Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-76457 are related to out-of-bounds read issues that are grouped under the Common Weakness Enumeration (CWE) CWE-125.
Published: 2026-10-07
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability described in CVE-2026-76457 is an out‑of‑bounds read flaw (CWE‑125) that can expose data contained outside the intended memory region. An attacker who can trigger the flaw may read sensitive information from memory, potentially revealing configuration details, credentials, or other confidential data. The issue is purely an information disclosure risk; it does not provide code execution or denial‑of‑service capabilities but can aid further attacks if the leaked data is leveraged.

Affected Systems

Affected products include Cisco NX‑OS Software, Cisco NX‑OS System Software in ACI Mode, and Cisco Unified Computing System (Managed). Any appliance or server running these software suites prior to the October 2026 hardening release is vulnerable. Exact version ranges are not specified, so all pre‑release versions should be considered at risk until the patch is applied.

Risk and Exploitability

The CVSS score of 8.6 indicates a high severity condition, and the EPSS score is not available, so current exploitation probability is uncertain but the lack of a KEV listing known yet. The likely attack vector is through remote access or network exposure of the affected device, with the attacker needing to trigger the out‑of‑bounds read by sending crafted data or commands. Given the nature of the flaw, an attacker that can influence input to the vulnerable component and can observe the memory state could gather sensitive data.

Generated by OpenCVE AI on October 7, 2026 at 18:11 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Cisco NX‑OS Software Security Hardening Release: October 2026 patch that fixes the out‑of‑bounds read vulnerabilities.
  • Upgrade any affected Cisco Unified Computing System (Managed) devices to a version that includes the hardening release.
  • Re‑segment management traffic so that NX‑OS devices are only reachable from trusted internal networks, limiting exposure to potential attackers.

Generated by OpenCVE AI on October 7, 2026 at 18:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Description As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76457 are related to out-of-bounds read issues that are grouped under the Common Weakness Enumeration (CWE) CWE-125.
Title Cisco NX-OS Software Security Hardening Release: October 2026 - Out-of-bounds Read Vulnerabilities
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-10-07T17:45:39.983Z

Reserved: 2026-08-19T12:02:03.637Z

Link: CVE-2026-76457

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T17:16:58.020

Modified: 2026-10-07T18:17:21.317

Link: CVE-2026-76457

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T18:15:14Z

Weaknesses