Security Advisory Desk
criticalQCS priority 100/100Cisco

Cisco NX-OS Software NX-API Remote Code Execution Vulnerability

A serious security weakness in Cisco NX-OS Software's NX-API feature lets attackers remotely run harmful code or disrupt the device. This happens because the system does not properly check data sent to NX-API. Attackers can send a specially crafted HTTP request to take control or cause the system to crash and restart. Cisco has issued software updates to fix this issue. There are no known workarounds besides updating the software.

QCS published 8/10/2026, 8:16:24 pm ISTVendor disclosure 8/10/2026, 7:41:23 pm ISTVerified 8/10/2026, 8:16:24 pm ISTRevision 1

In plain language

What this advisory means

A serious security weakness in Cisco NX-OS Software's NX-API feature lets attackers remotely run harmful code or disrupt the device. This happens because the system does not properly check data sent to NX-API. Attackers can send a specially crafted HTTP request to take control or cause the system to crash and restart. Cisco has issued software updates to fix this issue. There are no known workarounds besides updating the software.

Technical explanation

How the issue affects the environment

The vulnerability resides in the NX-API feature of Cisco NX-OS Software due to insufficient input validation of data submitted via HTTP requests. An unauthenticated remote attacker can exploit this by sending a crafted HTTP request to the NX-API endpoint, leading to remote code execution with root privileges or denial of service caused by process crashes that may reload the device. On Cisco Nexus 3000 and 9000 Series Switches, NX-API is disabled by default, reducing exposure risk. In contrast, the Cisco UCS 6300 Series Fabric Interconnects require valid low-privileged credentials for exploitation through the UCS Manager XML API, lowering the security impact rating to High for this product. Cisco has released patched software versions to address the vulnerability linked to CVE-2026-76471. No effective workarounds are available, but Cisco provides a Live Protect shield as a temporary mitigation prior to patching.

Operational impact

Why teams should care

Exploitation can give attackers full control (root access) over affected network devices or cause their operational interruption through denial of service. Such impacts can disrupt network availability, potentially affecting business operations and security. Devices may automatically reload after crashes, leading to downtime. Organizations running vulnerable NX-API-enabled devices are urged to promptly apply the released software updates to restore secure operations.

Immediate action

Install the Cisco NX-OS Software updates released by Cisco that contain fixes for this vulnerability. For UCS 6300 Series Fabric Interconnects, upgrade to Cisco UCS Software Release 4.3(6j) or later. Consult Cisco's official security advisory page and use the Cisco Software Checker tool to identify fixed releases appropriate for your devices. Confirm NX-API feature status using 'show feature | include nxapi' and plan upgrades accordingly. No workaround fully mitigates this risk; upgrading software is the recommended remediation.

Affected and fixed releases

Affected versionsCisco NX-OS Software releases running on Nexus 3000 Series Switches with NX-API enabled, Cisco NX-OS Software releases running on Nexus 9000 Series Switches in standalone mode with NX-API enabled, Cisco UCS Software versions 4.2 and earlier on UCS 6300 Series Fabric Interconnects
Fixed versionsCisco NX-OS Software releases with NX-API patch after initial advisory publication, Cisco UCS Software Release 4.3(6j)

Temporary risk reduction

There are no effective workarounds to mitigate this vulnerability. Cisco offers a Live Protect shield as a temporary mitigation for Cisco NX-OS Software until the fixed software can be applied. Network operators should use this temporary tool only as an interim measure while planning software upgrades.

Evidence and validation checklist

  • Cisco PSIRT publicly documented the vulnerability in advisory cisco-sa-napi-rce-r2shwu2j
  • Cisco rated the security impact as Critical with CVSS v3.1 Base Score 9.8
  • Cisco released fixed software versions and updates
  • The vulnerability affects NX-API feature input validation in NX-OS Software
  • No known effective workarounds exist; only software update addresses the issue
  • Temporary mitigation Live Protect shield provided by Cisco for NX-OS
  • No confirmed exploitation or public announcements as per Cisco PSIRT

Authoritative reference

Cisco PSIRT Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source