In the last three days, NVD published seven CRITICAL, network-vector CVEs affecting Cisco products, with CVSS scores topping out at 9.8. The cluster includes CVE-2026-76480, CVE-2026-76485, CVE-2026-76486, CVE-2026-76500, CVE-2026-76501, CVE-2026-20328, and CVE-2026-76454. Two distinct product lines take the heaviest hits: Cisco License On-Prem (formerly Smart Software Manager On-Prem / SSM On-Prem) and Cisco NX-OS, specifically the VXLAN Operation, Administration, and Maintenance (OAM) feature.
If you run a data center fabric on Nexus switches or manage Smart Licensing through an on-prem SSM satellite, this is a drop-everything patch cycle. Network-exploitable, pre-authentication-style flaws at 9.8 severity in infrastructure this central are exactly the class of bugs that ends up in CISA KEV and in ransomware operator tooling within weeks.
What Happened
The headline bug, CVE-2026-76480 (CVSS 9.8), affects Cisco License On-Prem — the on-premises licensing satellite that virtually every large Cisco estate uses to synchronize Smart Licensing entitlements without direct internet exposure. Per Cisco's disclosure language, this flaw was internally discovered during a comprehensive security review that produced software hardening releases. That framing matters: internally discovered means we have a window — possibly a short one — before external researchers and threat actors reverse-engineer the patches and develop exploits.
Meanwhile, CVE-2026-76485 and CVE-2026-76486 (both CVSS 9.8) affect the VXLAN OAM feature of Cisco NX-OS. VXLAN OAM (NGOAM) is used for fault management and continuity checks in VXLAN EVPN fabrics — meaning the vulnerable code path processes specially crafted packets arriving over the data plane. That is about as exposed as a parsing bug can get in a modern spine-and-leaf data center.
Technical Analysis
Affected Products
| Product | CVEs | Max CVSS | Attack Vector |
|---|---|---|---|
| Cisco License On-Prem (SSM On-Prem) | CVE-2026-76480 (and related hardening CVEs) | 9.8 | Network (management interface / API) |
| Cisco NX-OS (VXLAN OAM feature) | CVE-2026-76485, CVE-2026-76486 | 9.8 | Network (data plane, crafted VXLAN OAM packets) |
| Additional Cisco products | CVE-2026-76500, CVE-2026-76501, CVE-2026-20328, CVE-2026-76454 | Critical | Network |
Why These Bugs Are Dangerous
SSM On-Prem (CVE-2026-76480): The licensing satellite is a privileged position in the network. It holds service accounts, syncs with Cisco's cloud (CSSM), and — critically — is frequently deployed with management interfaces reachable from broad internal network segments because every licensed device needs to talk to it. A 9.8 network-exploitable flaw here is an ideal initial-access and persistence pivot: compromise the license server, and you've landed on a box that every switch, router, firewall, and collaboration endpoint in the enterprise trusts and communicates with regularly.
NX-OS VXLAN OAM (CVE-2026-76485 / CVE-2026-76486): OAM features parse control traffic from the fabric itself. Exploitation typically requires the attacker to send malformed OAM packets to a vulnerable switch — which means any compromised host, rogue VM, or tenant workload inside the data center fabric could potentially crash or compromise adjacent Nexus switches. In multi-tenant or co-lo environments, the blast radius is severe. VXLAN OAM operates over UDP — commonly associated with port 4789 (VXLAN) and the NGOAM channel — giving defenders concrete network telemetry to hunt against.
Exploitation Status
As of publication, these CVEs were disclosed through Cisco's internal review process with no confirmed in-the-wild exploitation and (at time of writing) no confirmed CISA KEV listing. Do not let that lull you. Cisco infrastructure CVEs at 9.8 have a consistent historical pattern: PoC surfaces within days-to-weeks of patch release via patch diffing, and mass scanning follows. Treat this as a pre-exploitation window and act accordingly.
