Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-76465: Cisco Nexus Switches allow remote code execution via MPLS

CVE-2026-76465 · published 4 days ago
Summary

The MPLS feature on Cisco Nexus 3000 and 9000 series switches can be tricked by a specially crafted network packet. An attacker who can send such a packet could take full control of the switch or cause it to restart, disrupting network services. Apply the latest Cisco software updates and restrict MPLS traffic to trusted sources to protect your devices.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
cisco cisco nx-os software 9.3(2)
Original advisory text
Cisco Nexus 3000 and 9000 Series Switches MPLS OAM Remote Code Execution Vulnerability
A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device.

This vulnerability is due to improper validation when an affected device is processing an MPLS echo-request packet. An attacker could exploit this vulnerability by sending a crafted MPLS echo-request to an IP address on an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes, which could result in a device reload and a DoS condition.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-590Free of Memory not on the Heap
Timeline
Published7 Oct 2026
Updated8 Oct 2026
First seen7 Oct 2026
Sources
CVE-2026-76465 · MITRE
Track software like this
Free during beta