CVE-2026-76465 is a vulnerability in Cisco Nx Os
Published on October 7, 2026
Cisco Nexus 3000 and 9000 Series Switches MPLS OAM Remote Code Execution Vulnerability
A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device.
This vulnerability is due to improper validation when an affected device is processing an MPLS echo-request packet. An attacker could exploit this vulnerability by sending a crafted MPLS echo-request to an IP address on an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes, which could result in a device reload and a DoS condition.
Vulnerability Analysis
CVE-2026-76465 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.
Weakness Type
Free of Memory not on the Heap
The application calls free() on a pointer to memory that was not allocated using associated heap allocation functions such as malloc(), calloc(), or realloc(). When free() is called on an invalid pointer, the program's memory management data structures may become corrupted. This corruption can cause the program to crash or, in some circumstances, an attacker may be able to cause free() to operate on controllable memory locations to modify critical program variables or execute code.
Products Associated with CVE-2026-76465
Want to know whenever a new CVE is published for Cisco Nx Os? stack.watch will email you.
Affected Versions
Cisco NX-OS Software:- Version 9.3(2) is affected.
- Version 9.3(1) is affected.
- Version 9.3(1z) is affected.
- Version 9.3(3) is affected.
- Version 9.3(4) is affected.
- Version 9.3(5) is affected.
- Version 9.3(6) is affected.
- Version 9.3(5w) is affected.
- Version 9.3(7) is affected.
- Version 9.3(7k) is affected.
- Version 9.3(7a) is affected.
- Version 9.3(8) is affected.
- Version 9.3(9) is affected.
- Version 9.3(10) is affected.
- Version 10.3(1) is affected.
- Version 10.3(2) is affected.
- Version 9.3(11) is affected.
- Version 10.3(3) is affected.
- Version 9.3(12) is affected.
- Version 10.4(1) is affected.
- Version 10.3(99w) is affected.
- Version 10.3(3w) is affected.
- Version 10.3(99x) is affected.
- Version 10.3(3o) is affected.
- Version 10.3(4) is affected.
- Version 10.3(3p) is affected.
- Version 10.3(4a) is affected.
- Version 10.4(2) is affected.
- Version 10.3(3q) is affected.
- Version 9.3(13) is affected.
- Version 10.3(5) is affected.
- Version 10.4(3) is affected.
- Version 10.3(3x) is affected.
- Version 10.3(4g) is affected.
- Version 10.5(1) is affected.
- Version 10.3(3r) is affected.
- Version 10.3(6) is affected.
- Version 9.3(14) is affected.
- Version 10.4(4) is affected.
- Version 10.3(4h) is affected.
- Version 10.5(2) is affected.
- Version 10.3(7) is affected.
- Version 10.4(5) is affected.
- Version 10.5(3) is affected.
- Version 9.3(15) is affected.
- Version 10.4(4g) is affected.
- Version 10.5(4) is affected.
- Version 10.6(1) is affected.
- Version 10.5(3t) is affected.
- Version 10.3(8) is affected.
- Version 10.4(6) is affected.
- Version 10.5(3s) is affected.
- Version 10.5(3e) is affected.
- Version 10.5(3o) is affected.
- Version 9.3(16) is affected.
- Version 10.6(1s) is affected.
- Version 10.6(2) is affected.
- Version 10.5(3p) is affected.
- Version 10.3(9) is affected.
- Version 10.6(2s) is affected.
- Version 10.6(3) is affected.
- Version 10.4(7) is affected.
- Version 10.5(5) is affected.
- Version 9.3(17) is affected.
- Version 10.6(2n) is affected.
- Version 10.6(3s) is affected.