T
Threats
Cisco NX-OS, License On-Prem, APIC and Meraki Critical Vulnerabilities
Overview
CVEs: CVE-2026-76482, CVE-2026-76455, CVE-2026-76465, CVE-2026-76471, CVE-2026-76480, CVE-2026-76485, CVE-2026-76486, CVE-2026-76498, CVE-2026-76499, CVE-2026-76500, CVE-2026-76501, CVE-2026-76464, CVE-2026-20328, CVE-2026-76454, CVE-2026-76483
Overall severity: Critical, maximum CVSS 10.0. The UCS 6300 exposure to the NX-API CVE is rated High by Cisco.
Advisory date: 8 October 2026.
Vendor publication: All eight source advisories were first published on 7 October 2026 at 16:00 GMT. The Meraki advisory was updated on 8 October 2026 at 00:18 GMT; the other reviewed advisories remain at their initial 7 October revisions.
Affected Versions
The first-fixed releases below are branch-specific. A newer-looking release in a different branch is not automatically a supported migration target. Feature and platform conditions must also be checked.
Cisco License On-Prem - password reset and API vulnerabilities
Affected: CVE-2026-20328 and CVE-2026-76454: SSM On-Prem 9-202601 and earlier must migrate. Cisco License On-Prem releases earlier than 10-202608 are listed as affected.
Fixed: 10-202608 is the first fixed release for these two CVEs. Use 10-202609 to also address the hardening CVEs below.
Not affected: 10-202609 is explicitly listed as not vulnerable. The separate Cisco Smart Licensing Utility product is not affected.
Source: Cisco License On-Prem password reset and API advisory
Cisco License On-Prem - security hardening
Affected: CVE-2026-76482, CVE-2026-76480, CVE-2026-76483: SSM On-Prem 9-202601 and earlier, and Cisco License On-Prem 10-202608 and earlier, regardless of configuration.
Fixed: 10-202609. Earlier SSM On-Prem releases require migration to a fixed release.
Not affected: 10-202609 and the separate Cisco Smart Licensing Utility product.
Source: Cisco License On-Prem October 2026 security hardening advisory
Follow the supported migration and intermediate upgrade paths in the Cisco License On-Prem 10-202609 Release Notes. Direct upgrade to 10-202609 is supported from 10-202608. If the installed release is not listed in the applicable upgrade path, Cisco directs customers to open a TAC case rather than proceed directly.
NX-OS hardening - MDS 9000 Series Multilayer Switches
Affected: CVE-2026-76455: NX-OS 9.3 and earlier require migration; unpatched releases in the 9.4 branch are affected. Device configuration does not remove exposure.
Fixed: 9.4(5a); migrate older branches to a fixed release.
Source: Cisco NX-OS October 2026 security hardening advisory
NX-OS hardening - Nexus 3000 and standalone Nexus 9000 switches
Affected: CVE-2026-76455: Cisco lists NX-OS 10.3 and earlier, 10.4, 10.5 and 10.6 release branches. Device configuration does not remove exposure.
Fixed: 10.3(10), 10.4(8), 10.5(6) and 10.6(4), respectively.
Source: Cisco NX-OS October 2026 security hardening advisory
NX-OS hardening - Nexus 7000 Series switches
Affected: CVE-2026-76455: NX-OS 8.3 and earlier require migration; unpatched releases in the 8.4 branch are affected. Device configuration does not remove exposure.
Fixed: 8.4(14); migrate older branches to a fixed release.
Source: Cisco NX-OS October 2026 security hardening advisory
NX-OS hardening - Nexus 9000 fabric switches in ACI mode
Affected: CVE-2026-76455: Cisco lists NX-OS 16.0 and earlier, 16.1 and 16.2 release branches. Device configuration does not remove exposure.
Fixed: 16.0(9h), 16.1(6g) and 16.2(3g), respectively.
Source: Cisco NX-OS October 2026 security hardening advisory
NX-OS hardening - UCS 6300, 6400, 6500, 6600 and 9108 100G fabric interconnects
Affected: CVE-2026-76455: Cisco lists UCS Software 4.2 and earlier, 4.3 and 6.0 release branches. Device configuration does not remove exposure.
