Skip to content

CVE-2026-76471

Cisco NX-OS NX-API remote code execution lets unauthenticated attackers run commands as root (CVE-2026-76471)

Critical 9.8 Vendor: Cisco Published

Cisco NX-OS Software and Cisco Unified Computing System (Managed) are affected by a critical unauthenticated remote code execution flaw in NX-API (CVE-2026-76471). Cisco has released fixed software and a Live Protect shield; there is no workaround. Upgrade per Cisco's advisory.

What happened

A vulnerability in the NX-API feature of Cisco NX-OS Software is due to insufficient input validation of data sent to the NX-API. An unauthenticated, remote attacker can send a crafted HTTP request and execute arbitrary code with root privileges, or cause process crashes that reload the device and create a denial-of-service condition. Cisco rates the issue critical, with a CVSS v3.1 base score of 9.8; the attack requires no privileges and no user interaction.

Cisco's advisory states that the Cisco PSIRT is not aware of any public announcements or malicious use of this vulnerability.

Who is affected

Affected releases listed by Cisco are:

  • Cisco NX-OS Software: 9.2(1), 9.2(2t), 9.2(2v), 9.2(3), 9.2(3y), 9.2(4), 9.3(1), 9.3(2)
  • Cisco Unified Computing System (Managed): 4.0(1a), 4.0(4a), 4.0(4c), 4.0(4e), 4.0(4f), 4.0(4h), 4.1(1c), 4.1(1d)

The vulnerable component is the NX-API feature. Check whether NX-API is enabled and reachable from untrusted networks.

What to do now

  1. Check your inventory for the affected Cisco NX-OS Software and Cisco Unified Computing System (Managed) releases, and determine whether NX-API is enabled.
  2. Upgrade to a fixed software release. Use the Fixed Software section of Cisco's advisory to identify the train-specific release, as no fixed version numbers are listed here.
  3. Until an upgrade can be scheduled, apply the Live Protect shield Cisco has released for CVE-2026-76471. This is a temporary mitigation, not a replacement for upgrading.
  4. There are no workarounds that address this vulnerability, so restrict network access to NX-API where possible while you plan the upgrade.

How to detect it

Watch for unexpected process crashes or device reloads on affected NX-OS or UCS Managed systems, which may indicate attempted denial-of-service exploitation. Review access to NX-API for crafted or unusual HTTP requests, particularly if NX-API is reachable from untrusted networks.

Beyond the patch

Because this flaw is reachable over the network without credentials, an exposed NX-API is the kind of issue Virtual CISO Services should catch during exposure review. If an attacker does get in, root-level code execution and post-exploitation activity are what Managed Detection & Response detects through EDR and SIEM monitoring.

Affected and fixed versions

ProductAffectedFixed in
Cisco NX-OS Software9.2(3)
9.2(2v)
9.2(1)
9.2(2t)
9.2(3y)
9.3(2)
9.2(4)
9.3(1)
No fixed version listed yet
Cisco Unified Computing System (Managed)4.0(1a)
4.1(1d)
4.0(4f)
4.0(4a)
4.0(4e)
4.0(4c)
4.0(4h)
4.1(1c)
No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.