Skip to content

CVE-2026-76465

Cisco Nexus 3000 and 9000 Series Switches MPLS OAM remote code execution (CVE-2026-76465)

Critical 9.8 Vendor: Cisco Published

Critical MPLS OAM flaw in Cisco NX-OS on Nexus 3000 and 9000 switches lets an unauthenticated remote attacker execute code with root privileges or reload the device. Cisco has released fixes; disable MPLS OAM if unused.

What happened

CVE-2026-76465 is a critical remote code execution vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software on Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches. It is caused by improper validation when an affected device processes an MPLS echo-request packet.

An unauthenticated, remote attacker can exploit the issue by sending a crafted MPLS echo-request to an IP address on an affected device. A successful exploit can execute arbitrary code with root privileges and can cause process crashes, which could result in a device reload and a denial of service. Cisco rates the vulnerability critical, with a CVSS 3.1 score of 9.8, and describes the access as network-based, low complexity, with no privileges or user interaction required.

Cisco PSIRT is not aware of any public announcements or malicious use of the vulnerability described in this advisory.

Who is affected

The affected software is Cisco NX-OS Software on Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches. Cisco lists affected NX-OS versions 9.3(1), 9.3(1z), 9.3(2), 9.3(3), 9.3(4), 9.3(5), 9.3(5w) and 9.3(6). The attack vector is present when the MPLS OAM feature is enabled; Cisco states that disabling the MPLS OAM feature removes the attack vector.

What to do now

  1. Apply Cisco's fix. Cisco states that fixes are available; use Cisco's advisory cisco-sa-moam-rce-uBTzYV7 to identify the fixed NX-OS release for your hardware and install it as a priority.
  2. If MPLS OAM is not required in your environment, disable it in global configuration mode with no feature mpls oam. Cisco notes there are no workarounds that address the vulnerability itself, that this mitigation has been tested successfully in a test environment, and that you should evaluate applicability and impact in your own environment before deploying it.
  3. Maintain a current list of Nexus 3000 and 9000 Series Switches with MPLS OAM enabled, and prioritise patching devices where the feature must remain in use.

How to detect it

Monitor affected Nexus 3000 and 9000 Series Switches with MPLS OAM enabled for unexpected process crashes or device reloads; Cisco describes these as possible outcomes of successful denial-of-service exploitation. Keep an inventory of devices with MPLS OAM enabled so the affected population is known and can be patched or mitigated without delay.

Beyond the patch

A vulnerability reachable over the network without credentials is an exposure problem before it is a patching problem. Virtual CISO Services can help you identify and track Nexus 3000 and 9000 devices with MPLS OAM exposed, and Managed Detection & Response can detect root-level code execution or post-exploitation activity if a device is compromised. Keeping Cisco's patch cycle visible across your installed base is also part of Supply Chain Defense & Third-Party Risk.

Affected and fixed versions

ProductAffectedFixed in
Cisco NX-OS Software9.3(2)
9.3(1)
9.3(1z)
9.3(3)
9.3(4)
9.3(5)
9.3(6)
9.3(5w)
No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.