{"id":"CVE-2026-76471","title":"A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device.&nbsp;\r\n\r\nThe…","summary":"A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device.&nbsp;\r\n\r\nThe…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-122"],"vendor":"Cisco","product":"Cisco NX-OS Software","affected":["nx-os_software 9.2(3)","nx-os_software 9.2(2v)","nx-os_software 9.2(1)","nx-os_software 9.2(2t)","nx-os_software 9.2(3y)","nx-os_software 9.3(2)","nx-os_software 9.2(4)","nx-os_software 9.3(1)","nx-os_software 9.3(1z)","nx-os_software 9.2(2)","nx-os_software 9.3(3)","nx-os_software 9.3(4)","nx-os_software 9.3(5)","nx-os_software 9.3(6)","nx-os_software 9.3(5w)","nx-os_software 9.3(7)","nx-os_software 9.3(7k)","nx-os_software 9.3(7a)","nx-os_software 9.3(8)","nx-os_software 9.3(9)","nx-os_software 9.3(10)","nx-os_software 10.3(1)","nx-os_software 10.3(2)","nx-os_software 9.3(11)","nx-os_software 10.3(3)","nx-os_software 9.3(12)","nx-os_software 10.4(1)","nx-os_software 10.3(99w)","nx-os_software 10.3(3w)","nx-os_software 10.3(99x)","nx-os_software 10.3(3o)","nx-os_software 10.3(4)","nx-os_software 10.3(3p)","nx-os_software 10.3(4a)","nx-os_software 10.4(2)","nx-os_software 10.3(3q)","nx-os_software 9.3(13)","nx-os_software 10.3(5)","nx-os_software 10.4(3)","nx-os_software 10.3(3x)","nx-os_software 10.3(4g)","nx-os_software 10.5(1)","nx-os_software 10.3(3r)","nx-os_software 10.3(6)","nx-os_software 9.3(14)","nx-os_software 10.4(4)","nx-os_software 10.3(4h)","nx-os_software 10.5(2)","nx-os_software 10.3(7)","nx-os_software 10.4(5)"],"published":"2026-10-07","updated":"2026-10-07","sourceUpdated":"2026-10-07T18:17:30.003","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-76471","references":[{"url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-napi-rce-r2shwu2j","label":"psirt@cisco.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"total","timestamp":"2026-10-07T17:46:00.325745Z"},"ingestedAt":"2026-10-07T16:38:22.248Z","slug":"CVE-2026-76471","body":"## Overview\n\nA vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device.&nbsp;\r\n\r\nThe vulnerability is due to insufficient input validation of data that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP request to the NX-API of an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes, which could result in a reload of the device and a DoS condition.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}