Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-76471: Cisco NX-OS NX-API can let remote attacker run code
CVE-2026-76471 · published 4 days ago
Summary
The NX-API function in Cisco NX-OS (including managed UCS systems) does not check incoming data properly, so a stranger on the network could send a specially crafted web request and gain full control of the device or cause it to crash. This could let the attacker take over the switch or make it unavailable. Install the latest Cisco software updates and limit network access to the NX-API interface to trusted hosts.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| cisco | cisco nx-os software | 9.2(3) |
| cisco | cisco unified computing system (managed) | 4.0(1a) |
Original advisory text
Cisco NX-OS Software NX-API Remote Code Execution Vulnerability
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device.
The vulnerability is due to insufficient input validation of data that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP request to the NX-API of an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes, which could result in a reload of the device and a DoS condition.
The vulnerability is due to insufficient input validation of data that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP request to the NX-API of an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes, which could result in a reload of the device and a DoS condition.
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-122Heap-based Buffer Overflow
Timeline
Published7 Oct 2026
Updated8 Oct 2026
First seen7 Oct 2026
Track software like this
Free during beta