A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code with root… (CVE-2026-76471)
Description
A critical vulnerability in the NX-API feature of Cisco NX-OS Software allows an unauthenticated remote attacker to execute arbitrary code with root privileges or cause a denial of service. The flaw stems from insufficient input validation of data sent to the NX-API, which can be exploited via crafted HTTP requests. Successful exploitation may lead to process crashes and device reloads, resulting in service disruption.
CVSS v3.1
Score 9.8critical
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-76471 is a critical vulnerability in Cisco NX-OS Software's NX-API feature caused by insufficient input validation. An unauthenticated remote attacker can send crafted HTTP requests to the NX-API to execute arbitrary code with root privileges or cause a denial of service by triggering process crashes and device reloads.
Potential Impact
An attacker exploiting this vulnerability can gain root-level code execution on the affected device, compromising its integrity and confidentiality. Additionally, exploitation can cause denial of service conditions by crashing processes and forcing device reloads, disrupting network operations.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a patch or official fix is available, restrict access to the NX-API interface to trusted networks and monitor for unusual HTTP requests targeting the NX-API.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-cw8g-p542-fwjp
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-76471"]
- Database Specific Severity
- CRITICAL
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac6bff42cdf04f656829097
Added to database: 10/07/2026, 21:56:04 UTC
Last enriched: 10/07/2026, 22:08:12 UTC
Last updated: 10/08/2026, 01:48:07 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.