Remote Code Execution Vulnerability in Cisco NX-OS Software Segment Routing
CVE-2026-76501

9.8CRITICAL

Key Information:

Vendor

Cisco

Vendor
CVE Published:
7 October 2026

Badges

👾 Exploit Exists

What is CVE-2026-76501?

A vulnerability exists in the Segment Routing over IPv6 (SRv6) Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software. This flaw can be exploited by unauthenticated attackers to send specially crafted IP packets to the device, leading to arbitrary code execution with root privileges or causing a denial of service (DoS) condition. When both NGOAM and SRv6 features are enabled, the risk is exacerbated due to improper input validation of incoming traffic, potentially resulting in severe security breaches or service disruptions.

Affected Version(s)

Cisco NX-OS Software 9.3(3)

Cisco NX-OS Software 9.3(4)

Cisco NX-OS Software 9.3(5)

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.