Cisco Addresses Dozens of Critical Vulnerabilities Across Multiple Product Lines
Cisco has released patches for 35 vulnerabilities, including over a dozen critical flaws affecting its Meraki, License On-Prem, NX-OS, and APIC products.

Cisco has announced a significant security update, patching a total of 35 vulnerabilities across its diverse product portfolio. Among these, more than a dozen have been classified as critical severity, posing substantial risks to users if left unaddressed.
The Meraki line of products sees fixes for multiple bugs, consolidated under seven CVEs, stemming from underlying memory corruption issues like buffer overflows and out-of-bounds writes. The most severe of these is tracked as CVE-2026-76464.
In its License On-Prem software, Cisco has resolved eight vulnerabilities, five of which are critical. These critical flaws include potential for unauthorized access (CVE-2026-20328) and denial-of-service conditions (CVE-2026-76454), with the concerning aspect that they could be exploited without requiring any authentication.
Further critical issues in License On-Prem, cataloged under CVE-2026-76482, CVE-2026-76480, and CVE-2026-76483, involve missing authentication checks, improper cryptographic signature verification, and inadequately protected credentials.
The NX-OS operating system is also affected, with patches released for 14 vulnerabilities, including seven critical ones. Multiple vulnerabilities related to improper access control and out-of-bounds writes are grouped under CVE-2026-76455 and CVE-2026-76459. Additionally, CVE-2026-76471 and CVE-2026-76465 could permit remote, unauthenticated attackers to execute arbitrary code with root privileges or trigger denial-of-service conditions.
Specific to Nexus 3000 and Nexus 9000 series switches with the Next Generation OAM (NGOAM) feature enabled, three vulnerabilities (CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501) have been addressed. These flaws could potentially be exploited by attackers.
The Application Policy Infrastructure Controller (APIC) also receives attention, with patches for three critical vulnerabilities (CVE-2026-76498, CVE-2026-76499, and CVE-2026-76500). These vulnerabilities encompass issues with improper access control, OS injection, and memory corruption.
Finally, security updates for Finesse resolve a high-severity Server-Side Request Forgery (SSRF) flaw, CVE-2026-20362, which had been publicly disclosed. Cisco states it is not aware of any of these vulnerabilities being actively exploited in the wild, but strongly advises users to update their Cisco devices promptly to mitigate these risks.