Threat reportVulnerabilityTL-2026-3209

Critical Cisco Nexus 3000/9000 NX-OS NGOAM Stack Buffer Overflows Allow Unauthenticated Root Code Execution (CVE-2026-76485, CVE-2026-76486, CVE-2026-76501)

criticalACTIVE

Critical Cisco Nexus 3000/9000 NX-OS NGOAM Stack Buffer (TL-2026-3209), also tracked as cisco-sa-ngoam-rce-LWKQ4BU, is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-10-10. It has no confirmed attribution, affects Cisco NX-OS Software on Nexus 3000 Series Switches (standalone NX-OS, references 3 CVEs (CVE-2026-76485, CVE-2026-76486, CVE-2026-76501), maps to 3 MITRE ATT&CK techniques (T1059, T1190, T1499.004), and is covered by 9 detection rules and 2 indicators of compromise.

CVSS
9.8/10Critical
CVEs
3Referenced vulnerabilities
Techniques
3MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
2Indicators of compromise

Key facts for TL-2026-3209

Threat ID
TL-2026-3209
Also known as
cisco-sa-ngoam-rce-LWKQ4BU, CSCwu19785, CSCwu19823, CSCwu57455
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
telecoms, data centers, enterprise, cloud service providers, finance, government administration
Target regions
Global
Detection rules
9
Indicators of compromise
2

Malware and tooling in Critical Cisco Nexus 3000/9000 NX-OS NGOAM Stack Buffer

Malware and tooling: Nexus

How Critical Cisco Nexus 3000/9000 NX-OS NGOAM Stack Buffer works

Three stack-based buffer overflows (CWE-121) in the NGOAM (VXLAN OAM) feature of Cisco NX-OS on Nexus 3000 and 9000 Series switches in standalone NX-OS mode let an unauthenticated remote attacker execute code as root, or crash and reload the device, via crafted IP traffic. Each is CVSS 9.8; Cisco advisory cisco-sa-ngoam-rce-LWKQ4BU was published 2026-10-07 and Cisco PSIRT reported no known public announcements or malicious exploitation at publication.

Cisco advisory cisco-sa-ngoam-rce-LWKQ4BU, published 2026-10-07, covers three vulnerabilities in the Next Generation Operation, Administration, and Maintenance (NGOAM, also described as VXLAN OAM) feature of Cisco NX-OS Software. The root cause in all three is improper input validation of IP traffic when NGOAM is enabled, resulting in stack-based buffer overflows (CWE-121). An unauthenticated, remote attacker who can send crafted packets to an IP interface of an affected device can execute arbitrary code with root privileges, or cause process crashes that lead to a device reload and denial of service. All three carry CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (9.8).

Exposure differs per CVE. CVE-2026-76485 requires only that NGOAM be enabled. CVE-2026-76486 requires NGOAM plus either Segment Routing over IPv6 (SRv6) or NV Overlay (NVE) with VXLAN EVPN VNI configuration (an active VXLAN EVPN peer). CVE-2026-76501 requires both NGOAM and SRv6 to be enabled. Cisco bug IDs are CSCwu19785, CSCwu19823 and CSCwu57455. Affected products are Cisco Nexus 3000 Series and Nexus 9000 Series switches running standalone NX-OS; Nexus 9000 in ACI mode and Nexus 7000 are not affected. Third-party CVE records list affected NX-OS ranges of 9.2(1) through 10.6(3s) for CVE-2026-76485 and 9.3(3)-9.3(17) plus 10.3(1)-10.6(3s) for CVE-2026-76486 and CVE-2026-76501.

Cisco states that no workarounds address the vulnerabilities, although disabling NGOAM (no feature ngoam) removes the attack vector; Cisco Live Protect shields are offered as a temporary mitigation. Fixed releases are determined with the Cisco Software Checker; the advisory sources reviewed do not enumerate them. A sibling issue disclosed alongside, CVE-2026-76465 (CWE-590, MPLS OAM echo-request handling, MPLS OAM disabled by default), is reported separately by SecurityOnline and is not part of this record. At publication no public exploit code, in-the-wild exploitation, attribution or network IOCs had been reported (CISA exploitation status 'none', EPSS <1% per OpenCVE). The IOCs recorded here are therefore exposure and hunting indicators (configuration state, commands, product identifiers), not adversary infrastructure. No network IOCs exist, so BeaconBeagle correlation was not applicable.

