Get real-time updates on Telegram
CVE-2026-76471: Cisco NX-OS Software 9.2(3), 9.2(2v), 9.2(1), 9.2(2t), 9.2(3y), 9.3(2), 9.2(4), 9.3(1), 9.3(1z), 9.2(2), 9.3(3)…
CVE-2026-76471. CVSS 3.1 base score 9.8 (CRITICAL, Vendor/CNA).
Affected technology
Cisco NX-OS Software · 9.2(3), 9.2(2v), 9.2(1), 9.2(2t), 9.2(3y), 9.3(2), 9.2(4), 9.3(1), 9.3(1z), 9.2(2), 9.3(3), 9.3(4), 9.3(5), 9.3(6), 9.3(5w), 9.3(7), 9.3(7k), 9.3(7a), 9.3(8), 9.3(9), 9.3(10), 10.3(1), 10.3(2), 9.3(11), 10.3(3), 9.3(12), 10.4(1), 10.3(99w), 10.3(3w), 10.3(99x), 10.3(3o), 10.3(4), 10.3(3p), 10.3(4a), 10.4(2), 10.3(3q), 9.3(13), 10.3(5), 10.4(3), 10.3(3x), 10.3(4g), 10.5(1), 10.3(3r), 10.3(6), 9.3(14), 10.4(4), 10.3(4h), 10.5(2), 10.3(7), 10.4(5), 10.5(3), 9.3(15), 10.4(4g), 10.5(4), 10.6(1), 10.5(3t), 10.3(8), 10.4(6), 10.5(3s), 10.5(3e), 10.5(3o), 9.3(16), 10.6(1s), 10.6(2), 10.5(3p), 10.3(9), 10.6(2s), 10.6(3), 10.4(7), 10.5(5), 9.3(17), 10.6(2n), 10.6(3s)
Cisco
Cisco Unified Computing System (Managed) · 4.0(1a), 4.1(1d), 4.0(4f), 4.0(4a), 4.0(4e), 4.0(4c), 4.0(4h), 4.1(1c), 4.0(2a), 4.1(1e), 4.1(2a), 4.0(2b), 4.0(1b), 4.0(4d), 4.0(2e), 4.1(1a), 4.0(4g), 4.0(1c), 4.0(1d), 4.0(4b), 4.0(4i), 4.0(2d), 4.1(1b), 4.1(2b), 4.0(4k), 4.1(3a), 4.1(3b), 4.1(2c), 4.0(4l), 4.1(4a), 4.1(3c), 4.1(3d), 4.2(1c), 4.2(1d), 4.0(4m), 4.1(3e), 4.2(1f), 4.1(3f), 4.2(1i), 4.1(3h), 4.2(1k), 4.2(1l), 4.0(4n), 4.2(1m), 4.1(3i), 4.2(2a), 4.2(1n), 4.1(3j), 4.2(2c), 4.2(2d), 4.2(3b), 4.1(3k), 4.0(4o), 4.2(2e), 4.2(3d), 4.2(3e), 4.2(3g), 4.1(3l), 4.3(2b), 4.2(3h), 4.2(3i), 4.3(2c), 4.1(3m), 4.3(2e), 4.3(3a), 4.2(3j), 4.3(3c), 4.3(4a), 4.2(3k), 4.3(4b), 4.3(4c), 4.2(3l), 4.3(4d), 4.3(2f), 4.2(3m), 4.3(5a), 4.3(4e), 4.1(3n), 4.3(4f), 4.2(3n), 4.3(5c), 4.2(3o), 4.3(5d), 4.3(6a), 4.3(6b), 4.3(5e), 4.3(6c), 4.2(3p), 4.3(6d), 4.3(6e), 4.3(6f), 4.2(3r), 4.3(6g), 4.3(6h), 4.2(3s), 4.3(6i)
Cisco
Component: Not specified by the source
Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · No privileges required · No user interaction required
What an attacker can do
An unauthenticated, remote attacker could execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. Vendor/CNA’s CVSS 3.1 assessment (base score 9.8/10) rates confidentiality, integrity and availability impact as high.
- CWE
- CWE-122
- CCR priority
- 39.2 /100 (P4)
- CVSS 3.1
- 9.8 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H · Vendor/CNA
- KEV
- no
Provenance
- NVD CVE API 2.0 · Source record · observed 2026-10-07 19:02:04.772962+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-76471.html