Forkast·
Cisco NX-API Carries an Unauthenticated Root RCE, and It Stays Off Until Automation Turns It On
CVE-2026-76471 allows an unauthenticated, remote attacker to send a crafted HTTP request to the NX-API of an affected device to execute arbitrary code with root privileges, provided the feature is enabled. The bug, detailed in the official…