CVE-2026-76456: Cisco NX-OS Software

High severity, CVSS 8.6. EPSS: 0.3% chance of exploitation in the next 30 days.

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76456 are related to improper input validation of special elements used in a command issue that are grouped under the Common Weakness Enumeration (CWE) CWE-20.

Affected products

  • Cisco Cisco NX-OS Software: version 8.2(5) only; version 7.3(5)D1(1) only; version 8.4(2) only; version 8.4(3) only; version 9.2(3) only; version 8.2(1) only; …
  • Cisco Cisco NX-OS System Software In ACI Mode: version 15.2(1g) only; version 15.2(2e) only; version 15.2(2f) only; version 15.2(2g) only; version 15.2(2h) only; version 15.2(3f) only; …
  • Cisco Cisco Unified Computing System Managed: version 4.0(1a) only; version 4.1(1a) only; version 4.1(1b) only; version 4.0(4h) only; version 4.1(1c) only; version 4.0(4e) only; …

Published 2026-10-07. Last modified 2026-10-08.