Cisco NX-OS NGOAM Carries Three Unauthenticated Root RCEs, and Cisco Lists No Workarounds

Cisco NX-OS NGOAM Carries Three Unauthenticated Root RCEs, and Cisco Lists No Workarounds

By Heath Callahan
Publication Date: 2026-10-09 14:39:00

Analysis

NGOAM exists to verify path health on Cisco Nexus switches. CVE-2026-76485 needs only that feature switched on to hand an unauthenticated attacker root, and Cisco’s workaround section is one sentence: there are none.

The Monitoring Plane as an Attack Vector

Cisco’s October 7 NX-OS disclosure cycle put unauthenticated remote code execution across four functional planes of one operating system on the record. The four-advisory synthesis covered the shape of that day. This is the deep dive on one advisory, the monitoring plane: cisco-sa-ngoam-rce-LWKQ4BU, where the feature that verifies path health is the attack surface.

CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501 each carry CVSS 9.8 at CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H: unauthenticated, remote, no user interaction. All three are stack-based buffer overflows (CWE-121) from improper input validation of IP traffic when the Next Generation Operation, Administration, and Maintenance feature, NGOAM, is enabled….