Cisco NX-OS Python Sandbox Escape Vulnerability Disclosed
Article Content
- •CVE-2026-20032 allows local attackers to escape Python sandbox in Cisco NX-OS.
- •Cisco has released patches; no workarounds are available for this vulnerability.
- •Affected systems include Cisco Nexus 9000 Series devices running vulnerable NX-OS versions.
A vulnerability identified as CVE-2026-20032 affects the Python interpreter in Cisco NX-OS Software, allowing authenticated local attackers with low privileges to escape the Python sandbox and gain unauthorized access to the underlying operating system. This flaw arises from insufficient validation of user-supplied input, enabling attackers to manipulate specific functions within the interpreter. Cisco has released software updates to address this vulnerability, but no workarounds are available. The vulnerability impacts devices running affected versions of Cisco NX-OS Software, specifically within the Cisco Nexus 9000 Series. The advisory was published on October 7, 2026, and is part of a broader set of advisories from Cisco. Security professionals are urged to review the advisory and apply the necessary updates.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-20032 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which devices are affected?
What is the nature of the vulnerability?
What should I do to protect my systems?
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…