 9.2(4) 9.3(1) | No fixed version listed yet |
| CVE-2026-76486, CVE-2026-76501 Cisco NX-OS Software | 9.3(3) 9.3(4) 9.3(5) 9.3(6) 9.3(5w) 9.3(7) 9.3(7k) 9.3(7a) | No fixed version listed yet |