Threat Advisory

Cisco NX-API Flaw Lets Attackers Execute Arbitrary Code with Root Privileges

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-76471 with a CVSS score of 9.8 is a vulnerability in the NX-API feature of Cisco NX-OS Software that could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial-of-service condition on an affected device due to insufficient input validation of data sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP request to the NX-API of an affected device, resulting in process crashes and potentially leading to a reload of the device and a denial-of-service condition. This vulnerability affects Cisco Nexus 3000 Series Switches, Nexus 9000 Series Switches in standalone NX-OS mode, and UCS 6300 Series Fabric Interconnects if they are running a vulnerable release of Cisco NX-OS Software and have the NX-API feature enabled; however, the NX-API feature is disabled by default for Cisco Nexus 3000 and 9000 Series Switches, and exploitation of the vulnerability requires valid low-privileged user credentials for Cisco UCS 6300 Series Fabric Interconnects. The business impact of this vulnerability includes potential loss of confidentiality, integrity, and availability of sensitive data stored on affected devices.

RECOMMENDATION:

We recommend you to update Cisco NX-OS Software to given version link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-napi-rce-r2shwu2j?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20NX-OS%20Software%20NX-API%20Remote%20Code%20Execution%20Vulnerability%26vs_k=1[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-76471 with a CVSS score of 9.8 is a vulnerability in the NX-API feature of Cisco NX-OS Software that could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial-of-service condition on an affected device due to insufficient input validation of data sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP request to the NX-API of an affected device, resulting in process crashes and potentially leading to a reload of the device and a denial-of-service condition. This vulnerability affects Cisco Nexus 3000 Series Switches, Nexus 9000 Series Switches in standalone NX-OS mode, and UCS 6300 Series Fabric Interconnects if they are running a vulnerable release of Cisco NX-OS Software and have the NX-API feature enabled; however, the NX-API feature is disabled by default for Cisco Nexus 3000 and 9000 Series Switches, and exploitation of the vulnerability requires valid low-privileged user credentials for Cisco UCS 6300 Series Fabric Interconnects. The business impact of this vulnerability includes potential loss of confidentiality, integrity, and availability of sensitive data stored on affected devices.

RECOMMENDATION:

We recommend you to update Cisco NX-OS Software to given version link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-napi-rce-r2shwu2j?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20NX-OS%20Software%20NX-API%20Remote%20Code%20Execution%20Vulnerability%26vs_k=1[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu