Improper Input Validation in Cisco NX-OS Products
CVE-2026-76456

8.6HIGH

What is CVE-2026-76456?

The security vulnerability in Cisco NX-OS stems from improper input validation mechanisms within the software, primarily affecting command processing. This issue falls under the category of weaknesses identified as CWE-20, indicating that the system does not adequately validate user inputs, which could lead to unauthorized access or further exploitation. As part of their commitment to enhancing security posture, Cisco has implemented software hardening measures to mitigate these vulnerabilities, ensuring that the integrity and reliability of their networking products remain intact.

Affected Version(s)

Cisco NX-OS Software 8.2(5)

Cisco NX-OS Software 7.3(5)D1(1)

Cisco NX-OS Software 8.4(2)

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.