VYPR
advisoryPublished Oct 7, 2026· Updated Oct 11, 2026· 1 source

Cisco Systems: 25 Vulnerabilities Disclosed in NX-OS, APIC, and License On-Prem on October 7, 2026

Key findings • Cisco Systems disclosed 25 vulnerabilities on October 7, 2026, impacting products like NX-OS, APIC, and License On-Prem. • Multiple Critical-severity vulnerabilities (CVSSv3 9.…

Key findings

  • Cisco Systems disclosed 25 vulnerabilities on October 7, 2026, impacting products like NX-OS, APIC, and License On-Prem.
  • Multiple Critical-severity vulnerabilities (CVSSv3 9.8) were found in Cisco NX-OS, particularly in OAM features, allowing for code execution or DoS.
  • Cisco APIC and License On-Prem also have multiple disclosed vulnerabilities, including Critical-severity flaws, stemming from internal security reviews.
  • The vulnerabilities were addressed through coordinated disclosure and software hardening releases by Cisco.
  • Users are urged to consult Cisco advisories and apply updates to mitigate risks.

On October 7, 2026, Cisco Systems disclosed a significant batch of 25 vulnerabilities affecting multiple product lines, including Cisco NX-OS Software, Cisco Application Policy Infrastructure Controller (APIC), and Cisco License On-Prem. The disclosed vulnerabilities range in severity from Medium to Critical, with several Critical-severity flaws carrying a CVSSv3 score of 9.8. This coordinated disclosure event highlights potential risks for organizations relying on these Cisco products for network infrastructure and management.

A notable cluster of vulnerabilities impacts Cisco NX-OS Software, particularly its Segment Routing over IPv6 (SRv6) OAM and VXLAN OAM features. CVE-2026-76501, CVE-2026-76486, and CVE-2026-76485 are all rated Critical (CVSSv3 9.8) and could allow unauthenticated, remote attackers to execute arbitrary code with root privileges or cause a denial of service (DoS). Another NX-OS vulnerability, CVE-2026-76471 (Critical, CVSSv3 9.8), affects the NX-API feature and stems from insufficient input validation. Additionally, CVE-2026-76465 (Critical, CVSSv3 9.8) targets the MPLS OAM feature on Cisco Nexus 3000 and 9000 Series Switches, posing similar risks of code execution or DoS. Other NX-OS related vulnerabilities include CVE-2026-76464 (Critical, CVSSv3 9.6), CVE-2026-76459 (Critical, CVSSv3 9.8), and several High-severity flaws such as CVE-2026-76472, CVE-2026-76470, CVE-2026-76463, CVE-2026-76458, CVE-2026-76457, and CVE-2026-76456.

The Cisco Application Policy Infrastructure Controller (APIC) is affected by multiple vulnerabilities, with CVE-2026-76498, CVE-2026-76499, and CVE-2026-76500 being Critical (CVSSv3 9.8). These were discovered during an internal security review. CVE-2026-76488 (Medium, CVSSv3 6.5) affects the export policies functionality, potentially allowing authenticated attackers to access sensitive files.

Cisco License On-Prem (formerly Cisco Smart Software Manager On-Prem) also saw several vulnerabilities disclosed, including CVE-2026-76482 (Critical, CVSSv3 10.0), CVE-2026-76480 (Critical, CVSSv3 9.8), CVE-2026-76483 (Critical, CVSSv3 9.1), and CVE-2026-76455 (Critical, CVSSv3 9.8). These were also identified through internal reviews and address issues such as missing authentication and improper verification of credentials.

Cisco has released software hardening releases to address these vulnerabilities. While the disclosure was coordinated by Cisco's Product Security Incident Response Team (PSIRT) and no public announcements or malicious use were known at the time of disclosure, the severity of several flaws warrants immediate attention. Organizations using affected Cisco products should consult Cisco's official advisories for specific version information and recommended updates to mitigate the risks associated with these vulnerabilities.

This batch of vulnerabilities underscores the importance of regular security audits and timely patching for complex network infrastructure components. Users are advised to review the specific CVE details relevant to their deployed Cisco products and apply the necessary security updates to protect against potential exploitation.

Cisco Systems disclosed 25 vulnerabilities on October 7, 2026, impacting products like NX-OS, APIC, and License On-Prem. Multiple Critical-severity vulnerabilities (CVSSv3 9.8) were found in Cisco NX-OS, particularly in OAM features, allowing for code execution or DoS. Cisco APIC and License On-Prem also have multiple disclosed vulnerabilities, including Critical-severity flaws, stemming from internal security reviews. The vulnerabilities were addressed through coordinated disclosure and software hardening releases by Cisco. Users are urged to consult Cisco advisories and apply updates to mitigate risks. A network diagram with multiple interconnected routers and switches, where several nodes are highlighted in red, indicating vulnerabilities. The overall aesthetic should be technical and abstract, avoiding any literal representations of people or animals. The focus is on the interconnectedness and the points of weakness within the system.

Synthesized by Vypr AI