External risk intelligence

Cisco NX-OS VXLAN OAM Code Execution and DoS Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-76486

The vulnerability exists in the VXLAN OAM feature of Cisco NX-OS, which is a specialized networking protocol typically used within data center fabrics or internal network segments. While network-reachable, this protocol is not designed to be exposed to the public internet, and such interfaces are generally restricted to internal management or transit networks.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory details a critical vulnerability within Cisco's VXLAN OAM feature, affecting network devices. The flaw could allow an attacker to remotely execute code or disrupt services, potentially impacting network operations. The primary concern is to confirm if this specific feature is in use within your environment.

  • Vulnerability allows remote code execution or denial of service.
  • Matters for potential network disruption and unauthorized access.
  • Confirm if the affected feature is active in your network.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker could exploit this vulnerability by sending specially crafted IP packets to a network device where the VXLAN OAM feature is enabled. This could allow the attacker to execute arbitrary code with full administrative privileges, or cause the device to crash and restart, leading to a denial of service.

  • No authentication or user interaction needed.
  • Sending malformed IP traffic to VXLAN OAM.
  • Arbitrary code execution or denial of service.

Live Threat

Current exploitation, exposure, and threat context

An unauthenticated, remote attacker could exploit this vulnerability by sending crafted packets to an IP interface on an affected device when the VXLAN OAM feature is enabled. A successful exploit may allow the attacker to execute arbitrary code with root privileges or cause a Denial-of-Service (DoS) condition.

  • Root privileges or device availability at risk.
  • Crafted IP packets sent to an interface.
  • Arbitrary code execution or device crash.

Operational Fix

Recommended remediation, mitigation, and detection steps

The VXLAN OAM feature in Cisco NX-OS Software is likely managed by network infrastructure or platform teams. The first practical step is to identify all devices with this feature enabled, determine their network reachability and criticality, and then assign ownership for remediation planning.

  • Network infrastructure or platform teams own this.
  • Verify VXLAN OAM feature enablement and reachability.
  • Plan remediation based on asset criticality and risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Cisco NX-OS Software and its NGOAM feature?

Cisco NX-OS is a network operating system used to manage data center switches. The NGOAM component is a specific set of tools within this software designed for Operation, Administration, and Maintenance of VXLAN tunnels. VXLAN is a technology used to extend layer 2 networks over a layer 3 infrastructure, commonly used to build flexible, scalable data center fabrics.

What is the vulnerability class for CVE-2026-76486?

This issue is classified under CWE-121, which refers to stack-based buffer overflow. In the context of this CVE, it means the software fails to properly validate the size and structure of incoming IP traffic intended for the NGOAM feature. When this validation fails, it can overwrite adjacent memory, potentially allowing an attacker to run their own commands or crash the system.

How does an attacker trigger this vulnerability?

An attacker triggers the vulnerability by sending specifically formatted, malicious IP packets to an affected device. Crucially, the vulnerability only exists when the NGOAM feature is explicitly enabled on the device. If the feature is disabled, the software code responsible for parsing this traffic is not active, and therefore the device cannot be compromised in this way.

How relevant is this to my organization's security?

According to Halo Surface Signal, this vulnerability is classified as unlikely to be exposed publicly. Because the NGOAM feature is meant for data center fabrics or internal network segments, it should not be reachable from the public internet. However, if your internal network architecture allows broad, unsegmented access, the risk increases for lateral movement by an attacker who has already gained a foothold inside your perimeter.

What should I do if I run Cisco NX-OS?

Your first step is to perform an inventory of your network infrastructure to identify which devices have the VXLAN OAM (NGOAM) feature enabled. Once you have identified these assets, evaluate their network reachability and business criticality to prioritize your response. Coordinate with your network infrastructure or platform teams to confirm if this feature is required and plan for necessary software updates or configuration changes.

References