Cisco patches critical NX-API RCE CVE-2026-76471 in NX-OS
Cisco released fixes for CVE-2026-76471, a CVSS 9.8 remote code execution flaw in the NX-API component of NX-OS. Nexus 3000 and 9000 switches in standalone mode and UCS 6300 fabric interconnects are affected, the latter exposing the flaw via the default-enabled UCS Manager XML API. No confirmed exploitation has been reported.
- CVSS 9.8: insufficient NX-API input validation allows root code execution or reload
- NX-API is off by default on Nexus 3000/9000 but exposed on UCS 6300 via UCS Manager
- Fixed releases: 10.3(10), 10.4(8), 10.5(6), 10.6(4) for Nexus; 4.3(6j) or 6.0(2e) for UCS
- Cisco's temporary Live Protect shield covers the flaw where no upgrade window exists
Read next
Security