Oct 8, 2026·6 min read·6 visits
Unauthenticated remote code execution and denial of service vulnerability in Cisco NX-OS NGOAM feature due to improper input validation during packet parsing.
CVE-2026-76485 is a critical stack-based buffer overflow vulnerability in the VXLAN OAM (NGOAM) parsing component of Cisco NX-OS Software. The flaw enables an unauthenticated, remote attacker to execute arbitrary code with root privileges or trigger a denial of service on affected Nexus switches. This vulnerability is triggered through crafted packets sent to an IP interface. No workarounds are currently available to mitigate the vulnerability while preserving the NGOAM functionality. Cisco has published software patches to address this flaw.
The VXLAN Operation, Administration, and Maintenance (OAM) feature in Cisco NX-OS Software, commonly referred to as NGOAM, contains a critical vulnerability that permits unauthenticated remote code execution or complete system denial of service. The underlying system component, NGOAM, processes diagnostic control queries to verify overlay path integrity, running with administrative privileges. This design exposes a high-value attack surface on affected Cisco Nexus switches, particularly in data center and enterprise environments.\n\nAn unauthenticated, network-based attacker can target this service by transmitting crafted packets directly to any IP interface on the switch where the NGOAM feature is enabled. Successful exploitation of this flaw allows full control of the device, enabling administrative access or causing process failures that trigger a full system reload.\n\nThis vulnerability is tracked as CVE-2026-76485. The vulnerability resides within the packet parsing routines of the NGOAM daemon, which fails to correctly restrict memory write sizes during data processing.
The root cause of CVE-2026-76485 is a stack-based buffer overflow (CWE-121) occurring in the NGOAM packet parsing library. When receiving VXLAN OAM control packets, the parser extracts diagnostic fields including Type-Length-Value (TLV) parameters. The parsing function decodes the length attribute directly from the network packet headers without confirming that this value is within the boundaries of the pre-allocated stack buffer.\n\nOnce the length parameter is extracted, the daemon utilizes memory copy operations such as memcpy to transfer the incoming payload into local stack variables. Because the function does not validate the source length against the destination buffer boundaries, a packet specifying an oversized length parameter causes data to overflow the designated buffer boundaries.\n\nThis overflow corrupts the adjacent memory on the stack, which contains crucial control structure data. Specifically, the data overwrites the saved frame pointer and the return instruction pointer of the active function stack. Consequently, when the parsing function completes, the processor jumps to an address supplied by the attacker, leading to control flow hijacking.
A conceptual analysis of the vulnerable parsing logic reveals the missing validation step during TLV extraction. The original, unpatched code extracts the length directly from the network payload and performs a memcpy operation. This direct copy allows any payload larger than the stack allocation to overwrite adjacent memory frames.\n\nc\n// Vulnerable Implementation\nvoid process_ngoam_packet(char *packet_data, uint16_t packet_len) {\n char stack_buffer[256]; // Fixed-size destination buffer\n uint16_t data_length;\n\n // Extract the length attribute directly from the packet header\n data_length = *(uint16_t *)(packet_data + OFFSET_LENGTH);\n\n // UNBOUNDED COPY: data_length is trusted and not verified\n memcpy(stack_buffer, packet_data + OFFSET_PAYLOAD, data_length);\n}\n\n\nThe patch introduces explicit size validation before the memory copy occurs. If the length parameter exceeds the size of the target buffer, the process logs an error and terminates processing of the packet, preventing any out-of-bounds write from occurring on the stack.\n\nc\n// Patched Implementation\nvoid process_ngoam_packet(char *packet_data, uint16_t packet_len) {\n char stack_buffer[256];\n uint16_t data_length;\n\n data_length = *(uint16_t *)(packet_data + OFFSET_LENGTH);\n\n // BOUNDS CHECK: Verify length does not exceed stack_buffer capacity\n if (data_length > sizeof(stack_buffer)) {\n log_security_alert(\"Invalid NGOAM TLV length\");\n return; // Terminate execution safely\n }\n\n // Safe memory copy within validated bounds\n memcpy(stack_buffer, packet_data + OFFSET_PAYLOAD, data_length);\n}\n
Exploitation of CVE-2026-76485 requires network access to the IP interface of the target switch with NGOAM enabled. The attacker must construct a custom UDP packet destined for the port handled by the NGOAM process, containing a corrupted TLV length field. No previous authentication or user interaction is required to trigger the vulnerability, as the packet is processed automatically by the system daemon upon arrival.\n\nTo cause a denial of service, the attacker can transmit a random high-value length attribute in the header, corrupting the return pointer with invalid addresses. This corruption triggers a hardware-level segmentation fault, which causes the ngoam daemon to crash. Due to the high availability architecture of NX-OS, this critical daemon crash causes the system watchdog to initiate a complete device reload.\n\nTo execute arbitrary code, the attacker must design a precise payload that matches the stack layout of the specific NX-OS platform. By stuffing the buffer with shellcode and overwriting the return address to point to the shellcode address, execution is redirected. Because the daemon executes with root administrative permissions, the resulting hijacked process runs with equivalent system privileges.
The impact of a successful exploit of CVE-2026-76485 is critical, compromising the entire network platform. An attacker achieving remote code execution as root can gain full administrative access to the command-line interface, configuration files, and cryptographic keys stored on the device. This control allows unauthorized modification of routing tables, interception of network traffic, and potential lateral movement across the enterprise or data center network.\n\nIf used to trigger a denial of service, the vulnerability can repeatedly reload the core or distribution layer switches. In a high-capacity data center VXLAN fabric, reloading key leaf or spine switches disrupts packet forwarding, resulting in packet loss and application downtime. The ease of access and lack of required credentials maximize the potential for disruption.\n\nThe CVSS v3.1 score of 9.8 reflects the high severity of the threat, driven by network-based exploitability and low complexity. Although active exploitation or weaponized public exploits have not been reported in the wild, the severity of the potential impact makes rapid mitigation necessary for affected organizations.
Remediation requires upgrading the Cisco NX-OS Software to a patched version containing the validation fixes. Because no software workarounds exist that can disable the vulnerability while maintaining the functionality of the NGOAM feature, applying the official vendor update is the only complete resolution. The fixed releases validate the length of all TLV parameters before executing memory operations.\n\nIn environments where immediate patching is not possible, organizations should implement defense-in-depth measures to restrict exposure. Configuring Infrastructure Access Control Lists (iACLs) on boundary routers can drop unsolicited UDP packets targeted at NGOAM diagnostic ports. Control Plane Policing (CoPP) should also be configured to drop unauthorized OAM traffic at the device boundary.\n\nAdministrators must audit their network device configurations to identify whether the NGOAM or VXLAN OAM feature is enabled. Removing the feature configuration from interfaces where it is not strictly required reduces the attack surface. Constant monitoring of system log messages for daemon crashes or unexpected reboots remains critical for early detection of potential attack indicators.
| Product | Affected Versions | Fixed Version |
|---|---|---|
NX-OS Software Cisco | 9.2.x, 9.3.x, 10.3.x, 10.4.x, 10.5.x, 10.6.x | Refer to Cisco Advisory |
| Attribute | Detail |
|---|---|
| CWE ID | CWE-121 |
| Attack Vector | Network (AV:N) |
| CVSS v3.1 | 9.8 (Critical) |
| Exploit Status | None |
| KEV Status | Not Listed |
| Impact | Remote Code Execution / Denial of Service |
An unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Ghost CMS from version 6.54.1 to 6.65.0. The vulnerability stems from a validation bypass in the favicon resolution logic within the bookmark-fetching subsystem, which allows remote, unauthenticated attackers to trigger arbitrary HTTP requests to the local host and internal networks. This bypass circumvents the custom DNS-level IP blocklist controls configured globally in the application.
A resource allocation vulnerability (CWE-770) in lz4-java before version 1.11.4 allows an unauthenticated remote attacker to trigger CPU exhaustion and high garbage collection overhead by streaming empty concatenated LZ4 frames.
A Denial of Service (DoS) vulnerability exists in the yawkat fork of lz4-java prior to version 1.11.4. Under specific non-default configurations (stopOnEmptyBlock = false), parsing crafted streams with a large sequence of contiguous empty LZ4 blocks triggers uncontrolled recursion inside the LZ4BlockInputStream.refill() method, causing stack exhaustion and thread termination.
A local privilege escalation and code execution vulnerability exists in the yawkat fork of lz4-java when extracting its bundled JNI shared library into the system temporary directory. Predictable path derivation and lack of exclusive file creation flags allow a local attacker to hijack library loading via a race condition.
A missing authorization vulnerability in Langflow versions 1.0.0 through 1.10.0 allows authenticated users (and unauthenticated users in versions prior to 1.7.2) to access private workflow structures and execute graph components by targeting deprecated API endpoints.
A critical OS command injection vulnerability exists in Langflow's Model Context Protocol (MCP) server integration using stdio transport, allowing unauthenticated remote command execution under default configurations.