# Critical Cisco Nexus 3000/9000 NX-OS NGOAM Stack Buffer Overflows Allow Unauthenticated Root Code Execution (CVE-2026-76485, CVE-2026-76486, CVE-2026-76501)

> Three stack-based buffer overflows (CWE-121) in the NGOAM (VXLAN OAM) feature of Cisco NX-OS on Nexus 3000 and 9000 Series switches in standalone NX-OS mode let an unauthenticated remote attacker execute code as root, or crash and reload the device, via crafted IP traffic. Each is CVSS 9.8; Cisco advisory cisco-sa-ngoam-rce-LWKQ4BU was published 2026-10-07 and Cisco PSIRT reported no known public announcements or malicious exploitation at publication.

- **Published:** 2026-10-10T00:00:00Z
- **Last reviewed:** 2026-10-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3209
- **ID:** TL-2026-3209
- **Severity:** CRITICAL (CVSS 9.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 2 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-76485, CVE-2026-76486, CVE-2026-76501

## Description

Cisco advisory cisco-sa-ngoam-rce-LWKQ4BU, published 2026-10-07, covers three vulnerabilities in the Next Generation Operation, Administration, and Maintenance (NGOAM, also described as VXLAN OAM) feature of Cisco NX-OS Software. The root cause in all three is improper input validation of IP traffic when NGOAM is enabled, resulting in stack-based buffer overflows (CWE-121). An unauthenticated, remote attacker who can send crafted packets to an IP interface of an affected device can execute arbitrary code with root privileges, or cause process crashes that lead to a device reload and denial of service. All three carry CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H (9.8).

Exposure differs per CVE. CVE-2026-76485 requires only that NGOAM be enabled. CVE-2026-76486 requires NGOAM plus either Segment Routing over IPv6 (SRv6) or NV Overlay (NVE) with VXLAN EVPN VNI configuration (an active VXLAN EVPN peer). CVE-2026-76501 requires both NGOAM and SRv6 to be enabled. Cisco bug IDs are CSCwu19785, CSCwu19823 and CSCwu57455. Affected products are Cisco Nexus 3000 Series and Nexus 9000 Series switches running standalone NX-OS; Nexus 9000 in ACI mode and Nexus 7000 are not affected. Third-party CVE records list affected NX-OS ranges of 9.2(1) through 10.6(3s) for CVE-2026-76485 and 9.3(3)-9.3(17) plus 10.3(1)-10.6(3s) for CVE-2026-76486 and CVE-2026-76501.

Cisco states that no workarounds address the vulnerabilities, although disabling NGOAM (no feature ngoam) removes the attack vector; Cisco Live Protect shields are offered as a temporary mitigation. Fixed releases are determined with the Cisco Software Checker; the advisory sources reviewed do not enumerate them. A sibling issue disclosed alongside, CVE-2026-76465 (CWE-590, MPLS OAM echo-request handling, MPLS OAM disabled by default), is reported separately by SecurityOnline and is not part of this record. At publication no public exploit code, in-the-wild exploitation, attribution or network IOCs had been reported (CISA exploitation status 'none', EPSS <1% per OpenCVE). The IOCs recorded here are therefore exposure and hunting indicators (configuration state, commands, product identifiers), not adversary infrastructure. No network IOCs exist, so BeaconBeagle correlation was not applicable.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1499.004 Endpoint Denial of Service: Application or System Exploitation

## Sources

- [Cisco Security Advisory cisco-sa-ngoam-rce-LWKQ4BU](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ngoam-rce-LWKQ4BU)
- [Critical Cisco Nexus Switch Vulnerabilities Allow Unauthenticated Attackers to Execute Code as Root](https://gbhackers.com/critical-cisco-nexus-switch-vulnerabilities/)
- [Cisco Nexus Vulnerabilities (OAM RCE) - SecurityOnline](https://securityonline.info/cisco-nexus-vulnerabilities-oam-rce/)
- [CVE-2026-76485 - OpenCVE](https://app.opencve.io/cve/CVE-2026-76485)
- [CVE-2026-76486 - OpenCVE](https://app.opencve.io/cve/CVE-2026-76486)
- [CVE-2026-76501 - OpenCVE](https://app.opencve.io/cve/CVE-2026-76501)
- [CVE-2026-76486 Cisco NX-OS NGOAM RCE/DoS - The Hacker Wire](https://www.thehackerwire.com/cve-2026-76486-cisco-nx-os-ngoam-rce-dos-via-crafted-vxlan-oam-packets/)
- [Cisco NX-OS NGOAM DoS advisory cisco-sa-nxos-ngoam-dos-LTDb9Hv (prior NGOAM issue, CVE-2021-1587)](https://www.cisco.com/c/en/us/support/docs/csa/cisco-sa-nxos-ngoam-dos-LTDb9Hv.html)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3209
