Skip to content
Critical RCE Vulnerability in Cisco NX-API Disclosed

Critical RCE Vulnerability in Cisco NX-API Disclosed

First seen 9 Oct 2026, 17:38 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 9, 2026 at 18:40 UTC

Cisco disclosed a critical vulnerability (CVE-2026-76471) in its NX-API, allowing unauthenticated remote code execution on Nexus 3000 and 9000 Series switches, with a CVSS score of 9.8. The vulnerability is a heap buffer overflow that can also lead to denial of service. On UCS 6300 Series Fabric Interconnects, exploitation requires low-privileged user credentials, reducing the severity to High. The NX-API feature is disabled by default on Nexus switches, but enabled by default on UCS 6300, increasing risk for those systems. Cisco advises that there are no workarounds and recommends upgrading to fixed releases. The vulnerability was found during internal security testing, and there have been no reports of public exploitation. The advisory was published on October 7, 2026, and the fix is not uniform across platforms.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-07
CVE-2026-76471 published
Cisco disclosed a critical vulnerability in NX-API affecting multiple series of switches and Fabric Interconnects.
Forkast.News
2026-10-08
Advisory revision 1.1 released
Cisco updated the advisory with a fixed release table for affected systems, indicating changes in the patching timeline.
Forkast.News

More articles in this cluster (2)

Following this threat?

Track CVE-2026-76471 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which devices are affected by CVE-2026-76471?
The vulnerability affects Cisco Nexus 3000 and 9000 Series switches and UCS 6300 Series Fabric Interconnects.
What is the recommended action for affected systems?
Cisco recommends upgrading to the fixed releases as there are no workarounds for this vulnerability.
Is there any evidence of exploitation in the wild?
Cisco has reported no public announcements or malicious use of the vulnerability.