# Cisco patches critical NX-OS RCE flaws

Published: 2026-10-08 · Severity: routine · Sectors: telecommunications, infrastructure, technology
Canonical: https://vorant.io/reports/4dc00264-9b2f-5a80-8d08-0ec72cc6d59d/cisco-patches-critical-nx-os-rce-flaws

> Cisco fixed nine NX-OS vulnerabilities, including two unauthenticated critical RCE bugs (CVSS 9.8) in NX-API; no active exploitation reported.

NCSC-NL republished Cisco's advisories covering nine vulnerabilities in Cisco NX-OS Software, the operating system used on Cisco Nexus switches and other networking hardware. The most severe issues include an unauthenticated remote code execution vulnerability in the NX-API feature (insufficient HTTP request input validation) that can allow root-level command execution or denial of service, and a heap-based buffer overflow issue, both rated CVSS 9.8. A separate Python interpreter sandbox-escape flaw allows a low-privileged authenticated local attacker to break out of the sandbox and execute arbitrary OS commands. Additional vulnerabilities relate to missing rate limiting on certain protocols, which can be abused by unauthenticated remote attackers to exhaust system resources and disrupt routing and control-plane protocols, as well as several internally discovered issues involving improper neutralization, access control, input validation, out-of-bounds read/write, and improper exception handling.

All vulnerabilities were discovered internally by Cisco's engineering team during security reviews, and Cisco states there is no evidence of in-the-wild exploitation at this time. Cisco has released software hardening updates addressing all nine CVEs. Given the presence of unauthenticated, root-level RCE vectors (CVE-2026-76455, CVE-2026-76471) reachable via NX-API on affected Nexus devices, defenders running Cisco NX-OS should prioritize patching, restrict NX-API and management-plane exposure to trusted networks, and monitor for anomalous HTTP requests to NX-API interfaces and unexpected control-plane resource exhaustion.

This advisory is a direct republication of Cisco's own security bulletins by the Dutch national CERT and does not constitute a rollup of unrelated third-party reporting.

## Mentioned in this report

- Vulnerabilities: CVE-2026-20032, CVE-2026-20173, CVE-2026-76453, CVE-2026-76455, CVE-2026-76456, CVE-2026-76457, CVE-2026-76458, CVE-2026-76459, CVE-2026-76471

## Detection guidance (public sample)

### NX-API Endpoint Requested From Non-Internal Source

ATT&CK: T1203

POST requests to the Cisco NX-API /ins endpoint from non-RFC1918 sources, which indicates exposed management-plane access that could be used to exploit the NX-API RCE/DoS flaws. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: NX-API Endpoint Requested From Non-Internal Source
description: Detects HTTP POST requests to the Cisco NX-API /ins endpoint originating
  from public (non-RFC1918, non-loopback) addresses. NX-API should only be reachable
  from trusted management networks; external access to it is the exposure needed to
  exploit the unauthenticated NX-API input-validation RCE/DoS flaws. This is an exposure
  and early-warning detection, not proof of exploitation. Several hits in a short
  window from one source should raise priority. Requires web or access logs from NX-API
  front-ends or upstream reverse proxies and load balancers.
tags:
- attack.initial-access
- attack.t1190
- attack.t1203
- attack.t1499
logsource:
  category: webserver
detection:
  selection:
    cs-method: POST
    cs-uri-stem|endswith: /ins
  filter_internal:
    c-ip|cidr:
    - 10.0.0.0/8
    - 172.16.0.0/12
    - 192.168.0.0/16
    - 127.0.0.0/8
  condition: selection and not filter_internal
falsepositives:
- Legitimate automation platforms or cloud-hosted network controllers that manage
  Nexus switches over NX-API from public addresses
- Third-party managed-service providers administering devices from known external
  IP ranges
level: medium
id: 1167db86-7595-5e18-a8c5-ae45e1f85f4f
status: experimental
author: Vorant
references:
- https://advisories.ncsc.nl/2026/ncsc-2026-0406.html
```

Behavioural rules are generated from public reporting — validate in your environment before deploying.

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0406.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/4dc00264-9b2f-5a80-8d08-0ec72cc6d59d/cisco-patches-critical-nx-os-rce-flaws.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
