Cisco Patches 35 Vulnerabilities as Critical Nexus Bugs Allow Root Access
Cisco has released a major security update fixing 35 vulnerabilities across several widely used networking and enterprise products, including more than a dozen flaws rated critical. The affected products include Cisco NX-OS, Meraki devices, License On-Prem and the Application Policy Infrastructure Controller, or APIC. Some of the most serious weaknesses could allow
Cisco has released a major security update fixing 35 vulnerabilities across several widely used networking and enterprise products, including more than a dozen flaws rated critical. The affected products include Cisco NX-OS, Meraki devices, License On-Prem and the Application Policy Infrastructure Controller, or APIC.
Some of the most serious weaknesses could allow unauthenticated attackers to execute code with root privileges, gain unauthorised access or crash affected systems remotely. Cisco says it has not seen evidence that the newly disclosed vulnerabilities are being exploited in real-world attacks.
FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals NX-OS Receives Major Security Fixes A large portion of the critical vulnerabilities affect Cisco NX-OS, the operating system used across several Cisco switches and data-centre networking products. Cisco released fixes for 14 NX-OS vulnerabilities in the October security batch.
Several of the flaws involve improper access controls, memory errors and input-validation weaknesses. Cisco grouped multiple internally discovered weaknesses into individual CVEs based on their underlying vulnerability class as part of its newer security disclosure process. The affected environments include MDS 9000 switches, Nexus 3000, Nexus 7000 and Nexus 9000 series devices, Nexus systems operating in ACI mode and certain UCS Fabric Interconnects.
Some Nexus Flaws Allow Root-Level Code Execution Among the most serious issues are vulnerabilities affecting the Next Generation Operations, Administration and Maintenance feature in Cisco NX-OS. The feature, commonly known as NGOAM, is used for monitoring and troubleshooting network connectivity.
Cisco says multiple flaws affecting NGOAM can allow an unauthenticated attacker to send specially crafted network traffic to a vulnerable device. A successful attack could allow arbitrary code to run with root privileges or trigger crashes that result in a denial-of-service condition.
The vulnerabilities are tracked as CVE-2026-76485, CVE-2026-76486 and CVE-2026-76501. They affect certain Nexus 3000 and Nexus 9000 switches when the vulnerable NGOAM functionality is enabled. Cisco has assigned them a maximum CVSS severity score of 9.8.
No Workaround for Critical Nexus Bugs Cisco says there are no workarounds that fully address the NGOAM vulnerabilities. Organisations therefore need to install the fixed NX-OS releases. This is important for data centres because Nexus switches can sit at the centre of critical network infrastructure.
A compromise with root-level access could potentially give an attacker extensive control over an affected networking device. Cisco has not reported malicious exploitation of these vulnerabilities so far. Cisco License On-Prem Also Hit by Critical Flaws Another major group of vulnerabilities affects Cisco License On-Prem, previously known as Cisco Smart Software Manager On-Prem.
The platform allows organisations to manage Cisco software licences inside their own infrastructure instead of relying entirely on cloud-based licensing services. Cisco patched several critical weaknesses in the product during the October release. One security-hardening advisory carries a maximum CVSS score of 10.0, the highest possible rating.
The vulnerabilities involve weaknesses such as missing authentication, insufficient protection of credentials, improper cryptographic signature verification and code execution. Attackers May Not Need Credentials Some of the Cisco License On-Prem vulnerabilities can be exploited without an attacker first authenticating to the system.
CVE-2026-20328, for example, can allow unauthorised access. Another flaw, CVE-2026-76454, can cause denial-of-service conditions. Other vulnerabilities addressed in the same product could expose credentials or bypass security controls.
Continue reading
Watch a short ad to unlock the full article
The rest stays locked if you skip or close the ad early.
Because licensing systems can have administrative relationships with other enterprise infrastructure, unauthorised access to them could create broader security risks. Meraki Devices Receive Security Hardening Update Cisco also released a major security-hardening update for Meraki products.
The affected devices include Meraki Campus Gateways, cellular gateways, wireless access points, switches, smart cameras and MX Security and SD-WAN appliances. Cisco grouped the underlying security weaknesses into seven CVEs. The most serious, CVE-2026-76464, has a CVSS score of 9.6 and involves memory-safety problems including buffer overflows and out-of-bounds writes.
Other Meraki vulnerabilities involve access-control weaknesses, input validation, command injection, calculation errors and resource-handling problems. Cisco says these vulnerabilities were discovered internally and are not known to have been exploited. Some Meraki Fixes Are Still Being Rolled Out Not every fixed Meraki release is immediately available across all product lines.
Cisco says some releases are scheduled for later in October or November. For example, fixed versions for certain Campus Gateway and switch branches are planned for later rollout dates. Administrators therefore need to check the exact device model and software branch rather than assuming a single update covers every Meraki product.
Cisco recommends moving to the fixed version specified for each affected release. APIC Vulnerabilities Reach CVSS 9.8 Cisco also patched three critical vulnerabilities in its Application Policy Infrastructure Controller. APIC is a central management platform used in Cisco Application Centric Infrastructure environments.
The flaws are tracked as CVE-2026-76498, CVE-2026-76499 and CVE-2026-76500. They cover improper access control, command or operating-system injection, and memory or resource-management weaknesses. Each vulnerability carries a maximum CVSS score of 9.8.
Cisco says affected APIC installations are vulnerable regardless of their configuration. There are no workarounds, making software upgrades the recommended remediation. AI Helped Find Some of the Bugs The October release also reflects a change in how Cisco is finding vulnerabilities.
Cisco says some of the flaws uncovered during its internal reviews were identified using existing security-testing processes alongside frontier AI models. The company has been changing its disclosure process partly in response to the increasing speed at which AI tools can identify software weaknesses.
Instead of issuing a separate advisory for every underlying defect, Cisco may group multiple related bugs under one CVE when they share the same vulnerability class. That means the number of CVEs does not necessarily represent the total number of individual coding defects fixed. Finesse Flaw Was Publicly Disclosed Cisco also patched a high-severity server-side request forgery vulnerability in Cisco Finesse.
Tracked as CVE-2026-20362, the flaw affects the product’s web-based management interface. An unauthenticated remote attacker could potentially send specially crafted HTTP requests through an affected system. Unlike the newly disclosed critical issues, the Finesse vulnerability had already been publicly disclosed.
Cisco has not reported active exploitation of it. Cisco Says No New Flaws Are Being Exploited The company says it is not aware of malicious exploitation involving the vulnerabilities included in the October 7 advisories. That is an important distinction from a separate Cisco Catalyst SD-WAN vulnerability disclosed recently.
That flaw, CVE-2026-76504, was already being exploited as a zero-day when Cisco released its patch. The new October patch batch should therefore not be described as an emergency response to confirmed attacks. However, the presence of remotely exploitable critical vulnerabilities means enterprises still need to prioritise updates.
Network Devices Are High-Value Targets Cisco switches, controllers and network-management products frequently sit deep inside enterprise infrastructure. They can handle traffic between servers, users, cloud services and data-centre systems. That makes vulnerabilities in these products particularly valuable to attackers.
A compromised endpoint may expose one computer. A compromised network controller or switch can potentially provide a much broader view of an organisation’s infrastructure. This is why vulnerabilities that provide root privileges or bypass authentication deserve immediate attention even when active exploitation has not yet been observed.
No Workarounds Increase Patching Pressure Several of Cisco’s critical advisories explicitly say there are no available workarounds. Administrators cannot fully remove the risk through a configuration change alone. Cisco is recommending that customers move to fixed software releases.
Organisations should first identify which affected Cisco products are deployed, confirm their current software versions and then compare them with Cisco’s fixed-release guidance. For large enterprises, that can be a significant task because Cisco equipment may be distributed across offices, data centres and branch networks.
What this means for you If your organisation runs Cisco Nexus, Meraki, APIC or License On-Prem products, administrators should check the October 7 Cisco advisories and install the appropriate fixed releases. Cisco has not reported active exploitation of these flaws, but several can be attacked remotely without authentication and some have no workaround other than upgrading.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics
Article text via FreeNewsAPI. Rights remain with The420.in.
Read on publisher site → Opens The420.in in a new tab