Cisco said in a security advisory that three flaws in its NX-OS switch software could let an attacker take over a device. They sit in a feature called Next Generation OAM, or NGOAM. The attacker needs no login and can strike over the network. Specially built packets sent to an IP interface could run code with root rights, the highest access level. They could also crash processes and force the switch to reload. The flaws are CVE-2026-76485, CVE-2026-76486 and CVE-2026-76501. They affect Nexus 3000 and Nexus 9000 switches in standalone NX-OS mode with NGOAM turned on. Cisco said it has released software updates.
Cisco's incident response team said it knows of no public announcements or malicious use of the flaws. Cisco said its own internal testing found them. Exposure differs by flaw. The first needs only NGOAM. The second needs NGOAM plus either SRv6 or NV Overlay, with extra setup for the latter. The third needs NGOAM and SRv6. Cisco listed products that are not affected, including Nexus 7000 and Nexus 9000 switches in ACI mode. Cisco's Software Checker tool shows the first fixed release for a given version.
Network teams running Nexus 3000 or 9000 switches can check whether NGOAM is on, because all three flaws depend on it. Cisco says no workarounds exist. It also says turning NGOAM off, where it is not needed, removes the attack path. Temporary Live Protect shields cover the gap until teams can schedule the upgrade.