Impact
The vulnerability described in CVE-2026-76457 is an out‑of‑bounds read flaw (CWE‑125) that can expose data contained outside the intended memory region. An attacker who can trigger the flaw may read sensitive information from memory, potentially revealing configuration details, credentials, or other confidential data. The issue is purely an information disclosure risk; it does not provide code execution or denial‑of‑service capabilities but can aid further attacks if the leaked data is leveraged.
Affected Systems
Affected products include Cisco NX‑OS Software, Cisco NX‑OS System Software in ACI Mode, and Cisco Unified Computing System (Managed). Any appliance or server running these software suites prior to the October 2026 hardening release is vulnerable. Exact version ranges are not specified, so all pre‑release versions should be considered at risk until the patch is applied.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity condition, and the EPSS score is not available, so current exploitation probability is uncertain but the lack of a KEV listing known yet. The likely attack vector is through remote access or network exposure of the affected device, with the attacker needing to trigger the out‑of‑bounds read by sending crafted data or commands. Given the nature of the flaw, an attacker that can influence input to the vulnerable component and can observe the memory state could gather sensitive data.
OpenCVE Enrichment