CVE-2026-76409
Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Limitation of a Pathname
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76409 are related to improper limitation of a pathname issues that are grouped under the Common Weakness Enumeration (CWE) CWE-22.
In plain language
AI Act nowBusinesses running Cisco Nexus Dashboard should treat this as urgent because public attack code is available and no fix information has been published.
CVE-2026-76409 is a CVSS 8.8 improper pathname limitation (CWE-22) issue in Cisco Nexus Dashboard that may enable a low-privileged network attacker to compromise confidentiality, integrity, and availability.
What to do now
- Check whether your organization runs Cisco Nexus Dashboard and identify its installed version.
- Ask Cisco or your support partner whether your installed version is affected by CVE-2026-76409; no fixed version has been published in the available findings.
- Until Cisco provides guidance, restrict dashboard access to trusted administrators and remove unnecessary accounts.
- Review dashboard and administrator-account activity for unexpected file-access, configuration, or availability changes.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-76409 and every CVE in our database. Create a free account — no credit card required.
Create Free Account