Detection & Response
Detection for network-appliance CVEs lives at two layers: (1) network telemetry — who is talking to your SSM On-Prem management interface and what VXLAN OAM traffic is flowing where it shouldn't, and (2) device syslog — NX-OS and SSM On-Prem forwarding to your SIEM. The detections below assume you ingest Cisco syslog via CEF/Syslog into Sentinel and have network connection logging (firewall/Zeek/EDR) available.
Sigma Rules
---
title: Unexpected Connection to Cisco SSM On-Prem Management Interface
id: 9c1e4a72-3b5f-4d28-a6e1-7f2c8d90b1a3
status: experimental
description: Detects network connections to Cisco Smart Software Manager On-Prem management/API ports (443, 8443) from sources outside expected licensing client behavior, potentially indicating exploitation attempts against CVE-2026-76480.
references:
- https://nvd.nist.gov/vuln/detail/CVE-2026-76480
author: Security Arsenal
date: 2026/04/06
tags:
- attack.initial_access
- attack.t1190
logsource:
category: network_connection
product: zeek
detection:
selection:
dst_port:
- 443
- 8443
dst_ip|cidr:
- 'SSM_ONPREM_IP/32'
filter_licensing_sync:
src_ip|cidr:
- 'KNOWN_LICENSED_DEVICE_RANGES'
condition: selection and not filter_licensing_sync
falsepositives:
- Legitimate administrator access from jump hosts (tune filter to your admin subnets)
- Vulnerability scanner activity (allowlist scanner IPs)
level: high
---
title: Anomalous VXLAN OAM Traffic From Non-VTEP Source
id: 2f7b8c41-6e9a-4d13-b8f5-3a1c6e07d294
status: experimental
description: Detects VXLAN (UDP 4789) traffic originating from hosts that are not legitimate VTEPs (Nexus switches), which may indicate crafted VXLAN OAM packets targeting CVE-2026-76485 or CVE-2026-76486 in Cisco NX-OS.
references:
- https://nvd.nist.gov/vuln/detail/CVE-2026-76485
- https://nvd.nist.gov/vuln/detail/CVE-2026-76486
author: Security Arsenal
date: 2026/04/06
tags:
- attack.lateral_movement
- attack.t1210
logsource:
category: network_connection
product: zeek
detection:
selection:
dst_port: 4789
proto: udp
filter_vteps:
src_ip|cidr:
- 'AUTHORIZED_VTEP_RANGES'
condition: selection and not filter_vteps
falsepositives:
- Misconfigured hypervisor VXLAN endpoints (verify and correct config)
- Overlay-enabled workloads (document and allowlist explicitly)
level: critical
---
title: Cisco NX-OS Process Crash or Core Dump Indicators in Syslog
id: 5d3a9f06-1c84-4e27-b9d0-8f4e2a15c736
status: experimental
description: Detects NX-OS syslog messages indicating a crashing or restarting process (including NGOAM/VXLAN OAM components), which may follow exploitation attempts against CVE-2026-76485/CVE-2026-76486.
references:
- https://nvd.nist.gov/vuln/detail/CVE-2026-76486
author: Security Arsenal
date: 2026/04/06
tags:
- attack.impact
- attack.t1499
logsource:
product: cisco
service: nxos
detection:
selection:
Message|contains:
- 'core dump'
- 'process crashed'
- 'Service crashed'
- 'ngoam'
- 'eth_oam'
- 'SYSMGR-2-SERVICE_CRASHED'
- 'kern panic'
condition: selection
falsepositives:
- Hardware faults and memory parity errors (correlate with hardware diagnostics)
- Known unstable code on older releases
level: high
Note: Replace the placeholder CIDRs (
SSM_ONPREM_IP/32,KNOWN_LICENSED_DEVICE_RANGES,AUTHORIZED_VTEP_RANGES) with your actual addressing before deploying. These rules are tuned for low-noise environments — if you cannot enumerate your VTEPs, start with rule two in alert-only mode and baseline for 72 hours.
