GPU VulnDB

Database/Firmware, BMC & network fabric

Cisco NX-OS: out-of-bounds write lets an authenticated user take over the switch

CVSS 8.8CVE-2026-76459Firmware, BMC & network fabriccurated

Impact

An authenticated low-privilege user triggers a memory-corrupting out-of-bounds write that yields full confidentiality, integrity and availability impact on the device (CVSS 8.8). Memory corruption in a switch process is both an escalation path and a reliable way to crash the control plane, so on a GPU cluster the realistic outcomes are control of a leaf that carries multiple tenants and an unplanned reconvergence that stalls distributed training jobs mid-run. Cisco discovered it internally and did not say which process or input path is affected.

Who can reach it

Any user with valid low-privilege credentials on an affected NX-OS device, reachable over the network. Authentication required, no user interaction.

What to do

Upgrade to a fixed NX-OS release per the Cisco hardening bulletin; no workaround is published. The upgrade reloads the switch - drain to the redundant peer first. Restricting who holds switch login credentials limits exposure but does not remove it.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.