THE CRUNCH
Cisco has released patches for 35 vulnerabilities across its product range, including more than a dozen rated critical severity. The batch covers Meraki networking gear, NX-OS switch software, License On-Prem and the Application Policy Infrastructure Controller (APIC), with flaws that could allow unauthorised access, information leaks, privilege escalation, denial-of-service attacks and remote code execution. The company says it is not aware of any of the bugs being exploited in the wild.
The most serious issues sit in NX-OS, which received fixes for 14 vulnerabilities, seven of them critical. Two bugs, tracked as CVE-2026-76471 and CVE-2026-76465, could let remote, unauthenticated attackers run arbitrary code with root privileges or trigger a denial-of-service condition. Three further NX-OS flaws only affect Nexus 3000 and Nexus 9000 switches with Next Generation OAM (NGOAM) enabled.
License On-Prem picked up fixes for eight bugs, five of them critical, including two exploitable without authentication. Meraki's new security hardening release addresses issues grouped under seven CVEs, led by memory problems such as buffer overflows and out-of-bounds writes, while APIC received patches for three critical flaws covering improper access control, OS injection and memory issues.
The update also resolves a high-severity server-side request forgery (SSRF) flaw in Finesse, tracked as CVE-2026-20362, which has been publicly disclosed. Cisco says it is not aware of any of these vulnerabilities being exploited in the wild.