Fixed: UCS Manager mode: 4.3(6j) or 6.0(2e). Intersight mode: 4.3(6.260049) or 6.0(2.260080). For 9108 100G only, the 4.3 Intersight fix is 4.3(6.260059). UCS 4.2 and earlier require migration.
Source: Cisco NX-OS October 2026 security hardening advisory
These vendor-table NX-OS hardening first-fixed releases apply to CVE-2026-76455. The separate MPLS OAM, NX-API and NGOAM fixes below were verified independently through Cisco Software Checker, rather than inferred from this hardening table.
Cisco Nexus 3000 Series Switches - CVE-2026-76465
Affected: CVE-2026-76465: Cisco explicitly lists the following NX-OS releases as known affected, subject to each CVE's platform and feature conditions: 9.3(1), 9.3(2), 9.3(3), 9.3(4), 9.3(5), 9.3(6), 9.3(7), 9.3(7a), 9.3(7k), 9.3(8), 9.3(9), 9.3(10), 9.3(11), 9.3(12), 9.3(13), 9.3(14), 9.3(15), 9.3(16), 9.3(17), 10.3(1), 10.3(2), 10.3(3), 10.3(4), 10.3(4a), 10.3(5), 10.3(6), 10.3(7), 10.3(8), 10.3(9), 10.4(1), 10.4(2), 10.4(3), 10.4(4), 10.4(5), 10.4(6), 10.4(7), 10.5(1), 10.5(2), 10.5(3), 10.5(4), 10.5(5), 10.6(1), 10.6(2), 10.6(3).
Fixed: 10.3(10) for the 9.3, 10.3 branches; 10.4(8) for the 10.4 branch; 10.5(6) for the 10.5 branch; 10.6(4) for the 10.6 branch. The listed 9.x releases require migration to 10.3(10).
Not affected: MPLS OAM disabled, or Nexus 9000 with a Silicon One ASIC.
Source: Cisco MPLS OAM structured advisory (CSAF); Cisco Software Checker, Nexus 3000 Series Switches.
Cisco Nexus 9000 Series Switches - CVE-2026-76465
Affected: CVE-2026-76465: Cisco explicitly lists the following NX-OS releases as known affected, subject to each CVE's platform and feature conditions: 9.3(1), 9.3(1z), 9.3(2), 9.3(3), 9.3(4), 9.3(5), 9.3(5w), 9.3(6), 9.3(7), 9.3(7a), 9.3(7k), 9.3(8), 9.3(9), 9.3(10), 9.3(11), 9.3(12), 9.3(13), 9.3(14), 9.3(15), 9.3(16), 9.3(17), 10.3(1), 10.3(2), 10.3(3), 10.3(3o), 10.3(3p), 10.3(3q), 10.3(3r), 10.3(3w), 10.3(3x), 10.3(4), 10.3(4a), 10.3(4g), 10.3(4h), 10.3(5), 10.3(6), 10.3(7), 10.3(8), 10.3(9), 10.3(99w), 10.3(99x), 10.4(1), 10.4(2), 10.4(3), 10.4(4), 10.4(4g), 10.4(5), 10.4(6), 10.4(7), 10.5(1), 10.5(2), 10.5(3), 10.5(3e), 10.5(3o), 10.5(3p), 10.5(3s), 10.5(3t), 10.5(4), 10.5(5), 10.6(1), 10.6(1s), 10.6(2), 10.6(2n), 10.6(2s), 10.6(3), 10.6(3s).
Fixed: 10.3(10) for the 9.3, 10.3 branches (except the special releases noted below); 10.4(8) for the 10.4 branch; 10.5(6) for the 10.5 branch; 10.6(4) for the 10.6 branch. The listed 9.x releases require migration to 10.3(10). Nexus 9000 10.3(99w), 10.3(99x) require 10.4(8), not 10.3(10).
Not affected: MPLS OAM disabled, or Nexus 9000 with a Silicon One ASIC.
Source: Cisco MPLS OAM structured advisory (CSAF); Cisco Software Checker, Nexus 9000 Series Switches.
Cisco Nexus 3000 Series Switches - CVE-2026-76471, CVE-2026-76485
Affected: CVE-2026-76471, CVE-2026-76485: Cisco explicitly lists the following NX-OS releases as known affected, subject to each CVE's platform and feature conditions: 9.2(1), 9.2(2), 9.2(2t), 9.2(2v), 9.2(3), 9.2(3y), 9.2(4), 9.3(1), 9.3(2), 9.3(3), 9.3(4), 9.3(5), 9.3(6), 9.3(7), 9.3(7a), 9.3(7k), 9.3(8), 9.3(9), 9.3(10), 9.3(11), 9.3(12), 9.3(13), 9.3(14), 9.3(15), 9.3(16), 9.3(17), 10.3(1), 10.3(2), 10.3(3), 10.3(4), 10.3(4a), 10.3(5), 10.3(6), 10.3(7), 10.3(8), 10.3(9), 10.4(1), 10.4(2), 10.4(3), 10.4(4), 10.4(5), 10.4(6), 10.4(7), 10.5(1), 10.5(2), 10.5(3), 10.5(4), 10.5(5), 10.6(1), 10.6(2), 10.6(3).
Fixed: 10.3(10) for the 9.2, 9.3, 10.3 branches; 10.4(8) for the 10.4 branch; 10.5(6) for the 10.5 branch; 10.6(4) for the 10.6 branch. The listed 9.x releases require migration to 10.3(10).
Not affected: NX-API disabled for the NX-API CVE. NGOAM disabled for the NGOAM CVEs. The additional feature conditions below also apply.
Source: Cisco NX-API structured advisory (CSAF); Cisco NGOAM structured advisory (CSAF); Cisco Software Checker, Nexus 3000 Series Switches.
Cisco Nexus 9000 Series Switches - CVE-2026-76471, CVE-2026-76485
Affected: CVE-2026-76471, CVE-2026-76485: Cisco explicitly lists the following NX-OS releases as known affected, subject to each CVE's platform and feature conditions: 9.2(1), 9.2(2), 9.2(3), 9.2(3y), 9.2(4), 9.3(1), 9.3(1z), 9.3(2), 9.3(3), 9.3(4), 9.3(5), 9.3(5w), 9.3(6), 9.3(7), 9.3(7a), 9.3(7k), 9.3(8), 9.3(9), 9.3(10), 9.3(11), 9.3(12), 9.3(13), 9.3(14), 9.3(15), 9.3(16), 9.3(17), 10.3(1), 10.3(2), 10.3(3), 10.3(3o), 10.3(3p), 10.3(3q), 10.3(3r), 10.3(3w), 10.3(3x), 10.3(4), 10.3(4a), 10.3(4g), 10.3(4h), 10.3(5), 10.3(6), 10.3(7), 10.3(8), 10.3(9), 10.3(99w), 10.3(99x), 10.4(1), 10.4(2), 10.4(3), 10.4(4), 10.4(4g), 10.4(5), 10.4(6), 10.4(7), 10.5(1), 10.5(2), 10.5(3), 10.5(3e), 10.5(3o), 10.5(3p), 10.5(3s), 10.5(3t), 10.5(4), 10.5(5), 10.6(1), 10.6(1s), 10.6(2), 10.6(2n), 10.6(2s), 10.6(3), 10.6(3s).
Fixed: 10.3(10) for the 9.2, 9.3, 10.3 branches (except the special releases noted below); 10.4(8) for the 10.4 branch; 10.5(6) for the 10.5 branch; 10.6(4) for the 10.6 branch. The listed 9.x releases require migration to 10.3(10). Nexus 9000 10.3(99w), 10.3(99x) require 10.4(8), not 10.3(10).
Not affected: NX-API disabled for the NX-API CVE. NGOAM disabled for the NGOAM CVEs. The additional feature conditions below also apply.
Source: Cisco NX-API structured advisory (CSAF); Cisco NGOAM structured advisory (CSAF); Cisco Software Checker, Nexus 9000 Series Switches.
