Cisco Fixes 35 Flaws, Including Root-Level Attack Paths in NX-OS

Cisco issued updates for 35 flaws across NX-OS, APIC, License On-Prem, Meraki and Finesse, including root execution and reload risks.

Cisco Fixes 35 Flaws, Including Root-Level Attack Paths in NX-OS
Vulnerabilities

Illustrative image generated with AI

Cisco has issued security updates for 35 CVE identifiers spanning NX-OS, Application Policy Infrastructure Controller (APIC), Cisco License On-Prem, Meraki and Finesse.

The Cisco PSIRT advance notification says the product advisories were published on October 7, 2026. Cisco first released the notification on September 30 and updated it on October 7. The publication listing records October 8 updates for the NX-API and Meraki advisories.

Cisco’s notification classifies 29 CVEs as Critical, one as High and five as Medium. Advisory-level CVSS base scores range from 4.4 to 10.0. These ratings describe severity, not evidence of active attacks.

SecurityWeek reports that Cisco said it was unaware of exploitation in the wild. The supplied Cisco PSIRT excerpts do not independently specify an exploitation status. They also contain no EPSS probabilities, so those materials do not support a probability-based comparison of exploitation likelihood.

NX-OS bugs expose root execution and device-reload risks

NX-OS accounts for 14 of the 35 CVEs. Cisco places 11 under Critical-rated advisories and the remaining three under Medium-rated advisories.

The October NX-OS Security Hardening Release groups six internally discovered vulnerabilities:

Cisco rates the grouped advisory Critical with a CVSS base score of 9.8. Individual NVD records, however, provide different scores and weakness classifications.

CVE-2026-76455 is an improper-access-control vulnerability classified as CWE-284 and scored 9.8. CVE-2026-76453 concerns improper neutralization under CWE-707, while CVE-2026-76459 covers an out-of-bounds write under CWE-787; both have NVD scores of 8.8.

CVE-2026-76456 involves improper validation of special command elements and is classified as CWE-20. CVE-2026-76457 is an out-of-bounds read under CWE-125, and CVE-2026-76458 concerns exceptional-condition handling under CWE-703. Each carries an NVD score of 8.6.

Those records show why a score assigned to a multi-CVE advisory should not automatically be treated as the score for every vulnerability inside it.

Two other NX-OS vulnerabilities have documented unauthenticated remote attack paths. CVE-2026-76471, rated 9.8, affects NX-API. Insufficient input validation allows an attacker to send a crafted HTTP request to an affected interface. Successful exploitation could execute arbitrary code as root, crash processes or force the device to reload, resulting in denial of service.

CVE-2026-76465 also has a 9.8 score. It affects the MPLS Operation, Administration, and Maintenance feature on Cisco Nexus 3000 and Nexus 9000 Series switches. An unauthenticated attacker can send a crafted MPLS echo-request to an IP address on the device. Improper packet validation could lead to root-level code execution, process crashes and a device reload.

The NGOAM advisory covers CVE-2026-76485, CVE-2026-76486 and CVE-2026-76501. Cisco says these vulnerabilities could let an unauthenticated remote attacker execute code as root or cause denial of service. According to SecurityWeek, exploitation requires NGOAM to be enabled on a Nexus 3000 or Nexus 9000 Series switch.

Three Medium NX-OS issues complete the set. CVE-2026-20038 is a CVSS 5.8 endpoint-group contract bypass affecting Nexus 9000 Series Fabric Switches in ACI mode. CVE-2026-20173 is a 5.8 control-plane denial-of-service vulnerability, while CVE-2026-20032 is a 4.4 Python sandbox escape.

The sources differ on the Critical count. SecurityWeek describes seven Critical NX-OS vulnerabilities, whereas the Cisco notification associates 11 NX-OS CVEs with Critical-rated advisories. The available material does not reconcile that difference.

