Database/Firmware, BMC & network fabric
Cisco NX-OS: crafted HTTP request to NX-API yields unauthenticated root code execution
Impact
NX-API is the programmatic management interface that automation and config-management tooling drives. Insufficient input validation on data sent to it lets an unauthenticated attacker who can reach that HTTP endpoint run code as root on the switch, or crash the process and trigger a device reload. On a GPU fleet this is the management-plane path: whoever holds root on the switch controls the data plane the cluster depends on, and the same advisory lists Cisco UCS (Managed) among the affected products, which puts compute management in the same blast radius. Note this is a separate flaw from the MPLS OAM issue published the same day - different feature, different advisory, different reach - and it is exposed to anything that can speak HTTP to the device rather than to IP packets alone.
Who can reach it
Anyone with HTTP access to the NX-API endpoint - in practice anyone on the management VLAN, or further afield if NX-API is reachable beyond it. No authentication required. Devices with the NX-API feature disabled are not exposed.
What to do
Upgrade to a fixed NX-OS release per the Cisco advisory; the advisory is authoritative for the per-platform fixed versions, so verify yours there. The upgrade reloads the switch, so plan it rack by rack and keep a spine path up. Until then, the practical mitigation is the feature itself: NX-API is off by default on most platforms, so check whether it is enabled (show feature | include nxapi) and disable it where automation does not need it. Where it is needed, restrict access to the management network with ACLs and front it so arbitrary hosts cannot reach the HTTP endpoint.
References
Related entries
- Cisco NX-OS: crafted IP packets to a VXLAN OAM interface give unauthenticated root code executionCVE-2026-76485 · Cisco NX-OS NGOAM (VXLAN OAM packet handling)Critical
- Cisco NX-OS: crafted IP packets to an SRv6 OAM interface give unauthenticated root code executionCVE-2026-76501 · Cisco NX-OS NGOAM (SRv6 OAM packet handling)Critical
- Cisco Catalyst SD-WAN Manager: URI-encoding auth bypass gives unauthenticated admin API accessCVE-2026-76504 · Cisco Catalyst SD-WAN Manager (API session authentication, URI encoding handling)Critical
- FreeIPMI SEL parser: stack overflow on malformed Fujitsu iRMC long-text SEL responsesCVE-2026-85504 · FreeIPMI libfreeipmi SEL parser (Fujitsu iRMC OEM long-text records)Critical
- FreeIPMI ipmi-oem: stack overflow parsing Dell get-system-info responses returned by a BMCCVE-2026-85506 · FreeIPMI ipmi-oem (Dell get-system-info handlers)Critical
- FreeIPMI FRU reader: stack overflow when a BMC returns more FRU bytes than requestedCVE-2026-85509 · FreeIPMI libfreeipmi FRU reader (_read_fru_data)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.