Choose your location

Latest
Artemis-II astronauts saw mysterious island of light on the Moon as they flew close $1,000,000,000,000: Cost of serving the debt storm in developing countries INDIA Bloc Protest Live: Fresh FIR against Rahul Gandhi, Priyanka over alleged assault, obstruction during stir Northern Ireland Assembly - Urgent Question on the First Minister on BBC Parliament: full details and when it's on Spanish pensioner whose eviction sparked nationwide protests dies, union says Blockchain and the future of insurance: a cross-stakeholder analysis and ecosystem implications

Cisco Patches 35 Vulnerabilities as Critical Nexus Bugs Allow Root Access

Cisco has released a major security update fixing 35 vulnerabilities across several widely used networking and enterprise products, including more than a dozen flaws rated critical. The affected products include Cisco NX-OS, Meraki devices, License On-Prem and the Application Policy Infrastructure Controller, or APIC. Some of the most serious weaknesses could allow

The420.in The420 Web Correspondent

Cisco has released a major security update fixing 35 vulnerabilities across several widely used networking and enterprise products, including more than a dozen flaws rated critical. The affected products include Cisco NX-OS, Meraki devices, License On-Prem and the Application Policy Infrastructure Controller, or APIC.

Some of the most serious weaknesses could allow unauthenticated attackers to execute code with root privileges, gain unauthorised access or crash affected systems remotely. Cisco says it has not seen evidence that the newly disclosed vulnerabilities are being exploited in real-world attacks.

FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals NX-OS Receives Major Security Fixes A large portion of the critical vulnerabilities affect Cisco NX-OS, the operating system used across several Cisco switches and data-centre networking products. Cisco released fixes for 14 NX-OS vulnerabilities in the October security batch.

Several of the flaws involve improper access controls, memory errors and input-validation weaknesses. Cisco grouped multiple internally discovered weaknesses into individual CVEs based on their underlying vulnerability class as part of its newer security disclosure process. The affected environments include MDS 9000 switches, Nexus 3000, Nexus 7000 and Nexus 9000 series devices, Nexus systems operating in ACI mode and certain UCS Fabric Interconnects.

Some Nexus Flaws Allow Root-Level Code Execution Among the most serious issues are vulnerabilities affecting the Next Generation Operations, Administration and Maintenance feature in Cisco NX-OS. The feature, commonly known as NGOAM, is used for monitoring and troubleshooting network connectivity.

Cisco says multiple flaws affecting NGOAM can allow an unauthenticated attacker to send specially crafted network traffic to a vulnerable device. A successful attack could allow arbitrary code to run with root privileges or trigger crashes that result in a denial-of-service condition.

The vulnerabilities are tracked as CVE-2026-76485, CVE-2026-76486 and CVE-2026-76501. They affect certain Nexus 3000 and Nexus 9000 switches when the vulnerable NGOAM functionality is enabled. Cisco has assigned them a maximum CVSS severity score of 9.8.

No Workaround for Critical Nexus Bugs Cisco says there are no workarounds that fully address the NGOAM vulnerabilities. Organisations therefore need to install the fixed NX-OS releases. This is important for data centres because Nexus switches can sit at the centre of critical network infrastructure.

A compromise with root-level access could potentially give an attacker extensive control over an affected networking device. Cisco has not reported malicious exploitation of these vulnerabilities so far. Cisco License On-Prem Also Hit by Critical Flaws Another major group of vulnerabilities affects Cisco License On-Prem, previously known as Cisco Smart Software Manager On-Prem.

The platform allows organisations to manage Cisco software licences inside their own infrastructure instead of relying entirely on cloud-based licensing services. Cisco patched several critical weaknesses in the product during the October release. One security-hardening advisory carries a maximum CVSS score of 10.0, the highest possible rating.

The vulnerabilities involve weaknesses such as missing authentication, insufficient protection of credentials, improper cryptographic signature verification and code execution. Attackers May Not Need Credentials Some of the Cisco License On-Prem vulnerabilities can be exploited without an attacker first authenticating to the system.

CVE-2026-20328, for example, can allow unauthorised access. Another flaw, CVE-2026-76454, can cause denial-of-service conditions. Other vulnerabilities addressed in the same product could expose credentials or bypass security controls.

Continue reading

Watch a short ad to unlock the full article

The rest stays locked if you skip or close the ad early.

Article text via FreeNewsAPI. Rights remain with The420.in.

Read on publisher site → Opens The420.in in a new tab

More in Local