CVE-2026-76465
Nexus: Free of Memory not on the Heap (CVE-2026-76465)
Description
A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper validation when an affected device is processing an MPLS echo-request packet. An attacker could exploit this vulnerability by sending a crafted MPLS echo-request to an IP address on an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes, which could result in a device reload and a DoS condition.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
3000 Series Switches9000 Series Switches9000 Series Fabric Switches <16.0(9h)9000 Series Fabric Switches <16.1(6g)9000 Series Fabric Switches <16.2(3g)9108 100G Fabric Interconnects <4.3(6.260049)9108 100G Fabric Interconnects <4.3(6.260059)9108 100G Fabric Interconnects <4.3(6j)9108 100G Fabric Interconnects <6.0(2.260080)9108 100G Fabric Interconnects <6.0(2e)MDS 9000 Series Multilayer Switches <9.4(5a)Nexus 3000 Series Switches <10.3(10)Nexus 3000 Series Switches <10.4(8)Nexus 3000 Series Switches <10.5(6)Nexus 3000 Series Switches <10.6(4)Nexus 7000 Series Switches <8.4(14)Nexus 9000 Series Fabric Switches <16.0(9h)Nexus 9000 Series Fabric Switches <16.1(6g)Nexus 9000 Series Fabric Switches <16.2(3g)Nexus 9000 Series Switches <10.3(10)Nexus 9000 Series Switches <10.4(8)Nexus 9000 Series Switches <10.5(6)Nexus 9000 Series Switches <10.6(4)UCS 6300, 6400, 6500, and 6600 Series <4.3(6.260049)UCS 6300, 6400, 6500, and 6600 Series <4.3(6.260059)UCS 6300, 6400, 6500, and 6600 Series <4.3(6j)UCS 6300, 6400, 6500, and 6600 Series <6.0(2.260080)UCS 6300, 6400, 6500, and 6600 Series <6.0(2e)UCS 6300 Series Fabric Interconnect <4.3(6.260049)UCS 6300 Series Fabric Interconnect <4.3(6j)Metrics
Show all metrics
Weakness classes (CWE)
CWE-590Variant
Free of Memory not on the Heap
The product calls free() on a pointer to memory that was not allocated using associated heap allocation functions such as malloc(), calloc(), or realloc().
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-10-08 04:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-76465","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
- SSVC: {"id":"CVE-2026-76465","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
- CVE Modified2026-10-07 18:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-76465","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
- New CVE Received2026-10-07 17:16 UTC· psirt@cisco.com
- Description: A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper validation when an affected device is processing an MPLS echo-request packet. An attacker could exploit this vulnerability by sending a crafted MPLS echo-request to an IP address on an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes, which could result in a device reload and a DoS condition.
- CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- CWE: CWE-590
- Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/76xxx/CVE-2026-76465.json">CVE-2026-76465</a>