CVE-2026-76455 CVE-2026-76453 CVE-2026-76459 CVE-2026-76456 CVE-2026-76457 CVE-2026-76458
Cisco NX-OS October 2026 hardening release fixes improper access control and other flaws
Cisco's October 2026 NX-OS hardening release fixes multiple internally found flaws, including a critical improper access control issue rated 9.8. No workarounds exist. Apply the hardening release for NX-OS, ACI mode and UCS Managed.
What happened
Cisco's NX-OS engineering team ran an internal security review and produced the October 2026 security hardening release. CVE-2026-76455 is an improper access control issue rated Critical with a CVSS score of 9.8. It is reachable over the network with low attack complexity, requires no privileges and no user interaction, and can compromise confidentiality, integrity and availability of the affected device.
The same release addresses five further vulnerabilities. CVE-2026-76453 and CVE-2026-76459 are improper neutralization and out-of-bounds write issues respectively. Both have a CVSS score of 8.8, are reachable over the network and require low privileges. CVE-2026-76456, CVE-2026-76457 and CVE-2026-76458 are an improper input validation, an out-of-bounds read and an improper handling of exceptional conditions. Each has a CVSS score of 8.6, requires no privileges, and can cause a high availability impact.
Cisco PSIRT says it is not aware of any public announcements or malicious use of these vulnerabilities. They were internally discovered and not publicly disclosed before the advisory.
Who is affected
Cisco lists affected builds for three product lines. For Cisco NX-OS Software, the affected builds are 8.2(5), 7.3(5)D1(1), 8.4(2), 8.4(3), 9.2(3), 8.2(1), 7.3(1)D1(1) and 9.2(2v). For Cisco NX-OS System Software in ACI Mode, affected builds are 15.2(1g), 15.2(2e), 15.2(2f), 15.2(2g), 15.2(2h), 15.2(3f), 15.2(3e) and 15.2(3g). For Cisco Unified Computing System (Managed), the affected builds are in the 4.0 and 4.1 families; CVE-2026-76456 has a slightly different UCS build list, so check that entry against your installed version. These are data centre switches, ACI fabrics and UCS management platforms.
What to do now
- Apply Cisco's October 2026 NX-OS security hardening release. Cisco states fixes are available, but has not listed specific fixed release numbers in its advisory; use Cisco's advisory to map your product train and platform to the correct fixed release.
- Do not wait for a workaround. Cisco states there are no workarounds that address these vulnerabilities.
- Restrict access to NX-OS, ACI and UCS management interfaces to trusted management networks while you schedule and complete patching.
- After patching, verify the release on each affected device and re-check the CVE entries against your asset inventory, since one CVE lists a different UCS build set.
How to detect it
Cisco's advisory does not publish indicators of compromise for these internally discovered vulnerabilities. Until the hardening release is applied, monitor NX-OS, ACI and UCS management interfaces for unexpected configuration changes, new administrative accounts or unplanned reloads.
Beyond the patch
With no workaround available, your exposure ends only when the hardening release is applied. Supply Chain Defense & Third-Party Risk can give you visibility into Cisco's patch cycle and your own window of exposure across the network estate, while Virtual CISO Services (vCISO) helps you control reachable management interfaces and sequence data centre patching.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| CVE-2026-76455, CVE-2026-76453, CVE-2026-76459, CVE-2026-76456, CVE-2026-76457, CVE-2026-76458 Cisco NX-OS Software | 8.2(5) 7.3(5)D1(1) 8.4(2) 8.4(3) 9.2(3) 8.2(1) 7.3(1)D1(1) 9.2(2v) | No fixed version listed yet |
| CVE-2026-76455, CVE-2026-76453, CVE-2026-76459, CVE-2026-76456, CVE-2026-76457, CVE-2026-76458 Cisco NX-OS System Software in ACI Mode | 15.2(1g) 15.2(2e) 15.2(2f) 15.2(2g) 15.2(2h) 15.2(3f) 15.2(3e) 15.2(3g) | No fixed version listed yet |
| CVE-2026-76455, CVE-2026-76453, CVE-2026-76459, CVE-2026-76457, CVE-2026-76458 Cisco Unified Computing System (Managed) | 4.0(1a) 4.1(1d) 4.0(4f) 4.0(4c) 4.0(2b) 4.1(2a) 4.0(4a) 4.0(4e) | No fixed version listed yet |
| CVE-2026-76456 Cisco Unified Computing System (Managed) | 4.0(1a) 4.1(1a) 4.1(1b) 4.0(4h) 4.1(1c) 4.0(4e) 4.0(4g) 4.0(2e) | No fixed version listed yet |
References
CVE
- CVE-2026-76455 — cve.org
- CVE-2026-76455 — NVD
- EUVD-2026-94460 — ENISA EUVD
- CVE-2026-76453 — cve.org
- CVE-2026-76453 — NVD
- EUVD-2026-94453 — ENISA EUVD
- CVE-2026-76459 — cve.org
- CVE-2026-76459 — NVD
- EUVD-2026-94462 — ENISA EUVD
- CVE-2026-76456 — cve.org
- CVE-2026-76456 — NVD
- EUVD-2026-94458 — ENISA EUVD
- CVE-2026-76457 — cve.org
- CVE-2026-76457 — NVD
- EUVD-2026-94459 — ENISA EUVD
- CVE-2026-76458 — cve.org
- CVE-2026-76458 — NVD
- EUVD-2026-94463 — ENISA EUVD