Cisco NX-OS SRv6 NGOAM unauthenticated root RCE
A flaw in the NGOAM feature of Cisco NX-OS allows an unauthenticated remote attacker to execute arbitrary code as root on Nexus switches using crafted SRv6 OAM packets.
- Vendor
- Cisco
- Product
- NX-OS (Nexus series)
- CVSS
- 9.8
- EPSS (exploit probability)
- 0.5%
- Status
- patched
- Published
CVE-2026-76501 is a critical-severity vulnerability in the NGOAM feature of Cisco NX-OS. CVSS 9.8. No authentication required.
What it is
NGOAM (Next-Generation OAM) implements Operation, Administration, and Maintenance for Cisco’s Segment Routing over IPv6 (SRv6) stack in NX-OS. CVE-2026-76501 allows an unauthenticated, remote attacker to send crafted SRv6 OAM packets to an affected device and execute arbitrary code with root privileges, or cause a denial-of-service condition.
SRv6 is deployed in service provider and large enterprise networks running modern IPv6 transport infrastructure.
Affected products
Cisco Nexus switches running NX-OS with the SRv6 NGOAM feature enabled. See the Cisco advisory for specific affected NX-OS release trains and fixed versions.
Exploitation status
No active exploitation confirmed. Not in the CISA KEV catalog as of October 9, 2026.
Remediation
Cisco released patched NX-OS software versions. The advisory documents whether disabling NGOAM is a viable workaround for environments where it is not required.
FAQ
What is CVE-2026-76501? A critical flaw in the SRv6 NGOAM feature of Cisco NX-OS. An unauthenticated attacker with network access can send crafted OAM packets to gain root code execution on the switch.
What is NGOAM? NGOAM is a network management protocol component for Segment Routing over IPv6. It handles OAM (fault detection and measurement) functions in SRv6 transport deployments.
Is there active exploitation? No exploitation has been confirmed as of October 9, 2026. CISA has not added this to KEV.
