Back Forkast.News Cisco NX-API Carries an Unauthenticated Root RCE, and It Stays Off Until Automation Turns It On
CVE-2026-76471 allows an unauthenticated, remote attacker to send a crafted HTTP request to the NX-API of an affected device to execute arbitrary code with root privileges, provided the feature is enabled. The bug, detailed in the official Cisco advisory published October 7, is a heap buffer overflow (CWE-122) carrying a CVSS base score of 9.8. It is tracked as CSCwu46199 for the Nexus 3000 and 9000 lines and CSCwu58579 for UCS 6300. The same bug can trigger process crashes that force a device reload and a denial of service.
For Cisco Nexus 3000 and 9000 Series switches, the NX-API feature is disabled by default. It stays off until automation workflows or programmable management requirements turn it on. Operators can check which side of that line their own fleet sits on with one command: show feature | include nxapi in the NX-OS CLI.
The threat model differs for the UCS 6300 Series Fabric Interconnects. There the vulnerability lives in the Cisco UCS Manager XML API, which is enabled by default and cannot be disabled without loss of functionality. Exploitation on the UCS 6300 requires valid low-privileged user credentials, and because of that authentication requirement the Security Impact Rating is reduced to High rather than the Critical rating carried on the Nexus switches. One CVE, two platforms, two different gates.
Cisco’s position on mitigation is flat: “There are no workarounds that address this vulnerability.” A Live Protect shield ships for CVE-2026-76471 as a temporary bridge only, good until software updates can be scheduled. The fix is an upgrade.
The path to that fix is not uniform. For NX-OS the advisory prints no version strings at all; it routes operators to the Cisco Software Checker for the first fixed release per platform and version. For the UCS 6300 line it is explicit: release 4.2 and earlier must migrate to a fixed release, and 4.3(6j) is the first fixed release on the 4.3 branch. Revision 1.1 of the advisory, published October 8, updated the fixed release table, so the fix map has already moved once.
CVE-2026-76471 is a management-plane bug, distinct from the S1HAL forwarding-plane RCE and the NGOAM monitoring-plane bugs in the same October 7 disclosure cycle, which our four-advisory synthesis covered as a set of six CVEs across four planes of one OS. The October 2026 NX-OS Security Hardening Release is Cisco’s broader fix vehicle for the cycle, but it does not replace the targeted upgrade for CVE-2026-76471. Cisco PSIRT reports no public announcements or malicious use of the vulnerability and says it was found during internal security testing.
The gate here is a feature flag, and automation is what flips it. The audit is one command. The fix is an upgrade, with the NX-OS version strings behind a lookup tool and the UCS 6300 branch pinned to 4.3(6j). That is the whole posture: the safe default and the working network are the same decision.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
