{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-76465", "assignerOrgId": "d1c1063e-7a18-46af-9102-31f8928bc633", "state": "PUBLISHED", "assignerShortName": "cisco", "dateReserved": "2026-08-19T12:02:03.637Z", "datePublished": "2026-10-07T16:14:26.107Z", "dateUpdated": "2026-10-07T17:44:53.620Z" }, "containers": { "cna": { "title": "Cisco Nexus 3000 and 9000 Series Switches MPLS OAM Remote Code Execution Vulnerability", "metrics": [ { "format": "cvssV3_1", "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" } } ], "descriptions": [ { "lang": "en", "value": "A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device.\r\n\r\nThis vulnerability is due to improper validation when an affected device is processing an MPLS echo-request packet. An attacker could exploit this vulnerability by sending a crafted MPLS echo-request to an IP address on an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes, which could result in a device reload and a DoS condition." } ], "references": [ { "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-moam-rce-uBTzYV7", "name": "cisco-sa-moam-rce-uBTzYV7" } ], "exploits": [ { "lang": "en", "value": "The Cisco Product Security Incident Response Team (PSIRT) is not aware of any public announcements or malicious use of the vulnerability that is described in this advisory." } ], "source": { "advisory": "cisco-sa-moam-rce-uBTzYV7", "discovery": "INTERNAL", "defects": [ "CSCwu19799" ] }, "problemTypes": [ { "descriptions": [ { "lang": "en", "description": "Free of Memory not on the Heap", "type": "cwe", "cweId": "CWE-590" } ] } ], "affected": [ { "vendor": "Cisco", "product": "Cisco NX-OS Software", "versions": [ { "version": "9.3(2)", "status": "affected" }, { "version": "9.3(1)", "status": "affected" }, { "version": "9.3(1z)", "status": "affected" }, { "version": "9.3(3)", "status": "affected" }, { "version": "9.3(4)", "status": "affected" }, { "version": "9.3(5)", "status": "affected" }, { "version": "9.3(6)", "status": "affected" }, { "version": "9.3(5w)", "status": "affected" }, { "version": "9.3(7)", "status": "affected" }, { "version": "9.3(7k)", "status": "affected" }, { "version": "9.3(7a)", "status": "affected" }, { "version": "9.3(8)", "status": "affected" }, { "version": "9.3(9)", "status": "affected" }, { "version": "9.3(10)", "status": "affected" }, { "version": "10.3(1)", "status": "affected" }, { "version": "10.3(2)", "status": "affected" }, { "version": "9.3(11)", "status": "affected" }, { "version": "10.3(3)", "status": "affected" }, { "version": "9.3(12)", "status": "affected" }, { "version": "10.4(1)", "status": "affected" }, { "version": "10.3(99w)", "status": "affected" }, { "version": "10.3(3w)", "status": "affected" }, { "version": "10.3(99x)", "status": "affected" }, { "version": "10.3(3o)", "status": "affected" }, { "version": "10.3(4)", "status": "affected" }, { "version": "10.3(3p)", "status": "affected" }, { "version": "10.3(4a)", "status": "affected" }, { "version": "10.4(2)", "status": "affected" }, { "version": "10.3(3q)", "status": "affected" }, { "version": "9.3(13)", "status": "affected" }, { "version": "10.3(5)", "status": "affected" }, { "version": "10.4(3)", "status": "affected" }, { "version": "10.3(3x)", "status": "affected" }, { "version": "10.3(4g)", "status": "affected" }, { "version": "10.5(1)", "status": "affected" }, { "version": "10.3(3r)", "status": "affected" }, { "version": "10.3(6)", "status": "affected" }, { "version": "9.3(14)", "status": "affected" }, { "version": "10.4(4)", "status": "affected" }, { "version": "10.3(4h)", "status": "affected" }, { "version": "10.5(2)", "status": "affected" }, { "version": "10.3(7)", "status": "affected" }, { "version": "10.4(5)", "status": "affected" }, { "version": "10.5(3)", "status": "affected" }, { "version": "9.3(15)", "status": "affected" }, { "version": "10.4(4g)", "status": "affected" }, { "version": "10.5(4)", "status": "affected" }, { "version": "10.6(1)", "status": "affected" }, { "version": "10.5(3t)", "status": "affected" }, { "version": "10.3(8)", "status": "affected" }, { "version": "10.4(6)", "status": "affected" }, { "version": "10.5(3s)", "status": "affected" }, { "version": "10.5(3e)", "status": "affected" }, { "version": "10.5(3o)", "status": "affected" }, { "version": "9.3(16)", "status": "affected" }, { "version": "10.6(1s)", "status": "affected" }, { "version": "10.6(2)", "status": "affected" }, { "version": "10.5(3p)", "status": "affected" }, { "version": "10.3(9)", "status": "affected" }, { "version": "10.6(2s)", "status": "affected" }, { "version": "10.6(3)", "status": "affected" }, { "version": "10.4(7)", "status": "affected" }, { "version": "10.5(5)", "status": "affected" }, { "version": "9.3(17)", "status": "affected" }, { "version": "10.6(2n)", "status": "affected" }, { "version": "10.6(3s)", "status": "affected" } ], "defaultStatus": "unknown" } ], "providerMetadata": { "orgId": "d1c1063e-7a18-46af-9102-31f8928bc633", "shortName": "cisco", "dateUpdated": "2026-10-07T16:14:26.107Z" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-10-07T17:44:39.306423Z", "id": "CVE-2026-76465", "options": [ { "Exploitation": "none" }, { "Automatable": "yes" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-10-07T17:44:53.620Z" } } ] } }