Forkast·

Cisco NX-API Carries an Unauthenticated Root RCE, and It Stays Off Until Automation Turns It On

Your call?

CVE-2026-76471 allows an unauthenticated, remote attacker to send a crafted HTTP request to the NX-API of an affected device to execute arbitrary code with root privileges, provided the feature is enabled. The bug, detailed in the official…

Share

More news