Description
A vulnerability in the Segment Routing over IPv6 (SRv6) Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) on an affected device.

This vulnerability is due to improper input validation of IP traffic when the NGOAM and SRv6 features are enabled. An attacker could exploit this vulnerability by sending crafted packets to an IP interface on an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes resulting in a reload and DoS condition.
Published: 2026-10-07
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an improper input validation flaw in the Segment Routing over IPv6 (SRv6) Operation, Administration, and Maintenance (OAM) feature of Cisco NX‑OS Software, designated NGOAM. It allows an unauthenticated remote attacker to send crafted IP packets to an interface on the switch, leading to arbitrary code execution with root privileges or to a denial of service by causing process crashes that trigger a reload. The weakness is a stack‑based buffer overflow (CWE‑121), which can compromise confidentiality, integrity, and availability by granting full control of the device.

Affected Systems

The affected products are Cisco NX‑OS Software running on Cisco Nexus 9000 Series switches. The advisories indicate that the vulnerability exists when the NGOAM and SRv6 features are enabled. No specific version ranges are provided in the data, so all installations of NX‑OS Software on Nexus 9000 devices that have these features enabled are potentially impacted.

Risk and Exploitability

The CVSS score of 9.8 marks this as critical, and the EPSS score is not available, implying that its exploit probability is currently unknown but potentially high given the remote code execution nature. The vulnerability is not listed in the CISA KEV catalog, but because it can be triggered over the network by unauthenticated traffic, the likelihood of exploitation is significant in environments where SRv6/NGOAM is enabled. The attack path requires only sending specially crafted packets to a device IP interface; no user interaction or privileged login is needed.

Generated by OpenCVE AI on October 7, 2026 at 18:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Cisco NX‑OS Software patch or firmware update that addresses the NGOAM buffer overflow
  • If a patch is not immediately available, disable the SRv6 and NGOAM features to eliminate the attack surface
  • Actively monitor the switch IP interfaces for anomalous packet patterns that could indicate attempts to exploit the vulnerability and apply network‑based intrusion detection rules if possible

Generated by OpenCVE AI on October 7, 2026 at 18:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in the Segment Routing over IPv6 (SRv6) Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) on an affected device. This vulnerability is due to improper input validation of IP traffic when the NGOAM and SRv6 features are enabled. An attacker could exploit this vulnerability by sending crafted packets to an IP interface on an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes resulting in a reload and DoS condition.
Title Cisco Nexus 9000 Series Switches SRv6 OAM (NGOAM) Remote Code Execution Vulnerability
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-10-08T03:55:37.730Z

Reserved: 2026-08-19T12:02:03.641Z

Link: CVE-2026-76501

cve-icon Vulnrichment

Updated: 2026-10-07T16:41:33.140Z

cve-icon NVD

Status : Received

Published: 2026-10-07T17:17:02.113

Modified: 2026-10-08T04:17:35.760

Link: CVE-2026-76501

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T18:45:12Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow