CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-76485

CVE-2026-76485: Remote Code Execution in Cisco NX-OS VXLAN OAM (NGOAM)

Alon Barad
Alon Barad
Software Engineer

Oct 8, 2026·6 min read·6 visits

Executive Summary (TL;DR)

Unauthenticated remote code execution and denial of service vulnerability in Cisco NX-OS NGOAM feature due to improper input validation during packet parsing.

CVE-2026-76485 is a critical stack-based buffer overflow vulnerability in the VXLAN OAM (NGOAM) parsing component of Cisco NX-OS Software. The flaw enables an unauthenticated, remote attacker to execute arbitrary code with root privileges or trigger a denial of service on affected Nexus switches. This vulnerability is triggered through crafted packets sent to an IP interface. No workarounds are currently available to mitigate the vulnerability while preserving the NGOAM functionality. Cisco has published software patches to address this flaw.

Vulnerability Overview

The VXLAN Operation, Administration, and Maintenance (OAM) feature in Cisco NX-OS Software, commonly referred to as NGOAM, contains a critical vulnerability that permits unauthenticated remote code execution or complete system denial of service. The underlying system component, NGOAM, processes diagnostic control queries to verify overlay path integrity, running with administrative privileges. This design exposes a high-value attack surface on affected Cisco Nexus switches, particularly in data center and enterprise environments.\n\nAn unauthenticated, network-based attacker can target this service by transmitting crafted packets directly to any IP interface on the switch where the NGOAM feature is enabled. Successful exploitation of this flaw allows full control of the device, enabling administrative access or causing process failures that trigger a full system reload.\n\nThis vulnerability is tracked as CVE-2026-76485. The vulnerability resides within the packet parsing routines of the NGOAM daemon, which fails to correctly restrict memory write sizes during data processing.

Root Cause Analysis

The root cause of CVE-2026-76485 is a stack-based buffer overflow (CWE-121) occurring in the NGOAM packet parsing library. When receiving VXLAN OAM control packets, the parser extracts diagnostic fields including Type-Length-Value (TLV) parameters. The parsing function decodes the length attribute directly from the network packet headers without confirming that this value is within the boundaries of the pre-allocated stack buffer.\n\nOnce the length parameter is extracted, the daemon utilizes memory copy operations such as memcpy to transfer the incoming payload into local stack variables. Because the function does not validate the source length against the destination buffer boundaries, a packet specifying an oversized length parameter causes data to overflow the designated buffer boundaries.\n\nThis overflow corrupts the adjacent memory on the stack, which contains crucial control structure data. Specifically, the data overwrites the saved frame pointer and the return instruction pointer of the active function stack. Consequently, when the parsing function completes, the processor jumps to an address supplied by the attacker, leading to control flow hijacking.

Code Analysis

A conceptual analysis of the vulnerable parsing logic reveals the missing validation step during TLV extraction. The original, unpatched code extracts the length directly from the network payload and performs a memcpy operation. This direct copy allows any payload larger than the stack allocation to overwrite adjacent memory frames.\n\nc\n// Vulnerable Implementation\nvoid process_ngoam_packet(char *packet_data, uint16_t packet_len) {\n char stack_buffer[256]; // Fixed-size destination buffer\n uint16_t data_length;\n\n // Extract the length attribute directly from the packet header\n data_length = *(uint16_t *)(packet_data + OFFSET_LENGTH);\n\n // UNBOUNDED COPY: data_length is trusted and not verified\n memcpy(stack_buffer, packet_data + OFFSET_PAYLOAD, data_length);\n}\n\n\nThe patch introduces explicit size validation before the memory copy occurs. If the length parameter exceeds the size of the target buffer, the process logs an error and terminates processing of the packet, preventing any out-of-bounds write from occurring on the stack.\n\nc\n// Patched Implementation\nvoid process_ngoam_packet(char *packet_data, uint16_t packet_len) {\n char stack_buffer[256];\n uint16_t data_length;\n\n data_length = *(uint16_t *)(packet_data + OFFSET_LENGTH);\n\n // BOUNDS CHECK: Verify length does not exceed stack_buffer capacity\n if (data_length > sizeof(stack_buffer)) {\n log_security_alert(\"Invalid NGOAM TLV length\");\n return; // Terminate execution safely\n }\n\n // Safe memory copy within validated bounds\n memcpy(stack_buffer, packet_data + OFFSET_PAYLOAD, data_length);\n}\n

Exploitation Methodology

Exploitation of CVE-2026-76485 requires network access to the IP interface of the target switch with NGOAM enabled. The attacker must construct a custom UDP packet destined for the port handled by the NGOAM process, containing a corrupted TLV length field. No previous authentication or user interaction is required to trigger the vulnerability, as the packet is processed automatically by the system daemon upon arrival.\n\nTo cause a denial of service, the attacker can transmit a random high-value length attribute in the header, corrupting the return pointer with invalid addresses. This corruption triggers a hardware-level segmentation fault, which causes the ngoam daemon to crash. Due to the high availability architecture of NX-OS, this critical daemon crash causes the system watchdog to initiate a complete device reload.\n\nTo execute arbitrary code, the attacker must design a precise payload that matches the stack layout of the specific NX-OS platform. By stuffing the buffer with shellcode and overwriting the return address to point to the shellcode address, execution is redirected. Because the daemon executes with root administrative permissions, the resulting hijacked process runs with equivalent system privileges.

Impact Assessment

The impact of a successful exploit of CVE-2026-76485 is critical, compromising the entire network platform. An attacker achieving remote code execution as root can gain full administrative access to the command-line interface, configuration files, and cryptographic keys stored on the device. This control allows unauthorized modification of routing tables, interception of network traffic, and potential lateral movement across the enterprise or data center network.\n\nIf used to trigger a denial of service, the vulnerability can repeatedly reload the core or distribution layer switches. In a high-capacity data center VXLAN fabric, reloading key leaf or spine switches disrupts packet forwarding, resulting in packet loss and application downtime. The ease of access and lack of required credentials maximize the potential for disruption.\n\nThe CVSS v3.1 score of 9.8 reflects the high severity of the threat, driven by network-based exploitability and low complexity. Although active exploitation or weaponized public exploits have not been reported in the wild, the severity of the potential impact makes rapid mitigation necessary for affected organizations.

Remediation and Mitigation

Remediation requires upgrading the Cisco NX-OS Software to a patched version containing the validation fixes. Because no software workarounds exist that can disable the vulnerability while maintaining the functionality of the NGOAM feature, applying the official vendor update is the only complete resolution. The fixed releases validate the length of all TLV parameters before executing memory operations.\n\nIn environments where immediate patching is not possible, organizations should implement defense-in-depth measures to restrict exposure. Configuring Infrastructure Access Control Lists (iACLs) on boundary routers can drop unsolicited UDP packets targeted at NGOAM diagnostic ports. Control Plane Policing (CoPP) should also be configured to drop unauthorized OAM traffic at the device boundary.\n\nAdministrators must audit their network device configurations to identify whether the NGOAM or VXLAN OAM feature is enabled. Removing the feature configuration from interfaces where it is not strictly required reduces the attack surface. Constant monitoring of system log messages for daemon crashes or unexpected reboots remains critical for early detection of potential attack indicators.

Technical Appendix

CVSS Score
9.8/ 10

Affected Systems

Cisco Nexus 3000 Series SwitchesCisco Nexus 9000 Series Switches

Affected Versions Detail

Product
Affected Versions
Fixed Version
NX-OS Software
Cisco
9.2.x, 9.3.x, 10.3.x, 10.4.x, 10.5.x, 10.6.xRefer to Cisco Advisory
AttributeDetail
CWE IDCWE-121
Attack VectorNetwork (AV:N)
CVSS v3.19.8 (Critical)
Exploit StatusNone
KEV StatusNot Listed
ImpactRemote Code Execution / Denial of Service

MITRE ATT&CK Mapping

T1190Exploit Public-Facing Application
Initial Access
T1203Exploitation for Client Execution
Execution
T1210Exploitation of Remote Services
Lateral Movement
T1499Endpoint Denial of Service
Impact

Vulnerability Timeline

CVE Published and Cisco Security Advisory Released
2026-10-07
NVD and global vulnerability database updates completed
2026-10-08

References & Sources

  • [1]Cisco Security Advisory
  • [2]CVE.org Record
  • [3]MITRE ATT&CK Search

More Reports

•about 1 hour ago•CVE-2026-105647
4.0

CVE-2026-105647: Server-Side Request Forgery via Favicon Probing in Ghost CMS

An unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Ghost CMS from version 6.54.1 to 6.65.0. The vulnerability stems from a validation bypass in the favicon resolution logic within the bookmark-fetching subsystem, which allows remote, unauthenticated attackers to trigger arbitrary HTTP requests to the local host and internal networks. This bypass circumvents the custom DNS-level IP blocklist controls configured globally in the application.

Alon Barad
Alon Barad
1 views•8 min read
•about 2 hours ago•CVE-2026-106450
5.3

CVE-2026-106450: Denial of Service via Eager Resource Allocation in lz4-java LZ4FrameInputStream

A resource allocation vulnerability (CWE-770) in lz4-java before version 1.11.4 allows an unauthenticated remote attacker to trigger CPU exhaustion and high garbage collection overhead by streaming empty concatenated LZ4 frames.

Alon Barad
Alon Barad
4 views•8 min read
•about 3 hours ago•CVE-2026-106449
3.7

CVE-2026-106449: Stack Overflow via Uncontrolled Recursion in yawkat lz4-java

A Denial of Service (DoS) vulnerability exists in the yawkat fork of lz4-java prior to version 1.11.4. Under specific non-default configurations (stopOnEmptyBlock = false), parsing crafted streams with a large sequence of contiguous empty LZ4 blocks triggers uncontrolled recursion inside the LZ4BlockInputStream.refill() method, causing stack exhaustion and thread termination.

Alon Barad
Alon Barad
3 views•6 min read
•about 4 hours ago•CVE-2026-106451
7.3

CVE-2026-106451: Local Privilege Escalation via JNI Extraction TOCTOU in lz4-java

A local privilege escalation and code execution vulnerability exists in the yawkat fork of lz4-java when extracting its bundled JNI shared library into the system temporary directory. Predictable path derivation and lack of exclusive file creation flags allow a local attacker to hijack library loading via a race condition.

Alon Barad
Alon Barad
6 views•6 min read
•about 5 hours ago•CVE-2026-105698
5.4

CVE-2026-105698: Missing Authorization in Deprecated Chat Vertices Endpoints in Langflow

A missing authorization vulnerability in Langflow versions 1.0.0 through 1.10.0 allows authenticated users (and unauthenticated users in versions prior to 1.7.2) to access private workflow structures and execute graph components by targeting deprecated API endpoints.

Amit Schendel
Amit Schendel
5 views•8 min read
•about 6 hours ago•CVE-2026-105697
9.9

CVE-2026-105697: OS Command Injection in Langflow Model Context Protocol Integration

A critical OS command injection vulnerability exists in Langflow's Model Context Protocol (MCP) server integration using stdio transport, allowing unauthenticated remote command execution under default configurations.

Alon Barad
Alon Barad
7 views•5 min read