CVE-2026-76459: Cisco NX-OS Software

Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76459 are related to out-of-bounds write issues that are grouped under the Common Weakness Enumeration (CWE) CWE-787.

Affected products

  • Cisco Cisco NX-OS Software: version 8.2(5) only; version 7.3(5)D1(1) only; version 8.4(2) only; version 8.4(3) only; version 9.2(3) only; version 8.2(1) only; …
  • Cisco Cisco NX-OS System Software In ACI Mode: version 15.2(1g) only; version 15.2(2e) only; version 15.2(2f) only; version 15.2(2g) only; version 15.2(2h) only; version 15.2(3f) only; …
  • Cisco Cisco Unified Computing System Managed: version 4.0(1a) only; version 4.1(1d) only; version 4.0(4f) only; version 4.0(4c) only; version 4.0(2b) only; version 4.1(2a) only; …

Published 2026-10-07. Last modified 2026-10-09.