AI analysis
Cisco NX-OS Software has a critical flaw (CVE-2026-76471, CWE-122 heap-based buffer overflow) in the NX-API feature caused by insufficient validation of data sent to that API. An unauthenticated remote attacker can trigger it by sending a crafted HTTP request to NX-API on an affected device, with no user interaction required (CVSS 3.1 9.8). A successful exploit can run arbitrary code with root privileges or crash processes, which can reload the device and cause a denial of service. It affects Cisco NX-OS devices on which NX-API is present and reachable; exact version ranges were not stated in the supplied data. There is no known public proof of concept and the CVE is not in CISA KEV, so exploitation is not known to be occurring in the wild.
What to do: Treat NX-API as a privileged management interface: disable it if it is not required, and if it is required, restrict it with ACLs, a management VRF, or out-of-band management so it is not reachable from untrusted networks. Apply Cisco’s fix for CVE-2026-76471 for your NX-OS platform as soon as fixed releases are published, and investigate unexpected NX-API process crashes or device reloads.
Affected
| Cisco NX-OS Software (NX-API feature) | Specific affected and fixed release ranges were not included in the advisory data; devices where the NX-API feature is present and reachable |
Estimated exposure
largeOn the order of 10,000–100,000 NX-OS devices with NX-API potentially enabled (mostly internal management networks; internet-exposed subset likely much smaller) — Order-of-magnitude estimate from Cisco Nexus/NX-OS use in enterprise data centers and common optional enablement of NX-API for automation; the advisory gives no install counts or scan totals, and NX-API is often limited to management…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation of data that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP request to the NX-API of an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes, which could result in a reload of the device and a DoS condition.