CVE-2026-76465
CVE-2026-76465 is a critical-severity vulnerability with a CVSS 3.x base score of 9.8. The underlying weakness is classified as CWE-590.
Key facts
- Severity: Critical (CVSS 3.x base score 9.8)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-590
- Published:
- Last modified:
Description
A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper validation when an affected device is processing an MPLS echo-request packet. An attacker could exploit this vulnerability by sending a crafted MPLS echo-request to an IP address on an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes, which could result in a device reload and a DoS condition.
Frequently asked questions
- What is CVE-2026-76465?
- A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper validation when an affected device is processing an MPLS echo-request packet. An attacker could exploit this vulnerability by sending a crafted MPLS echo-request to an IP address on an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes, which could result in a device reload and a DoS condition.
- How severe is CVE-2026-76465?
- CVE-2026-76465 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2026-76465 being actively exploited?
- It is not currently listed in CISA's Known Exploited Vulnerabilities catalog, and no EPSS exploit-prediction score is available yet.
- How do I fix CVE-2026-76465?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its critical severity, prioritise patching exposed systems.
- When was CVE-2026-76465 published?
- CVE-2026-76465 was published on 2026-10-07.
References
Other CWE-590 vulnerabilities
- CVE-2026-95311 — Critical (CVSS 9.6): Free of non-heap memory in Fonts in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social…
- CVE-2025-32911 — Critical (CVSS 9.0): A use-after-free type vulnerability was found in libsoup, in the soup_message_headers_get_content_disposition()…
- CVE-2026-20810 — High (CVSS 7.8): Free of memory not on the heap in Windows Ancillary Function Driver for WinSock allows an authorized attacker to…
- CVE-2025-54899 — High (CVSS 7.8): Free of memory not on the heap in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2025-42995 — High (CVSS 7.5): SAP MDM Server Read function allows an attacker to send specially crafted packets which could trigger a memory read…
- CVE-2025-42994 — High (CVSS 7.5): SAP MDM Server ReadString function allows an attacker to send specially crafted packets which could trigger a memory…