Cisco NX-OS NX-API unauthenticated root RCE
A flaw in the NX-API feature of Cisco NX-OS allows an unauthenticated remote attacker to execute arbitrary code as root or cause a denial of service on Nexus switches.
- Vendor
- Cisco
- Product
- NX-OS (Nexus 3000, 9000 series)
- CVSS
- 9.8
- EPSS (exploit probability)
- 0.5%
- Status
- patched
- Published
CVE-2026-76471 is a critical-severity flaw in the NX-API feature of Cisco NX-OS. CVSS 9.8. No authentication required.
What it is
NX-API is a REST/JSON management interface in NX-OS. When enabled, it accepts HTTP and HTTPS requests on the management plane. CVE-2026-76471 allows an unauthenticated, remote attacker to send a crafted request to the NX-API listener and execute arbitrary code with root privileges, or trigger a denial-of-service condition on the affected device.
NX-API is disabled by default but is commonly enabled in data center environments that use automation and programmability workflows.
Affected products
Cisco Nexus 3000 series and Nexus 9000 series switches running NX-OS with NX-API enabled. Consult the Cisco advisory for the specific affected release trains and fixed versions.
Exploitation status
No active exploitation confirmed. Not in the CISA KEV catalog as of October 9, 2026.
Remediation
Cisco released fixed NX-OS software versions. The advisory also documents a workaround: disable NX-API if the feature is not required. Check the linked advisory for the fixed release applicable to your NX-OS train.
FAQ
What is CVE-2026-76471? A critical vulnerability in the NX-API management feature of Cisco NX-OS that lets an unauthenticated remote attacker run arbitrary code as root on Nexus 3000 and 9000 series switches.
Does NX-API need to be enabled for this to apply? Yes. NX-API is disabled by default. The vulnerability only affects devices where NX-API has been explicitly enabled.
Is there active exploitation? No exploitation has been confirmed as of October 9, 2026. CISA has not added this to KEV.