APIC updates cover five access, injection and file-handling flaws

Cisco’s APIC releases address five CVEs. The APIC October 2026 Security Hardening Release includes CVE-2026-76498, CVE-2026-76499 and CVE-2026-76500. Cisco rates the advisory Critical with a CVSS base score of 9.8.

Reported weakness categories include improper access control, operating-system injection and memory flaws. The available reporting does not map those categories to individual CVEs, so administrators should not assume which identifier represents a particular weakness.

Two additional APIC vulnerabilities are rated Medium at 6.5. CVE-2026-20321 is an API command-injection vulnerability, and CVE-2026-76488 could permit unauthorized file access.

License On-Prem receives two Critical, 10.0 advisories

Cisco License (Smart Software Manager) On-Prem—formerly Cisco Smart Software Manager On-Prem—accounts for eight CVEs split between two advisories. Both advisories are rated Critical with a CVSS base score of 10.0.

The first covers CVE-2026-20328, CVE-2026-76437, CVE-2026-76452 and CVE-2026-76454. Cisco’s PSIRT summary specifically places these vulnerabilities in the product’s web-based management interface and API endpoints. Potential outcomes include unauthorized access, disclosure of sensitive information and denial of service.

CVE-2026-20328 could provide unauthorized access, while CVE-2026-76454 could cause denial of service. Both are described as remotely exploitable without authentication.

A separate License On-Prem Security Hardening Release addresses CVE-2026-76480, CVE-2026-76482, CVE-2026-76483 and CVE-2026-76484. Reported weakness types associated with CVE-2026-76480, CVE-2026-76482 and CVE-2026-76483 include missing authentication, improper verification of cryptographic signatures and inadequately protected credentials. The reporting does not assign each category to a specific identifier.

The supplied evidence does not establish that all four hardening-release vulnerabilities affect the same web management interface and API endpoints described in the separate advisory.

Meraki and Finesse fixes address seven Critical CVEs and one SSRF

Cisco’s Meraki October 2026 Security Hardening Release covers CVE-2026-76463, CVE-2026-76464, CVE-2026-76467, CVE-2026-76468, CVE-2026-76469, CVE-2026-76470 and CVE-2026-76472.

The advisory carries a Critical rating and a CVSS base score of 9.6. Cisco says the vulnerabilities were identified through an internal security review.

CVE-2026-76464 is reported as the most severe identifier in the group. It covers memory-safety problems including buffer overflows and out-of-bounds writes.

Cisco Finesse has the only High-rated vulnerability in this release set. CVE-2026-20362 is a server-side request forgery flaw with a CVSS base score of 7.2. SecurityWeek reports that it had been publicly disclosed, but public disclosure does not by itself demonstrate exploitation.

Fixed versions must be checked in each product advisory

Cisco recommends upgrading to the fixed software specified in the individual advisories. The supplied excerpts do not contain affected or corrected release numbers, so they cannot establish vulnerable or safe build ranges.

Administrators should consult the relevant product advisory and compare its release table with each deployed system. Exposure checks should also account for the prerequisites documented in the available material: NX-API accessibility, MPLS OAM use, NGOAM enablement, and Nexus 9000 switches operating in ACI mode.

The Cisco PSIRT publication listing marks Workaround: No for the NX-API, Meraki, both License On-Prem, NGOAM, MPLS OAM and NX-OS hardening advisories. The advance notification more broadly states No workarounds available. For the listed issues, Cisco’s prescribed remediation is installation of the designated fixed software.

Before upgrading, Cisco advises customers to verify that devices have sufficient memory and that the resulting hardware and software configurations remain supported. Customers entitled to fixed software but unable to obtain it through their point of sale are directed to Cisco Technical Assistance Center.

The operational priority should not be derived from CVSS alone. Scores as high as 10.0 describe technical severity and exploit conditions, while the cited reporting says Cisco had not observed in-the-wild exploitation. The supplied sources and excerpts contain no EPSS data with which to estimate exploitation probability.

Security dossiers

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Back to home

Latest Cybersecurity News

All cybersecurity news →