Cisco patches critical NX-OS RCE flaws
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
Cisco fixed nine NX-OS vulnerabilities, including two unauthenticated critical RCE bugs (CVSS 9.8) in NX-API; no active exploitation reported.
NCSC-NL republished Cisco's advisories covering nine vulnerabilities in Cisco NX-OS Software, the operating system used on Cisco Nexus switches and other networking hardware. The most severe issues include an unauthenticated remote code execution vulnerability in the NX-API feature (insufficient HTTP request input validation) that can allow root-level command execution or denial of service, and a heap-based buffer overflow issue, both rated CVSS 9.8. A separate Python interpreter sandbox-escape flaw allows a low-privileged authenticated local attacker to break out of the sandbox and execute arbitrary OS commands. Additional vulnerabilities relate to missing rate limiting on certain protocols, which can be abused by unauthenticated remote attackers to exhaust system resources and disrupt routing and control-plane protocols, as well as several internally discovered issues involving improper neutralization, access control, input validation, out-of-bounds read/write, and improper exception handling.
All vulnerabilities were discovered internally by Cisco's engineering team during security reviews, and Cisco states there is no evidence of in-the-wild exploitation at this time. Cisco has released software hardening updates addressing all nine CVEs. Given the presence of unauthenticated, root-level RCE vectors (CVE-2026-76455, CVE-2026-76471) reachable via NX-API on affected Nexus devices, defenders running Cisco NX-OS should prioritize patching, restrict NX-API and management-plane exposure to trusted networks, and monitor for anomalous HTTP requests to NX-API interfaces and unexpected control-plane resource exhaustion.
This advisory is a direct republication of Cisco's own security bulletins by the Dutch national CERT and does not constitute a rollup of unrelated third-party reporting.
Mentioned in this report
Detection guidance
NX-API Endpoint Requested From Non-Internal Source
POST requests to the Cisco NX-API /ins endpoint from non-RFC1918 sources, which indicates exposed management-plane access that could be used to exploit the NX-API RCE/DoS flaws. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.
title: NX-API Endpoint Requested From Non-Internal Source
description: Detects HTTP POST requests to the Cisco NX-API /ins endpoint originating
from public (non-RFC1918, non-loopback) addresses. NX-API should only be reachable
from trusted management networks; external access to it is the exposure needed to
exploit the unauthenticated NX-API input-validation RCE/DoS flaws. This is an exposure
and early-warning detection, not proof of exploitation. Several hits in a short
window from one source should raise priority. Requires web or access logs from NX-API
front-ends or upstream reverse proxies and load balancers.
tags:
- attack.initial-access
- attack.t1190
- attack.t1203
- attack.t1499
logsource:
category: webserver
detection:
selection:
cs-method: POST
cs-uri-stem|endswith: /ins
filter_internal:
c-ip|cidr:
- 10.0.0.0/8
- 172.16.0.0/12
- 192.168.0.0/16
- 127.0.0.0/8
condition: selection and not filter_internal
falsepositives:
- Legitimate automation platforms or cloud-hosted network controllers that manage
Nexus switches over NX-API from public addresses
- Third-party managed-service providers administering devices from known external
IP ranges
level: medium
id: 1167db86-7595-5e18-a8c5-ae45e1f85f4f
status: experimental
author: Vorant
references:
- https://advisories.ncsc.nl/2026/ncsc-2026-0406.html
Behavioural rules are generated from public reporting — validate in your environment before deploying.
Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0406.html
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 11,003 reports from 148 sources, 474 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs