Cisco Patches a Dozen Critical Vulnerabilities
Cisco patched 35 flaws, including more than a dozen critical bugs, and reports no known exploitation.
Cisco patched 35 vulnerabilities, including more than a dozen critical-severity bugs, across Meraki, License On-Prem, NX-OS, and Application Policy Infrastructure Controller. Unauthenticated License On-Prem issues include unauthorized access (CVE-2026-20328) and denial of service (CVE-2026-76454). On NX-OS, CVE-2026-76471 and CVE-2026-76465 could let remote unauthenticated attackers run code as root or cause a denial of service, while three NGOAM flaws affect only Nexus 3000 and 9000 switches with that feature enabled. Cisco also fixed a publicly disclosed high-severity SSRF in Finesse, CVE-2026-20362, and said it is not aware of exploitation.