Forkast.News Critical RCE Vulnerability in Cisco NX-API Disclosed
Article Content
- •CVE-2026-76471 allows unauthenticated RCE on Cisco NX-API with a CVSS score of 9.8.
- •The vulnerability affects Nexus 3000 and 9000 Series switches and UCS 6300 Series Fabric Interconnects.
- •Cisco recommends immediate upgrades as there are no workarounds for this vulnerability.
Cisco disclosed a critical vulnerability (CVE-2026-76471) in its NX-API, allowing unauthenticated remote code execution on Nexus 3000 and 9000 Series switches, with a CVSS score of 9.8. The vulnerability is a heap buffer overflow that can also lead to denial of service. On UCS 6300 Series Fabric Interconnects, exploitation requires low-privileged user credentials, reducing the severity to High. The NX-API feature is disabled by default on Nexus switches, but enabled by default on UCS 6300, increasing risk for those systems. Cisco advises that there are no workarounds and recommends upgrading to fixed releases. The vulnerability was found during internal security testing, and there have been no reports of public exploitation. The advisory was published on October 7, 2026, and the fix is not uniform across platforms.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-76471 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which devices are affected by CVE-2026-76471?
What is the recommended action for affected systems?
Is there any evidence of exploitation in the wild?
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…