CISCO has fixed a critical NX-API flaw, CVE-2026-76471, that could let an unauthenticated attacker run code as root on Cisco Nexus switches. Cisco also released an NX-OS hardening release that groups six additional vulnerabilities into separate CVEs, bringing the total seven CVEs for the advisory. Notably, no exploitation has been publicly observed. The highest-severity issue is CVE-2026-76471 at CVSSv3 9.8, described as NX-API Remote Code Execution, with other hardening-class bugs rated 8.6–9.8.
The hardening release covers improper access control (CVE-2026-76455) and out-of-bounds write (CVE-2026-76459), plus four more weaknesses across improper neutralisation, input validation, out-of-bounds read and exception handling. The article emphasises that none of these have been exploited to date.
The NX-OS impact spans Nexus 3000 and 9000 in standalone mode and UCS 6300 interconnects for the NX-API flaw, while the hardening release extends to MDS 9000, Nexus 7000, Nexus 9000 in ACI mode, and UCS 6400–6600. First fixed releases for Nexus 3000/9000 standalone are 10.3(10), 10.4(8), 10.5(6) and 10.6(4); ACI mode requires 16.0(9h), 16.1(6g) or 16.2(3g); MDS 9000 needs 9.4(5a); Nexus 7000 needs 8.4(14); UCS fabric interconnects require 4.3(6j) or 6.0(2e).
Cisco advises upgrading to fixed releases and notes a temporary Live Protect shield for CVE-2026-76471 while patches are applied. No workarounds are listed.