Cisco Nexus 3000 Series Switches - CVE-2026-76486
Affected: CVE-2026-76486: Cisco explicitly lists the following NX-OS releases as known affected, subject to each CVE's platform and feature conditions: 9.3(3), 9.3(4), 9.3(5), 9.3(6), 9.3(7), 9.3(7a), 9.3(7k), 9.3(8), 9.3(9), 9.3(10), 9.3(11), 9.3(12), 9.3(13), 9.3(14), 9.3(15), 9.3(16), 9.3(17), 10.3(1), 10.3(2), 10.3(3), 10.3(4), 10.3(4a), 10.3(5), 10.3(6), 10.3(7), 10.3(8), 10.3(9), 10.4(1), 10.4(2), 10.4(3), 10.4(4), 10.4(5), 10.4(6), 10.4(7), 10.5(1), 10.5(2), 10.5(3), 10.5(4), 10.5(5), 10.6(1), 10.6(2), 10.6(3).
Fixed: 10.3(10) for the 9.3, 10.3 branches; 10.4(8) for the 10.4 branch; 10.5(6) for the 10.5 branch; 10.6(4) for the 10.6 branch. The listed 9.x releases require migration to 10.3(10).
Not affected: NGOAM disabled for the NGOAM CVEs. The additional feature conditions below also apply.
Source: Cisco NGOAM structured advisory (CSAF); Cisco Software Checker, Nexus 3000 Series Switches.
Cisco Nexus 9000 Series Switches - CVE-2026-76486, CVE-2026-76501
Affected: CVE-2026-76486, CVE-2026-76501: Cisco explicitly lists the following NX-OS releases as known affected, subject to each CVE's platform and feature conditions: 9.3(3), 9.3(4), 9.3(5), 9.3(5w), 9.3(6), 9.3(7), 9.3(7a), 9.3(7k), 9.3(8), 9.3(9), 9.3(10), 9.3(11), 9.3(12), 9.3(13), 9.3(14), 9.3(15), 9.3(16), 9.3(17), 10.3(1), 10.3(2), 10.3(3), 10.3(3o), 10.3(3p), 10.3(3q), 10.3(3r), 10.3(3w), 10.3(3x), 10.3(4), 10.3(4a), 10.3(4g), 10.3(4h), 10.3(5), 10.3(6), 10.3(7), 10.3(8), 10.3(9), 10.3(99w), 10.3(99x), 10.4(1), 10.4(2), 10.4(3), 10.4(4), 10.4(4g), 10.4(5), 10.4(6), 10.4(7), 10.5(1), 10.5(2), 10.5(3), 10.5(3e), 10.5(3o), 10.5(3p), 10.5(3s), 10.5(3t), 10.5(4), 10.5(5), 10.6(1), 10.6(1s), 10.6(2), 10.6(2n), 10.6(2s), 10.6(3), 10.6(3s).
Fixed: 10.3(10) for the 9.3, 10.3 branches (except the special releases noted below); 10.4(8) for the 10.4 branch; 10.5(6) for the 10.5 branch; 10.6(4) for the 10.6 branch. The listed 9.x releases require migration to 10.3(10). Nexus 9000 10.3(99w), 10.3(99x) require 10.4(8), not 10.3(10).
Not affected: NGOAM disabled for the NGOAM CVEs. The additional feature conditions below also apply.
Source: Cisco NGOAM structured advisory (CSAF); Cisco Software Checker, Nexus 9000 Series Switches.
Cisco Software Checker independently reports 10.3(10), 10.4(8), 10.5(6) and 10.6(4) as not affected by the selected MPLS OAM, NX-API and NGOAM advisories on Nexus 3000 and standalone Nexus 9000 platforms. Its results do not account for enabled or disabled features. Source: Cisco Software Checker.
The structured-advisory release lists are not declarations that every platform supports every feature. For CVE-2026-76501, SRv6 support and both NGOAM and SRv6 being enabled are required. For CVE-2026-76486, the additional SRv6 or NV Overlay conditions in the technical breakdown are required.
UCS 6300 fabric interconnects - NX-API CVE
Affected: CVE-2026-76471: Cisco lists UCS Software 4.2 and earlier and the 4.3 branch. The UCS Manager XML API requires low-privileged user credentials for exploitation.
Fixed: UCS Manager mode: 4.3(6j). Intersight mode: 4.3(6.260049). Releases 4.2 and earlier must migrate.
Source: Cisco NX-OS NX-API remote code execution advisory
For the MPLS OAM and NGOAM CVEs, Cisco also confirms that MDS 9000, Nexus 7000, Nexus 9000 in ACI mode, all listed UCS fabric interconnects, Firepower 1000/2100/4100/9300 and Secure Firewall 200/1200/3100/4200/6100 are not affected. For the NX-API CVE, the same exclusions apply except that UCS 6300 is affected as described above. Sources: Cisco Nexus MPLS OAM remote code execution advisory; Cisco Nexus NGOAM remote code execution advisories; Cisco NX-OS NX-API remote code execution advisory.
Cisco Meraki Campus Gateways
Affected: CVE-2026-76464: 32.2 and 33.1 branches. Cisco lists these products regardless of configuration.
Fixed: Planned, not yet released as of 8 October 2026: 32.2.5 in late October 2026 and 33.1.4 in mid-November 2026.
Source: Cisco Meraki October 2026 security hardening advisory
Cisco Meraki MG Cellular Gateways
Affected: CVE-2026-76464: 26.1 branch. Cisco lists these products regardless of configuration.
Fixed: 26.1.4.
Source: Cisco Meraki October 2026 security hardening advisory
Cisco Meraki MR Wireless Access Points
Affected: CVE-2026-76464: 30.7, 31.1, 32.2 and 33.1 branches. Cisco lists these products regardless of configuration.
Fixed: 30.7.3, 31.1.8.1 and 33.1.3. The 32.2 fix, 32.2.5, is planned for late October 2026.
Source: Cisco Meraki October 2026 security hardening advisory
Cisco Meraki MS Series Switches
Affected: CVE-2026-76464: 18.1 branch and IOS XE 17.15, 17.18 and 26.1 branches. Cisco lists these products regardless of configuration.
Fixed: 18.1.9 is planned for mid-October 2026. IOS XE first-fixed releases are 17.15.6, 17.18.4.1 and 26.1.2.
Source: Cisco Meraki October 2026 security hardening advisory
Cisco Meraki MV Smart Cameras
Affected: CVE-2026-76464: Release 7. Cisco lists these products regardless of configuration.
Fixed: 8.0.
Source: Cisco Meraki October 2026 security hardening advisory
Cisco Meraki MX Security and SD-WAN Appliances
Affected: CVE-2026-76464: 18.1, 19.2, 26.1 and 26.2 branches. Cisco lists these products regardless of configuration.
Fixed: 18.107.14, 19.2.9, 26.1.7 and 26.2.3. Release 19.2.9 is available only for Meraki Z3 devices. Contact Meraki Technical Support if 18.107.14 or 19.2.9 is not offered as an update.
Source: Cisco Meraki October 2026 security hardening advisory
Cisco Application Policy Infrastructure Controller
Affected: CVE-2026-76498, CVE-2026-76499, CVE-2026-76500: APIC 5.3 and earlier require migration; Cisco lists the 6.0, 6.1 and 6.2 branches, regardless of configuration.
Fixed: 6.0(9h), 6.1(6g) and 6.2(3g), respectively. Migrate APIC 5.3 and earlier to a fixed release.
Vulnerability Breakdown
CVE-2026-76482 - Improper cryptographic signature verification
Product: Cisco License On-Prem.
Severity: Critical.
CVSS: 10.0.
Description: Cisco groups internally discovered cryptographic signature verification weaknesses under CWE-347. The published score is the maximum severity of the most impactful issue in this group.
Impact: Cryptographic signature verification protections may be undermined. Cisco does not publish individual exploit outcomes for the grouping.
Conditions: A vulnerable Cisco License On-Prem or legacy SSM On-Prem release, regardless of configuration. Individual issue prerequisites are not detailed.
Versions: See the CVE-specific product and platform entries in Affected Versions above.
Source: Cisco License On-Prem October 2026 security hardening advisory.
CVE-2026-76455 - Improper access control
Product: Cisco NX-OS Software.
Severity: Critical.
CVSS: 9.8.
Description: Cisco groups access-control weaknesses under CWE-284. This class covers authorisation, authentication, privilege handling and bypasses.
Impact: Access-control protections may be compromised. Cisco does not specify an individual exploit outcome for every grouped issue.
Conditions: An affected MDS, Nexus or UCS fabric-interconnect platform running a vulnerable release, regardless of device configuration.
Versions: See the CVE-specific product and platform entries in Affected Versions above.
Source: Cisco NX-OS October 2026 security hardening advisory.
CVE-2026-76465 - MPLS OAM remote code execution
Product: Cisco Nexus 3000 and 9000 Series.
Severity: Critical.
CVSS: 9.8.
Description: Improper validation of MPLS echo-request packets allows exploitation of the MPLS OAM feature.
Impact: An unauthenticated remote attacker could execute code with root privileges or cause process crashes, device reload and denial of service.
Conditions: A vulnerable Nexus 3000 or Nexus 9000 switch in standalone NX-OS mode with MPLS OAM enabled. The feature is disabled by default. Nexus 9000 switches with a Silicon One ASIC do not support this feature and are not affected.
Versions: See the CVE-specific product and platform entries in Affected Versions above.
Source: Cisco Nexus MPLS OAM remote code execution advisory.
CVE-2026-76471 - NX-API remote code execution
Product: Cisco NX-OS Software.
Severity: Critical.
CVSS: 9.8.
Description: Insufficient input validation of requests to NX-API exposes affected devices to crafted HTTP requests.
Impact: Code execution with root privileges or denial of service through process crashes and device reload.
Conditions: On Nexus 3000 and standalone Nexus 9000 switches, NX-API must be enabled and authentication is not required. NX-API is disabled by default on these switches. On UCS 6300 fabric interconnects, exploitation uses the default-enabled UCS Manager XML API and requires valid low-privileged credentials; Cisco rates this platform High, not Critical.
Versions: See the CVE-specific product and platform entries in Affected Versions above.
CVE-2026-76480 - Missing authentication for critical function
Product: Cisco License On-Prem.
Severity: Critical.
CVSS: 9.8.
Description: Cisco groups missing-authentication weaknesses for critical functions under CWE-306. These issues were found during internal testing.
Impact: Critical functions may be exposed without authentication. Cisco does not disclose individual exploit outcomes for this grouping.
Conditions: A vulnerable Cisco License On-Prem or legacy SSM On-Prem release, regardless of configuration.
Versions: See the CVE-specific product and platform entries in Affected Versions above.
Source: Cisco License On-Prem October 2026 security hardening advisory.
CVE-2026-76485 - NGOAM remote code execution
Product: Cisco Nexus 3000 and 9000 Series.
Severity: Critical.
CVSS: 9.8.
Description: Improper validation of IP traffic in NGOAM exposes affected switches to crafted packets.
Impact: An unauthenticated remote attacker could execute code with root privileges or cause process crashes, reload and denial of service.
Conditions: A vulnerable Nexus 3000 or standalone Nexus 9000 switch with NGOAM enabled. No additional feature configuration is required for this CVE.
Versions: See the CVE-specific product and platform entries in Affected Versions above.
CVE-2026-76486 - NGOAM remote code execution with SRv6 or NV Overlay
Product: Cisco Nexus 3000 and 9000 Series.
Severity: Critical.
CVSS: 9.8.
Description: Improper validation of IP traffic in NGOAM exposes switches with specific additional features to crafted packets.
Impact: An unauthenticated remote attacker could execute code with root privileges or cause process crashes, reload and denial of service.
Conditions: NGOAM plus either SRv6 or NV Overlay must be enabled. For NV Overlay, a VXLAN EVPN VNI must be mapped to an NVE interface with at least one learned peer VTEP. Nexus 3000 switches do not support SRv6, so the SRv6 condition does not apply to those platforms.
Versions: See the CVE-specific product and platform entries in Affected Versions above.
CVE-2026-76498 - Improper access control
Product: Cisco APIC.
Severity: Critical.
CVSS: 9.8.
Description: Cisco groups access-control weaknesses under CWE-284, covering authorisation, authentication, privileges and bypasses.
Impact: Access-control protections may be compromised. Individual exploit outcomes are not disclosed for this grouping.
Conditions: A vulnerable Cisco APIC release, regardless of device configuration. Per-issue attack prerequisites are not detailed.
Versions: See the CVE-specific product and platform entries in Affected Versions above.
Source: Cisco APIC October 2026 security hardening advisory.
CVE-2026-76499 - Improper neutralisation
Product: Cisco APIC.
Severity: Critical.
CVSS: 9.8.
Description: Cisco groups improper-neutralisation weaknesses under CWE-707. The class covers command, operating-system and argument injection.
Impact: Injection-related compromise is the identified weakness class. Cisco does not specify execution privileges or individual outcomes for every grouped issue.
Conditions: A vulnerable Cisco APIC release, regardless of device configuration. Per-issue attack prerequisites are not detailed.
Versions: See the CVE-specific product and platform entries in Affected Versions above.
Source: Cisco APIC October 2026 security hardening advisory.
CVE-2026-76500 - Improper resource lifetime control
Product: Cisco APIC.
Severity: Critical.
CVSS: 9.8.
Description: Cisco groups resource-lifetime weaknesses under CWE-664. The class includes memory and file-handler issues, null-pointer dereferences and invalid frees.
Impact: Resource-handling protections may fail. Cisco does not disclose individual availability or compromise outcomes for every grouped issue.
Conditions: A vulnerable Cisco APIC release, regardless of device configuration. Per-issue attack prerequisites are not detailed.
Versions: See the CVE-specific product and platform entries in Affected Versions above.
Source: Cisco APIC October 2026 security hardening advisory.
CVE-2026-76501 - SRv6 NGOAM remote code execution
Product: Cisco Nexus 9000 Series.
Severity: Critical.
CVSS: 9.8.
Description: Improper validation of IP traffic in the SRv6 NGOAM feature exposes affected switches to crafted packets.
Impact: An unauthenticated remote attacker could execute code with root privileges or cause process crashes, reload and denial of service.
Conditions: Both NGOAM and SRv6 must be enabled on a vulnerable, SRv6-capable Nexus 9000 switch in standalone NX-OS mode. Nexus 3000 switches do not support SRv6 and are not affected by this CVE.
Versions: See the CVE-specific product and platform entries in Affected Versions above.
CVE-2026-76464 - Buffer management weaknesses
Product: Cisco Meraki.
Severity: Critical.
CVSS: 9.6.
Description: Cisco groups buffer-boundary weaknesses under CWE-119. This includes buffer overflows and out-of-bounds writes across the listed Meraki product families.
Impact: Buffer-boundary protections may fail. Cisco publishes a maximum grouped score, not a separate outcome for every underlying issue.
Conditions: A vulnerable release on a Meraki Campus Gateway, MG gateway, MR access point, MS switch, MV camera or MX appliance, regardless of configuration. The maximum-score vector specifies adjacent-network access; per-issue prerequisites are not detailed.
Versions: See the CVE-specific product and platform entries in Affected Versions above.
Source: Cisco Meraki October 2026 security hardening advisory.
CVE-2026-20328 - Arbitrary account password reset
Product: Cisco License On-Prem.
Severity: Critical.
CVSS: 9.1.
Description: Improper checks in the password reset process allow a malicious request to the web-based management interface.
Impact: An unauthenticated remote attacker could reset any account password, including privileged administrator accounts, and potentially gain unauthorised application access.
Conditions: A vulnerable Cisco License On-Prem or legacy SSM On-Prem release with a reachable web-based management interface. Cisco lists affected releases regardless of configuration.
Versions: See the CVE-specific product and platform entries in Affected Versions above.
Source: Cisco License On-Prem password reset and API advisory.
CVE-2026-76454 - Unauthenticated API arbitrary file write
Product: Cisco License On-Prem.
Severity: Critical.
CVSS: 9.1.
Description: Improper input validation and missing authentication in the management API allow crafted requests to the Cisco Smart Licensing Utility API within License On-Prem.
Impact: An unauthenticated remote attacker could write arbitrary files, modify system files or cause denial of service.
Conditions: A vulnerable Cisco License On-Prem or legacy SSM On-Prem release with access to the affected API. The separate Cisco Smart Licensing Utility product is not affected.
Versions: See the CVE-specific product and platform entries in Affected Versions above.
Source: Cisco License On-Prem password reset and API advisory.
CVE-2026-76483 - Insufficiently protected credentials
Product: Cisco License On-Prem.
Severity: Critical.
CVSS: 9.1.
Description: Cisco groups credential-protection weaknesses under CWE-522. The score represents the highest-impact issue within this class.
Impact: Credential protection may be compromised. Cisco does not disclose individual credential-exposure mechanisms for the grouping.
Conditions: A vulnerable Cisco License On-Prem or legacy SSM On-Prem release, regardless of configuration. Individual issue prerequisites are not detailed.
Versions: See the CVE-specific product and platform entries in Affected Versions above.
Source: Cisco License On-Prem October 2026 security hardening advisory.
Mitigation
License On-Prem: Upgrade or migrate to 10-202609 to cover both the password reset/API flaws and the selected hardening CVEs. Follow Cisco's supported intermediate upgrade paths. No workaround is available. Sources: Cisco License On-Prem password reset and API advisory; Cisco License On-Prem October 2026 security hardening advisory; Cisco License On-Prem 10-202609 Release Notes.
NX-OS hardening: Apply the platform-specific first-fixed release listed above for CVE-2026-76455. Use the separately verified RCE mappings above, including the Nexus 9000 10.3(99w) and 10.3(99x) migration exception. Source: Cisco NX-OS October 2026 security hardening advisory.
MPLS OAM: If the feature is not required, Cisco says disabling MPLS OAM removes the attack vector. Assess operational impact before disabling it. This is a mitigation, not a software fix. Source: Cisco Nexus MPLS OAM remote code execution advisory.
NGOAM: If the feature is not required, Cisco says disabling NGOAM removes the attack vector for all three NGOAM CVEs. Assess the impact on network diagnostics and operation first. Source: Cisco Nexus NGOAM remote code execution advisories.
NX-API, MPLS OAM and NGOAM: Cisco provides Live Protect shields as temporary mitigations. Confirm the shield, platform, release, memory, licence and feature-compatibility requirements in the Cisco Live Protect configuration guide. Live Protect enforcement starts with 10.6(2)F and requires an NXOS_ESSENTIALS licence; monitoring alone is not blocking. Shields are not replacements for fixed software. Sources: Cisco NX-OS NX-API remote code execution advisory; Cisco Nexus MPLS OAM remote code execution advisory; Cisco Nexus NGOAM remote code execution advisories.
APIC: Upgrade to 6.0(9h), 6.1(6g) or 6.2(3g), as appropriate, or migrate older releases. No workaround is available. Source: Cisco APIC October 2026 security hardening advisory.
Meraki: Apply available product-specific fixes. Track Cisco's planned Campus Gateway, MR 32.2 and MS 18.1 releases. Do not describe planned fixes as already available. Cisco lists no workaround for this hardening advisory. Source: Cisco Meraki October 2026 security hardening advisory.
Summary for IT Teams
Products: Cisco License On-Prem and legacy SSM On-Prem; affected MDS, Nexus and UCS NX-OS platforms; Cisco APIC; Meraki Campus, MG, MR, MS, MV and MX product families.
Threat Level: Critical overall, CVSS 9.1 to 10.0 for the selected CVEs. Cisco reduces the NX-API platform rating to High on UCS 6300 because credentials are required.
Action Required: Match each device to its exact product, mode, installed version and enabled features. Apply verified branch-specific fixes. Apply the independently verified Nexus RCE first-fixed mappings, including the special-release exception. Track planned Meraki fixes and use only Cisco-documented, applicable temporary mitigations.
Reference
Need Help?
The Secure ISS SOC team can help assess exposure and plan remediation. Please get in touch on 1300 769 460 or email the Secure ISS SOC team. We are here to help you strengthen your cybersecurity posture.