MITRE ATT&CK techniques used in TL-2026-3209

Execution

T1059 Command and Scripting Interpreter

Initial Access

T1190 Exploit Public-Facing Application

Impact

T1499.004 Endpoint Denial of Service: Application or System Exploitation

Affected products and versions in Critical Cisco Nexus 3000/9000 NX-OS NGOAM Stack Buffer

  • Cisco — NX-OS Software on Nexus 3000 Series Switches (standalone NX-OS mode)
    Vulnerable versions: 9.2(1) through 10.6(3s) (per CVE-2026-76485 record; see Cisco Software Checker)
    Fixed in: See Cisco Software Checker for fixed releases
  • Cisco — NX-OS Software on Nexus 9000 Series Switches (standalone NX-OS mode)
    Vulnerable versions: 9.2(1) through 10.6(3s) (CVE-2026-76485); 9.3(3) through 9.3(17) and 10.3(1) through 10.6(3s) (CVE-2026-76486, CVE-2026-76501)
    Fixed in: See Cisco Software Checker for fixed releases

Remediation for Critical Cisco Nexus 3000/9000 NX-OS NGOAM Stack Buffer

Patches

  • Upgrade NX-OS to a fixed release identified with the Cisco Software Checker for cisco-sa-ngoam-rce-LWKQ4BU

Immediate actions

  • Identify exposure with 'show feature | include ngoam', 'show feature | include srv6', 'show feature | include nve' and 'show nve peers'
  • Disable NGOAM where not required: 'no feature ngoam' in global configuration mode (removes the attack vector)
  • Apply Cisco Live Protect shields as a temporary mitigation for all three CVEs
  • Restrict reachability of switch IP interfaces to trusted management and underlay sources with ACLs/control-plane policing

Workarounds

  • Cisco states there are no workarounds that address the vulnerabilities; disabling NGOAM ('no feature ngoam') removes the attack vector

Longer-term hardening

  • Monitor switches for unexpected process crashes, core files and reloads
  • Segment and baseline underlay/management networks for Nexus devices
  • Track the advisory for revisions and any report of exploitation

CVEs associated with Critical Cisco Nexus 3000/9000 NX-OS NGOAM Stack Buffer

CVE-2026-76485, CVE-2026-76486, CVE-2026-76501

Weaknesses (CWE) in Critical Cisco Nexus 3000/9000 NX-OS NGOAM Stack Buffer

CWE-121

Timeline of Critical Cisco Nexus 3000/9000 NX-OS NGOAM Stack Buffer

  • Cisco published cisco-sa-nxos-ngoam-dos-LTDb9Hv (CVE-2021-1587), an earlier NGOAM denial-of-service flaw triggered by TRILL OAM EtherType 0x8902 packets, showing NGOAM as a recurring attack surface (distinct from the 2026 issues).
  • CVE-2026-76485, CVE-2026-76486 and CVE-2026-76501 were reserved; Cisco reports the flaws were found during internal security testing.
  • At publication Cisco PSIRT reported no known public announcements or malicious exploitation of these vulnerabilities; no workaround other than disabling NGOAM and Live Protect shields was offered.
  • Cisco published advisory cisco-sa-ngoam-rce-LWKQ4BU covering three CVSS 9.8 stack-based buffer overflows in NX-OS NGOAM on Nexus 3000/9000 (standalone NX-OS mode), with software updates available.
  • CVE records for CVE-2026-76485, CVE-2026-76486 and CVE-2026-76501 were updated with affected NX-OS version ranges; EPSS <1% and no known exploitation per CISA status.
  • GBHackers and SecurityOnline reported the flaws; SecurityOnline also noted the sibling MPLS OAM flaw CVE-2026-76465 disclosed alongside.

Sources cited for Critical Cisco Nexus 3000/9000 NX-OS NGOAM Stack Buffer

Detection coverage for TL-2026-3209

As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3209 across Splunk SPL, Microsoft KQL and Sigma, covering 2 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
2 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats