---
id: CVE-2026-76471
title: "A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device.&nbsp;\r\n\r\nThe…"
summary: "A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device.&nbsp;\r\n\r\nThe…"
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-122
vendor: Cisco
product: Cisco NX-OS Software
affected:
  - nx-os_software 9.2(3)
  - nx-os_software 9.2(2v)
  - nx-os_software 9.2(1)
  - nx-os_software 9.2(2t)
  - nx-os_software 9.2(3y)
  - nx-os_software 9.3(2)
  - nx-os_software 9.2(4)
  - nx-os_software 9.3(1)
  - nx-os_software 9.3(1z)
  - nx-os_software 9.2(2)
  - nx-os_software 9.3(3)
  - nx-os_software 9.3(4)
  - nx-os_software 9.3(5)
  - nx-os_software 9.3(6)
  - nx-os_software 9.3(5w)
  - nx-os_software 9.3(7)
  - nx-os_software 9.3(7k)
  - nx-os_software 9.3(7a)
  - nx-os_software 9.3(8)
  - nx-os_software 9.3(9)
  - nx-os_software 9.3(10)
  - nx-os_software 10.3(1)
  - nx-os_software 10.3(2)
  - nx-os_software 9.3(11)
  - nx-os_software 10.3(3)
  - nx-os_software 9.3(12)
  - nx-os_software 10.4(1)
  - nx-os_software 10.3(99w)
  - nx-os_software 10.3(3w)
  - nx-os_software 10.3(99x)
  - nx-os_software 10.3(3o)
  - nx-os_software 10.3(4)
  - nx-os_software 10.3(3p)
  - nx-os_software 10.3(4a)
  - nx-os_software 10.4(2)
  - nx-os_software 10.3(3q)
  - nx-os_software 9.3(13)
  - nx-os_software 10.3(5)
  - nx-os_software 10.4(3)
  - nx-os_software 10.3(3x)
  - nx-os_software 10.3(4g)
  - nx-os_software 10.5(1)
  - nx-os_software 10.3(3r)
  - nx-os_software 10.3(6)
  - nx-os_software 9.3(14)
  - nx-os_software 10.4(4)
  - nx-os_software 10.3(4h)
  - nx-os_software 10.5(2)
  - nx-os_software 10.3(7)
  - nx-os_software 10.4(5)
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T18:17:30.003'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-76471'
references:
  - url: >-
      https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-napi-rce-r2shwu2j
    label: psirt@cisco.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-10-07T17:46:00.325745Z'
ingestedAt: '2026-10-07T16:38:22.248Z'
---

## Overview

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device.&nbsp;

The vulnerability is due to insufficient input validation of data that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP request to the NX-API of an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes, which could result in a reload of the device and a DoS condition.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
