Back Forkast.News Cisco NX-OS NGOAM Carries Three Unauthenticated Root RCEs, and Cisco Lists No Workarounds
Cisco’s October 7 NX-OS disclosure cycle put unauthenticated remote code execution across four functional planes of one operating system on the record. The four-advisory synthesis covered the shape of that day. This is the deep dive on one advisory, the monitoring plane: cisco-sa-ngoam-rce-LWKQ4BU , where the feature that verifies path health is the attack surface.
CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501 each carry CVSS 9.8 at CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H: unauthenticated, remote, no user interaction. All three are stack-based buffer overflows (CWE-121) from improper input validation of IP traffic when the Generation Operation, Administration, and Maintenance feature, NGOAM, is enabled. The attacker sends crafted packets to an IP interface on the switch and gets arbitrary code execution as root, or crashes processes hard enough to reload the device.
Feature-Gated Exposure
Which CVE you are exposed to is a configuration question, and the gates are narrow enough to audit.
CVE-2026-76485: NGOAM enabled, nothing else. Cisco’s advisory is blunt: “That is the only requirement.” Its machine-readable record lists known-affected releases across NX-OS 9.2 through 10.6 service packs on Nexus 3000 and Nexus 9000 switches in standalone NX-OS mode. Widest surface of the three by a distance.
CVE-2026-76486: NGOAM plus either Segment Routing over IPv6 (SRv6) or Network Virtualization Overlay. The overlay case needs a VXLAN EVPN VNI mapped to an NVE interface with at least one peer VTEP learned. Affected releases begin at 9.3.
CVE-2026-76501: NGOAM and SRv6 both enabled. Nexus 3000 switches do not support SRv6, so this one is Nexus 9000 only, and only the subset that runs SRv6.
Read the feature gates against the CVE list and the shape is familiar. The diagnostic subsystem, built to catch loops on Layer 3 interfaces and trace SRv6 paths with IPv6 ping and pathtrace, accepts unauthenticated input well enough to hand over root. The visibility feature is the widest unauthenticated RCE in the bundle. That is architectural debt in the diagnostic plane, the same class of problem the four-plane synthesis named, not an isolated coding slip.
No Workarounds, One Kill Switch
Cisco’s workaround section is one sentence: “There are no workarounds that address these vulnerabilities.”
What exists instead is narrower. If the network does not need NGOAM, no feature ngoam in global configuration mode removes the attack vector for all three CVEs. Cisco calls that a mitigation, proven in a test environment, and tells operators to weigh it against their own visibility requirements. Cisco also shipped Live Protect shields for all three CVEs as a temporary bridge until software updates can be scheduled. Shields are not the fix. The fix is the upgrade.
The upgrade line itself is worth stating precisely: the advisory and its machine-readable record do not print a fixed-release version string. Cisco routes operators to the Cisco Software Checker for first-fixed releases per platform, with the October 2026 NX-OS security hardening release as the fix train. There is no single version to patch to. There is a lookup.
All three bugs came out of Cisco’s own internal security testing, and PSIRT says it is aware of no public announcements and no malicious use. No known exploitation, no in-the-wild crash race. For now this is a disclosure, not an incident.
It still follows the S1HAL pattern : a feature on a critical plane, shipped reachable, carrying root. Operators running Nexus 3000 or 9000 in standalone NX-OS mode can settle their exposure question in three commands: show feature | include ngoam , show feature | include srv6 , and show feature | include nve . The switches that answer “enabled” are the ones this advisory is .
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
