---
id: CVE-2026-76465
title: >-
  A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM)
  feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco
  Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to
  exe…
summary: >-
  A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM)
  feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco
  Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to
  exe…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-590
vendor: Cisco
product: Cisco NX-OS Software
affected:
  - nx-os_software 9.3(2)
  - nx-os_software 9.3(1)
  - nx-os_software 9.3(1z)
  - nx-os_software 9.3(3)
  - nx-os_software 9.3(4)
  - nx-os_software 9.3(5)
  - nx-os_software 9.3(6)
  - nx-os_software 9.3(5w)
  - nx-os_software 9.3(7)
  - nx-os_software 9.3(7k)
  - nx-os_software 9.3(7a)
  - nx-os_software 9.3(8)
  - nx-os_software 9.3(9)
  - nx-os_software 9.3(10)
  - nx-os_software 10.3(1)
  - nx-os_software 10.3(2)
  - nx-os_software 9.3(11)
  - nx-os_software 10.3(3)
  - nx-os_software 9.3(12)
  - nx-os_software 10.4(1)
  - nx-os_software 10.3(99w)
  - nx-os_software 10.3(3w)
  - nx-os_software 10.3(99x)
  - nx-os_software 10.3(3o)
  - nx-os_software 10.3(4)
  - nx-os_software 10.3(3p)
  - nx-os_software 10.3(4a)
  - nx-os_software 10.4(2)
  - nx-os_software 10.3(3q)
  - nx-os_software 9.3(13)
  - nx-os_software 10.3(5)
  - nx-os_software 10.4(3)
  - nx-os_software 10.3(3x)
  - nx-os_software 10.3(4g)
  - nx-os_software 10.5(1)
  - nx-os_software 10.3(3r)
  - nx-os_software 10.3(6)
  - nx-os_software 9.3(14)
  - nx-os_software 10.4(4)
  - nx-os_software 10.3(4h)
  - nx-os_software 10.5(2)
  - nx-os_software 10.3(7)
  - nx-os_software 10.4(5)
  - nx-os_software 10.5(3)
  - nx-os_software 9.3(15)
  - nx-os_software 10.4(4g)
  - nx-os_software 10.5(4)
  - nx-os_software 10.6(1)
  - nx-os_software 10.5(3t)
  - nx-os_software 10.3(8)
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T18:17:28.580'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76465'
references:
  - url: >-
      https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-moam-rce-uBTzYV7
    label: psirt@cisco.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-10-07T17:44:39.306423Z'
ingestedAt: '2026-10-07T16:38:22.251Z'
---

## Overview

A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute arbitrary code with&nbsp;root privileges or cause a denial of service (DoS) condition on an affected device.

This vulnerability is due to improper validation when an affected device is processing an MPLS echo-request packet. An attacker could exploit this vulnerability by sending a crafted MPLS echo-request to an IP address on an affected device. A successful exploit could allow the attacker to execute arbitrary code with&nbsp;root privileges and could cause process crashes, which could result in a device reload and a DoS condition.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