KQL — Microsoft Sentinel / Defender
// Hunt 1: Syslog from NX-OS devices showing VXLAN OAM process instability or crash events
// Assumes Cisco syslog ingestion via Syslog or CommonSecurityLog (CEF) tables
union isfuzzy=true
(Syslog
| where Facility =~ "local7" or SyslogMessage has_any ("ngoam", "VXLAN", "OAM")
| where SyslogMessage has_any ("crash", "core", "restart", "SYSMGR-2-SERVICE_CRASHED", "L2FM", "BGP")),
(CommonSecurityLog
| where DeviceVendor =~ "Cisco"
| where Message has_any ("ngoam", "oam", "crash", "core dump", "SERVICE_CRASHED"))
| summarize EventCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated)
by Computer, DeviceProduct, SyslogMessage = tostring(column_ifexists("SyslogMessage", Message))
| order by EventCount desc
;
// Hunt 2: Network connections to SSM On-Prem from non-switch sources (via firewall/CEF logs)
CommonSecurityLog
| where DestinationPort in (443, 8443)
| where DestinationIP == "<SSM_ONPREM_IP>" // replace with your SSM On-Prem address
| where DeviceVendor !~ "Cisco" or DeviceAction =~ "allowed"
| summarize ConnCount = count(), DistinctSources = dcount(SourceIP), SourceIPs = make_set(SourceIP, 20)
by DestinationIP, DestinationPort, bin(TimeGenerated, 1h)
| where DistinctSources > 5 // flag unusual fan-in from unexpected segments
| order by TimeGenerated desc
;
// Hunt 3: Endpoints sending UDP 4789 (VXLAN) — only VTEPs should ever do this
DeviceNetworkEvents
| where RemotePort == 4789 and Protocol =~ "Udp"
| summarize FirstSeen = min(Timestamp), LastSeen = max(Timestamp), Targets = make_set(RemoteIP, 25)
by DeviceName, InitiatingProcessFileName, LocalIP
| order by FirstSeen asc
Velociraptor VQL
For endpoint-side hunting — identifying servers or workstations originating VXLAN-encapsulated traffic or establishing suspicious sessions to your licensing infrastructure:
-- Hunt for endpoints with UDP 4789 (VXLAN) sockets or connections to SSM On-Prem
-- Only legitimate VTEPs should source VXLAN; flag everything else
SELECT Pid, Name, Path, CommandLine,
Address AS LocalAddr, Port AS LocalPort,
Raddress AS RemoteAddr, Rport AS RemotePort,
Status
FROM netstat()
WHERE (RemotePort = 4789 OR LocalPort = 4789)
OR (RemoteAddr =~ '<SSM_ONPREM_IP>' AND RemotePort in (443, 8443))
-- Broader sweep: processes holding listening sockets on licensing-related ports
-- on systems that should NOT be running licensing services (impostor/pivot detection)
SELECT Pid, Name, Path, CommandLine, Port, Address, Status
FROM netstat()
WHERE Status =~ 'LISTEN'
AND Port in (8443)
AND NOT Path =~ 'Cisco|cssm|license'
Remediation & Verification Script
Use this Bash script against your NX-OS inventory (via SSH with show commands) and SSM On-Prem hosts to establish exposure and verify hardening posture:
#!/bin/bash
# Cisco CVE-2026-76480 / 76485 / 76486 exposure assessment
# Run from a management jump host with SSH access to Nexus inventory
DEVICE_LIST="nexus_inventory.txt" # one management IP per line
SSM_HOST="<SSM_ONPREM_IP>"
echo "=== NX-OS Version & VXLAN OAM Feature Check ==="
while read -r dev; do
echo "--- $dev ---"
# Pull NX-OS version for advisory mapping
ssh -o ConnectTimeout=5 -o BatchMode=yes admin@"$dev" "show version | include 'NXOS|kickstart|system'" 2>/dev/null
# Is VXLAN/NGOAM enabled? If not, attack surface is reduced
ssh admin@"$dev" "show feature | include 'nv overlay|vnseg|ngoam|eth_oam'" 2>/dev/null
