Cisco patches critical NX-API flaw CVE-2026-76471 rated 9.8
Cisco released fixes for CVE-2026-76471 in NX-OS, where insufficient input validation in NX-API lets a crafted HTTP request achieve root-level code execution or reload the device. Nexus 3000/9000 in standalone mode and UCS 6300 fabric interconnects are affected; NX-API is disabled by default on Nexus but reachable via the UCS Manager XML API.
- CVSS 9.8: exploit yields root access or a device reload
- NX-API is disabled by default on Nexus 3000 and 9000
- UCS 6300 exposed via UCS Manager XML API with low-privileged credentials
- Fixes include NX-OS 10.3(10), 10.4(8), 10.5(6), 10.6(4) and more
Read next
Security