Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-76455: Cisco NX-OS could allow unauthorized configuration changes

CVE-2026-76455 · published 4 days ago
Summary

The Cisco NX‑OS operating system and the Unified Computing System that runs it may let users without proper permission modify device settings. This could let an attacker alter network behavior or gain further access. Install the October 2026 security hardening update as soon as possible to close the gap.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
cisco cisco nx-os software 8.2(5)
cisco cisco nx-os system software in aci mode 15.2(1g)
cisco cisco unified computing system (managed) 4.0(1a)
Original advisory text
Cisco NX-OS Software Security Hardening Release: October 2026 - Improper Access Control Vulnerabilities
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-76455 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-284Improper Access Control
Timeline
Published7 Oct 2026
Updated8 Oct 2026
First seen7 Oct 2026
Sources
CVE-2026-76455 · MITRE
Track software like this
Free during beta