Database/Firmware, BMC & network fabric
Cisco NX-OS: crafted MPLS echo-request gives unauthenticated root code execution on Nexus switches
Impact
An unauthenticated attacker who can land a packet on any IP address of the switch executes code as root on the switch itself, or crashes the process and forces a device reload. Nexus 3000/9000 are the leaf-and-spine switches carrying tenant traffic, storage traffic and often the management network of a GPU cluster, so root on one of them means the ability to mirror or redirect traffic that crosses tenant boundaries. A reload is not a cheap event either: a leaf going down takes its whole rack of GPU nodes out of the fabric, and collective operations across the cluster stall rather than degrade. Exploitation needs no credentials and no existing foothold.
Who can reach it
Anyone who can send IP packets to an address on the switch, including any tenant workload whose traffic reaches a switch SVI or loopback. No authentication required. Only devices with the MPLS OAM feature processing echo-requests are affected.
What to do
Apply the fixed NX-OS release named in the Cisco advisory; the advisory is the only source for which train fixes which platform, so check it against your running version rather than assuming. Upgrading NX-OS means reloading the switch, which drains or isolates every node behind that leaf - schedule it per rack, and do spine switches one at a time so the fabric keeps a path. If an upgrade cannot be scheduled immediately, confirm whether MPLS is needed at all on the device; the flaw is in MPLS OAM echo-request processing, so a switch with no MPLS role is a candidate for disabling the feature. Also restrict which networks can reach switch IP addresses.
References
Related entries
- Cisco NX-OS: crafted HTTP request to NX-API yields unauthenticated root code executionCVE-2026-76471 · Cisco NX-OS NX-API (HTTP request input validation)Critical
- Cisco NX-OS: crafted IP packets to a VXLAN OAM interface give unauthenticated root code executionCVE-2026-76485 · Cisco NX-OS NGOAM (VXLAN OAM packet handling)Critical
- Cisco NX-OS: crafted IP packets to an SRv6 OAM interface give unauthenticated root code executionCVE-2026-76501 · Cisco NX-OS NGOAM (SRv6 OAM packet handling)Critical
- Cisco Catalyst SD-WAN Manager: URI-encoding auth bypass gives unauthenticated admin API accessCVE-2026-76504 · Cisco Catalyst SD-WAN Manager (API session authentication, URI encoding handling)Critical
- FreeIPMI SEL parser: stack overflow on malformed Fujitsu iRMC long-text SEL responsesCVE-2026-85504 · FreeIPMI libfreeipmi SEL parser (Fujitsu iRMC OEM long-text records)Critical
- FreeIPMI ipmi-oem: stack overflow parsing Dell get-system-info responses returned by a BMCCVE-2026-85506 · FreeIPMI ipmi-oem (Dell get-system-info handlers)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.