# Check for OAM configuration on interfaces
ssh admin@"$dev" "show running-config | include 'oam|vxlan'" 2>/dev/null
# Recent crash evidence?
ssh admin@"$dev" "show cores" 2>/dev/null
ssh admin@"$dev" "show logging logfile | include 'CRASHED|core|ngoam' | last 20" 2>/dev/null
done < "$DEVICE_LIST"
echo ""
echo "=== SSM On-Prem Exposure Check ==="
# What is reachable on the licensing server, and from where?
nmap -sS -p 443,8443,22,80 "$SSM_HOST" -oG - | grep -E 'open|filtered'
# Verify current SSM On-Prem software version (requires valid session token)
curl -sk "https://$SSM_HOST:8443/api/v1/health" | python3 -m json.tool 2>/dev/null
echo ""
echo "=== ACTION ITEMS ==="
echo "1. Map NX-OS versions to Cisco advisory fixed releases"
echo "2. Upgrade SSM On-Prem to the latest hardening release per Cisco advisory"
echo "3. Restrict SSM On-Prem 443/8443 to licensed-device subnets + admin jump hosts via ACL"
echo "4. If VXLAN OAM not operationally required: 'no feature' the OAM components"
echo "5. Apply control-plane policing (CoPP) to rate-limit OAM traffic to trusted VTEPs"
Remediation
Priority 1 — SSM On-Prem (CVE-2026-76480, CVSS 9.8):
- Inventory every SSM On-Prem instance — including DR/backup satellites that teams forget exist. A forgotten licensing satellite is exactly where an attacker will persist.
- Apply Cisco's hardening release immediately. Cisco's advisory for this internally discovered issue ships fixed software; consult the advisory linked from CVE-2026-76480 and the Cisco Security Advisory portal (cisco.com/go/psirt) for the exact fixed version applicable to your train. Verify the running version post-upgrade via the SSM On-Prem console or API.
- Segment aggressively. SSM On-Prem management should be reachable only from (a) licensed Cisco devices on their sync ports and (b) a hardened admin jump host. If your licensing server is reachable from user VLANs, fix that today — this is free risk reduction regardless of patch status.
- Review SSM On-Prem local accounts and API tokens for signs of creation or use you don't recognize; rotate credentials as a precaution after patching.
Priority 2 — NX-OS VXLAN OAM (CVE-2026-76485, CVE-2026-76486, CVSS 9.8):
- Determine exposure first: if
nv overlay/ VXLAN EVPN is not enabled, these bugs are not reachable. Document that determination — auditors will ask. - Patch per Cisco advisory for your specific Nexus platform (N9K variants dominate here, but verify against the advisory's affected-product list, as software maintenance differs by platform and train).
- If patching must wait: implement infrastructure ACLs and CoPP policies restricting VXLAN OAM traffic to known VTEP addresses, and disable OAM features not operationally required. These are mitigations, not fixes — schedule the maintenance window.
- Baseline crash telemetry: pull
show coresand system logs from all fabric switches now so you have a clean baseline to hunt against going forward.
Priority 3 — Remaining CVEs (CVE-2026-76500, CVE-2026-76501, CVE-2026-20328, CVE-2026-76454): Cross-reference each against your asset inventory via the NVD entries and Cisco's advisory bundle. Critical network-vector Cisco CVEs published in the same window frequently share an advisory release — one maintenance action may close several.
Strategic notes: Watch CISA KEV closely over the next 30 days — Cisco 9.8s are KEV regulars, and KEV listing triggers a 21-day (or shorter) federal remediation deadline that's a good forcing function for private-sector SLAs too. Subscribe to Cisco PSIRT notifications if you haven't; internal-review disclosures like this one are precisely the patch-diffing targets where exploit development moves fastest.
Related Resources
Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.