Cisco discloses three NX-OS flaws including remote code execution
Cisco disclosed three NX-OS flaws: unauthenticated NX-API remote code execution, a Python sandbox escape, and a control-plane denial of service.
Cisco disclosed three NX-OS Software vulnerabilities on 7 October 2026. Insufficient validation of data sent to the NX-API lets an unauthenticated remote attacker send a crafted HTTP request to execute arbitrary code with root privileges or crash processes and reload the device, and Cisco has released software updates. A separate Python interpreter flaw lets an authenticated local attacker with low privileges who is already allowed to run Python escape the sandbox and execute operating-system commands only with that user's existing privileges; Cisco does not report active exploitation. A third issue is improper rate limiting: an unauthenticated remote attacker can send a high rate of UDP or TCP connections to a data-plane interface, exhausting resources and temporarily disrupting routing and control-plane protocols until the flood stops and the condition clears without manual intervention. The reports do not disagree and do not publish CVE identifiers.
- On 2026-10-07 Cisco disclosed three separate NX-OS Software vulnerabilities.
- An NX-API input-validation flaw lets an unauthenticated remote attacker use a crafted HTTP request to run arbitrary code as root or crash processes and reload the device; Cisco has released software updates.
- A Python interpreter sandbox escape requires an authenticated local account already allowed to execute Python and can run operating-system commands only with that user's existing privileges.
- Cisco does not report in-the-wild exploitation of the Python sandbox escape.
- Improper rate limiting lets an unauthenticated remote attacker send a high rate of UDP or TCP connections to a data-plane interface, exhausting resources and disrupting routing and control-plane protocols.
- The control-plane denial of service causes temporary packet loss and clears without manual intervention once the traffic stops.
- None of the reports name CVE identifiers.
Coverage timelineoldest first · each row is one article
- · 1d agoCisco NX-OS Software NX-API Remote Code Execution Vulnerability
Cisco Security Advisories· 76
Unauthenticated attackers can gain root code execution on Cisco NX-OS through crafted NX-API HTTP requests.
- · 1d agoCisco NX-OS Software Python Sandbox Escape Vulnerability
Cisco Security Advisories· 52
Cisco NX-OS Python sandbox flaw lets a low-privileged authenticated user escape and run operating-system commands.
- · 1d agoCisco NX-OS Software Control Plane Denial of Service Vulnerability
Cisco Security Advisories· 50