Cisco Patches a Dozen Critical Vulnerabilities
Cisco patched 35 flaws, including more than a dozen critical bugs, and reports no known exploitation.
Cisco patched 35 vulnerabilities, including more than a dozen critical-severity bugs, across Meraki, License On-Prem, NX-OS, and Application Policy Infrastructure Controller. Unauthenticated License On-Prem issues include unauthorized access (CVE-2026-20328) and denial of service (CVE-2026-76454). On NX-OS, CVE-2026-76471 and CVE-2026-76465 could let remote unauthenticated attackers run code as root or cause a denial of service, while three NGOAM flaws affect only Nexus 3000 and 9000 switches with that feature enabled. Cisco also fixed a publicly disclosed high-severity SSRF in Finesse, CVE-2026-20362, and said it is not aware of exploitation.
- 35 Cisco flaws patched, more than a dozen critical
- Unauthenticated NX-OS bugs can allow root code execution
- Nexus 3000 and 9000 NGOAM issues require that feature
- Publicly disclosed Finesse SSRF CVE-2026-20362 is fixed
- Cisco says none are known to be exploited
Vulnerabilities mentionedAll →
- CVE-2026-764809.8—Missing authentication in Cisco License On-Prempublished · Cisco License On-Prem (formerly Cisco Smart Software Manager On-Prem / SSM On-Prem)+3 related
- CVE-2026-203627.2—Unauthenticated SSRF in Cisco Finesse management interfacepublished · Cisco Finesse (web-based management interface)
Full article310 words · extracted from securityweek.com · click to collapse
Cisco on Wednesday announced patches for 35 vulnerabilities across its products, including over a dozen critical-severity bugs.
A fresh Meraki security hardening release fixes multiple bugs grouped together under seven CVEs, based on the underlying weakness type. The most severe of these is CVE-2026-76464, which covers memory issues such as buffer overflows and out-of-bounds writes.
Cisco also resolved eight bugs in License On-Prem, including five critical-severity issues. Two of them could lead to unauthorized access (CVE-2026-20328) and DoS conditions (CVE-2026-76454), and could be exploited without authentication.
The remaining three CVEs, CVE-2026-76482, CVE-2026-76480, and CVE-2026-76483, cover multiple security holes across missing authentication, improper verification of cryptographic signature, and insufficiently protected credentials.
NX-OS received fixes for 14 vulnerabilities, including seven critical-severity issues. Multiple improper access control and out-of-bounds write flaws have been grouped together under two CVEs: CVE-2026-76455 and CVE-2026-76459.
Two other bugs, CVE-2026-76471 and CVE-2026-76465, could allow remote, unauthenticated attackers to execute arbitrary code with root privileges or cause a DoS condition.
Advertisement. Scroll to continue reading.
The remaining three issues, CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501, can only be triggered on Nexus 3000 and Nexus 9000 series switches that have Next Generation OAM (NGOAM) enabled.
Cisco also rolled out patches for three critical-severity CVEs in Application Policy Infrastructure Controller (APIC). Tracked as CVE-2026-76498, CVE-2026-76499, and CVE-2026-76500, they cover multiple improper access control, OS injection, and memory flaws.
Additionally, the company announced that security updates for Finesse resolve a high-severity SSRF flaw tracked as CVE-2026-20362 that has been publicly disclosed.
Cisco says it is not aware of any of these vulnerabilities being exploited in the wild. Additional information can be found on the company’s security advisories page or in its notifications.
Related: SonicWall and Splunk Patch Critical Vulnerabilities
Related: FortiBleed Attackers Locking Victims Out of Fortinet Devices
Related: Chrome 155 Update Patches 247 Vulnerabilities
Related: Atlassian Patches Critical Vulnerability Affecting 8 Products