[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fW8PAPUAJDZgZetDekAMjUDVrIVZ3-0Eaq4lmTjI7EgU":3},{"article":4,"iocs":40},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"e60724e7-4068-4bd8-8205-be9c95ad88a7","Cisco Patches a Dozen Critical Vulnerabilities","cisco-patches-a-dozen-critical-vulnerabilities-cf3dc8","The security defects could lead to unauthorized access, information leaks, privilege escalation, DoS attacks, and remote code execution. The post Cisco Patches a Dozen Critical Vulnerabilities appeared first on SecurityWeek.","Cisco has announced patches for 35 vulnerabilities across its product lines, with more than a dozen classified as critical severity. These vulnerabilities, affecting products like Meraki, License On-Prem, NX-OS, and APIC, could lead to unauthorized access, information leaks, privilege escalation, denial-of-service, and remote code execution. Cisco has stated they are not aware of any of these vulnerabilities being actively exploited in the wild.","Cisco releases patches for 35 vulnerabilities, including over a dozen critical bugs.","Cisco on Wednesday announced patches for 35 vulnerabilities across its products, including over a dozen critical-severity bugs. A fresh Meraki security hardening release fixes multiple bugs grouped together under seven CVEs, based on the underlying weakness type. The most severe of these is CVE-2026-76464, which covers memory issues such as buffer overflows and out-of-bounds writes. Cisco also resolved eight bugs in License On-Prem, including five critical-severity issues. Two of them could lead to unauthorized access (CVE-2026-20328) and DoS conditions (CVE-2026-76454), and could be exploited without authentication. The remaining three CVEs, CVE-2026-76482, CVE-2026-76480, and CVE-2026-76483, cover multiple security holes across missing authentication, improper verification of cryptographic signature, and insufficiently protected credentials. NX-OS received fixes for 14 vulnerabilities, including seven critical-severity issues. Multiple improper access control and out-of-bounds write flaws have been grouped together under two CVEs: CVE-2026-76455 and CVE-2026-76459. Two other bugs, CVE-2026-76471 and CVE-2026-76465, could allow remote, unauthenticated attackers to execute arbitrary code with root privileges or cause a DoS condition.Advertisement. Scroll to continue reading. The remaining three issues, CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501, can only be triggered on Nexus 3000 and Nexus 9000 series switches that have Next Generation OAM (NGOAM) enabled. Cisco also rolled out patches for three critical-severity CVEs in Application Policy Infrastructure Controller (APIC). Tracked as CVE-2026-76498, CVE-2026-76499, and CVE-2026-76500, they cover multiple improper access control, OS injection, and memory flaws. Additionally, the company announced that security updates for Finesse resolve a high-severity SSRF flaw tracked as CVE-2026-20362 that has been publicly disclosed. Cisco says it is not aware of any of these vulnerabilities being exploited in the wild. Additional information can be found on the company’s security advisories page or in its notifications. Related: SonicWall and Splunk Patch Critical Vulnerabilities Related: FortiBleed Attackers Locking Victims Out of Fortinet Devices Related: Chrome 155 Update Patches 247 Vulnerabilities Related: Atlassian Patches Critical Vulnerability Affecting 8 Products Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire FortiBleed Attackers Locking Victims Out of Fortinet DevicesQilin Ransomware Suspect Arrested in Japan, Extradited to GermanyChrome 155 Update Patches 247 VulnerabilitiesASOS Confirms Cyberattack, Data BreachAndroid’s October 2026 Updates Patch 25 VulnerabilitiesAtlassian Patches Critical Vulnerability Affecting 8 ProductsFBI Arrests ‘Most Wanted’ Developer of Ploutus ATM MalwareApple to Tighten Full Disk Access Controls in macOS Amid AI Risks Latest News Security Awareness Training Isn’t Dead, but It Needs a RethinkAttackers Target Critical Atlassian Vulnerability Within Hours of PoC PublicationUS Seeks Alleged Chinese Hafnium Hacker With $10 Million RewardSonicWall and Splunk Patch Critical VulnerabilitiesRein Security Raises $25 Million to Guard AI Agents at RuntimeTP-Link Faces State Lawsuits and New Scrutiny Over ISP Router FlawsFake Decryption Tools Masked $11M Markup in Ransomware Recovery SchemeOracle Health Data Breach Tally Climbs to Nearly 20 Million Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveRapid7 has named Rik Ferguson as VP of Security Intelligence.Cytactic has appointed Tim Brown as CSO.Scott Simkin has joined Vega as CMO.More People On The MoveExpert Insights AI Has Changed Attack Speed, Not Security Fundamentals As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. (Joshua Goldfarb) Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fcisco-patches-a-dozen-critical-vulnerabilities\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2025\u002F02\u002FCisco-company-logo.jpeg","2026-10-08T15:28:06+00:00","2026-10-08T16:00:12.652795+00:00",8,[18,21,24,26,28,30],{"name":19,"type":20},"Cisco","vendor",{"name":22,"type":23},"Meraki","product",{"name":25,"type":23},"License On-Prem",{"name":27,"type":23},"NX-OS",{"name":29,"type":23},"Nexus 3000",{"name":31,"type":23},"Nexus 9000","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":32,"icon":34,"name":35,"slug":36},null,"Vulnerabilities","vulnerabilities",[38],{"category":39},{"id":32,"icon":34,"name":35,"slug":36},[41,45,48,51,54,57,60,63,66,69,72,75,77,79,82,85,88],{"type":42,"value":43,"context":44},"cve","CVE-2026-76464","Memory issues including buffer overflows and out-of-bounds writes in Meraki",{"type":42,"value":46,"context":47},"CVE-2026-20328","Unauthorized access vulnerability in License On-Prem",{"type":42,"value":49,"context":50},"CVE-2026-76454","Denial of Service vulnerability in License On-Prem",{"type":42,"value":52,"context":53},"CVE-2026-76482","Missing authentication vulnerability in License On-Prem",{"type":42,"value":55,"context":56},"CVE-2026-76480","Improper verification of cryptographic signature vulnerability in License On-Prem",{"type":42,"value":58,"context":59},"CVE-2026-76483","Insufficiently protected credentials vulnerability in License On-Prem",{"type":42,"value":61,"context":62},"CVE-2026-76455","Improper access control vulnerability in NX-OS",{"type":42,"value":64,"context":65},"CVE-2026-76459","Out-of-bounds write vulnerability in NX-OS",{"type":42,"value":67,"context":68},"CVE-2026-76471","Remote code execution with root privileges vulnerability in NX-OS",{"type":42,"value":70,"context":71},"CVE-2026-76465","Denial of Service vulnerability in NX-OS",{"type":42,"value":73,"context":74},"CVE-2026-76485","Vulnerability affecting Nexus 3000\u002F9000 series switches with NGOAM enabled",{"type":42,"value":76,"context":74},"CVE-2026-76486",{"type":42,"value":78,"context":74},"CVE-2026-76501",{"type":42,"value":80,"context":81},"CVE-2026-76498","Improper access control vulnerability in APIC",{"type":42,"value":83,"context":84},"CVE-2026-76499","OS injection vulnerability in APIC",{"type":42,"value":86,"context":87},"CVE-2026-76500","Memory flaw vulnerability in APIC",{"type":42,"value":89,"context":90},"CVE-2026-20362","Server-Side Request Forgery (SSRF) flaw in Finesse"]