SB2026100865 - Multiple vulnerabilities in Cisco NX-OS Software
Published: October 8, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 7 vulnerabilities.
1) Improper isolation or compartmentalization (CVE-ID: CVE-2026-20032)
CWE-ID: CWE-653 - Improper isolation or compartmentalization
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escape the Python sandbox and execute arbitrary commands on the underlying operating system with the privileges of the authenticated user.
The vulnerability exists due to insufficient validation of user-supplied input in the Python interpreter of Cisco NX-OS Software when processing user-supplied input. A local user can manipulate specific functions within the Python interpreter to escape the Python sandbox and execute arbitrary commands on the underlying operating system with the privileges of the authenticated user.
Exploitation requires Python execution privileges.
2) Command injection (CVE-ID: CVE-2026-76453)
CWE-ID: CWE-77 - Command injection
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary commands.
The vulnerability exists due to command injection in Cisco NX-OS Software when commands or arguments are processed without proper neutralization. A remote user can exploit the improper neutralization over the network to execute arbitrary commands.
Affected devices are vulnerable regardless of device configuration.
3) Improper access control (CVE-ID: CVE-2026-76455)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information, modify data, and cause a denial of service.
The vulnerability exists due to improper access control in Cisco NX-OS Software when network-accessible operations are subject to inadequate access restrictions. A remote attacker can bypass access controls over the network to disclose sensitive information, modify data, and cause a denial of service.
Affected devices are vulnerable regardless of device configuration.
4) Input validation error (CVE-ID: CVE-2026-76456)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in Cisco NX-OS Software when processing special elements used in commands. A remote attacker can exploit the input-validation weakness over the network to cause a denial of service.
Affected devices are vulnerable regardless of device configuration.
5) Out-of-bounds read (CVE-ID: CVE-2026-76457)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds read issues in Cisco NX-OS Software when memory is read beyond its valid boundaries. A remote attacker can trigger out-of-bounds reads over the network to cause a denial of service.
Affected devices are vulnerable regardless of device configuration.
6) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-76458)
CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of exceptional conditions in Cisco NX-OS Software when exceptional conditions arise during network-accessible operations. A remote attacker can trigger improperly handled exceptional conditions over the network to cause a denial of service.
Affected devices are vulnerable regardless of device configuration.
7) Stack-based buffer overflow (CVE-ID: CVE-2026-76459)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose sensitive information, modify data, and cause a denial of service.
The vulnerability exists due to stack-based buffer overflow issues in Cisco NX-OS Software when writes exceed stack buffer boundaries. A remote user can exploit the buffer overflow over the network to disclose sensitive information, modify data, and cause a denial of service.
Affected devices are vulnerable regardless of device configuration.
Remediation
Install update from vendor's website.
References
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-mppe-dhKZAFgb
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nxos-mppe-dhKZAFgb
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-nxosw1-cWzSbtR
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-nxosw1-cWzSbtR