AI analysis
CVE-2026-76455 tracks improper access control issues (CWE-284) in Cisco NX-OS that Cisco found in an internal security review and addressed in a software hardening release. Cisco's published scoring is CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), which indicates a network-reachable flaw with low complexity, no privileges, and no user interaction, and high impact to confidentiality, integrity, and availability. The provided data does not describe a specific trigger or name affected NX-OS versions or Nexus platforms. Operators of Cisco NX-OS are the population in scope until Cisco's advisory narrows the releases. There is no known public proof of concept, and the CVE is not listed in CISA's Known Exploited Vulnerabilities catalog.
What to do: Install the Cisco NX-OS software hardening release identified in Cisco's PSIRT advisory for CVE-2026-76455, and confirm the fixed image for each Nexus platform before upgrading. Until that release is applied, limit NX-OS management access to trusted networks and review access-control configuration for unexpected changes. No public exploit is known, but the published CVSS vector treats the issue as remotely reachable without authentication.
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76455 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.