TL;DR
Cisco has fixed a critical NX-API flaw, CVE-2026-76471, that could let an unauthenticated attacker run code as root on Nexus switches. Alongside it, Cisco shipped a hardening release that groups many other Cisco NX-OS vulnerabilities under six CVE IDs. Cisco reports no exploitation of any of these bugs.
- Total: 7 CVEs
- Severity: 2 Critical Β· 5 High
- Actively exploited: None confirmed
- Highest severity: 9.8 (Critical Β· CVSSv3) β CVE-2026-76471
- Action: Apply the latest security updates now
Turn Cisco CVEs into GitHub Issues automatically β no copy-pasting, no duplicates.
Try Team free for 14 daysNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-76471 | 9.8 | NX-API Remote Code Execution | Not exploited |
| CVE-2026-76455 | 9.8 | Security Hardening Release: October 2026 - Improper Access Control | Not exploited |
| CVE-2026-76459 | 8.8 | Security Hardening Release: October 2026 - Out-of-bounds Write | Not exploited |
| CVE-2026-76453 | 8.8 | Security Hardening Release: October 2026 - Improper Neutralization | Not exploited |
| CVE-2026-76456 | 8.6 | Security Hardening Release: October 2026 - Improper Input Validation | Not exploited |
| CVE-2026-76457 | 8.6 | Security Hardening Release: October 2026 - Out-of-bounds Read | Not exploited |
| CVE-2026-76458 | 8.6 | Security Hardening Release: October 2026 - Improper Handling of Exceptional Conditions | Not exploited |
Why It Matters
NX-OS runs Cisco’s Nexus data center switches, MDS storage switches and UCS fabric interconnects. Root access on these devices could expose or disrupt an entire data center fabric. Notably, the hardening release applies “regardless of device configuration.”
Cisco found all of these issues internally. The hardening advisory says testing used “existing testing processes as well as frontier AI models.” The PSIRT “is not aware of any public announcements or malicious use” of these flaws.
How the Attacks Work
NX-API Code Execution (CVE-2026-76471)
This bug scores 9.8 on CVSS. According to the NX-API advisory, it stems from “insufficient input validation of data that is sent to the NX-API.” An attacker sends a crafted HTTP request to the API. Success could mean root-level code execution or a device reload.
NX-API is off by default on Nexus 3000 and 9000 switches. However, UCS 6300 fabric interconnects expose the flaw through the UCS Manager XML API, which is on by default. There, an attacker needs low-privileged credentials, so Cisco rates it High rather than Critical.
Hardening Release
The October 2026 hardening release groups bugs by weakness class. Two classes rate 9.8: improper access control (CVE-2026-76455) and out-of-bounds write (CVE-2026-76459). The others cover injection, input validation, out-of-bounds read and exception handling, scored 8.6 to 8.8.
Affected Versions
The NX-API flaw affects Nexus 3000, Nexus 9000 in standalone mode and UCS 6300 interconnects. The hardening release reaches further, adding MDS 9000, Nexus 7000, Nexus 9000 in ACI mode and UCS 6400 through 6600.
First fixed releases for Nexus 3000 and 9000 standalone are 10.3(10), 10.4(8), 10.5(6) and 10.6(4). ACI mode needs 16.0(9h), 16.1(6g) or 16.2(3g). MDS 9000 needs 9.4(5a), and Nexus 7000 needs 8.4(14). UCS fabric interconnects need 4.3(6j) or 6.0(2e) in UCS Manager mode, with matching Intersight builds. Older trains with these Cisco NX-OS vulnerabilities must migrate to a fixed release.
Patch and Mitigation Steps
Upgrade to a fixed release, since Cisco lists no workarounds for these Cisco NX-OS vulnerabilities. Run “show feature | include nxapi” to see whether NX-API is enabled. If it is, Cisco offers a temporary Live Protect shield for CVE-2026-76471 until you can patch.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!