Cisco Patches 18 CVEs, Including Three 9.8-Rated RCE Flaws in NX-OS
Cisco released fixes for 18 vulnerabilities, seven of them critical. Three unauthenticated RCE flaws rated CVSS 9.8 in the NGOAM (VXLAN OAM) feature affect Nexus 3000 and 9000 switches. No exploitation has been observed and no workarounds exist.
- CVE-2026-76485, CVE-2026-76486 and CVE-2026-76501 are unauthenticated RCE flaws rated CVSS 9.8
- Affected: Cisco Nexus 3000 and 9000 switches via the NGOAM (VXLAN OAM) feature
- CVE-2026-76501 requires SRv6 and hits Nexus 9000 only
- No exploitation seen and no workarounds — patching is the only fix
Read next
Security