Threat reportVulnerabilityTL-2026-3108
Cisco October 2026 Security Advisories: Critical Flaws in Meraki, License (SSM) On-Prem, NX-OS, APIC and Finesse (CVE-2026-76464, CVE-2026-20328, CVE-2026-76485 and others)
Cisco October 2026 Security Advisories (TL-2026-3108), also tracked as Cisco October 2026 Security Advisory Bundle, is a critical-severity software vulnerability scored CVSS 10, first published 2026-10-09. It has no confirmed attribution, affects Cisco License (Smart Software Manager) On-Prem, references 35 CVEs (CVE-2026-76464, CVE-2026-76463, CVE-2026-76467), maps to 9 MITRE ATT&CK techniques (T1005, T1059, T1059.006), and is covered by 9 detection rules and 18 indicators of compromise.
- CVSS
- 10/10Critical
- CVEs
- 35Referenced vulnerabilities
- Techniques
- 9MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 18Indicators of compromise
Key facts for TL-2026-3108
- Threat ID
- TL-2026-3108
- Also known as
- Cisco October 2026 Security Advisory Bundle
- Severity
- CRITICAL
- CVSS
- 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- enterprise, telecoms, data-center, government administration, finance, contact-center
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 18
- Updates
- 2026-10-09 · revalidated 1× · latest source
How Cisco October 2026 Security Advisories works
On October 7, 2026 Cisco published advisories covering 35 vulnerabilities, including over a dozen rated critical, across Meraki, License (Smart Software Manager) On-Prem, NX-OS (Nexus 3000/9000), APIC and Finesse. Cisco says it is not aware of exploitation in the wild; the Finesse SSRF (CVE-2026-20362) has been publicly announced.
Cisco's October 2026 advisory cycle (published 2026-10-07, reported by SecurityWeek on 2026-10-08) fixes 35 vulnerabilities across network-infrastructure and contact-center products. Cisco PSIRT states it is not aware of malicious exploitation of any of them. This record covers the critical and high issues; no network or file IOCs exist because there is no observed exploitation.
Cisco License (Smart Software Manager) On-Prem: the SSM On-Prem advisories carry a top score of CVSS 10.0. Reported issues include an unauthenticated arbitrary account password reset caused by improper checks in the reset process (CVE-2026-20328, CVSS 9.1, CWE-862), an unauthenticated API flaw permitting file writes (path traversal, CWE-23) or denial of service (CVE-2026-76454, CVSS 9.1), and the hardening-release issues CVE-2026-76480, CVE-2026-76482 (reported at CVSS 10.0, CWE-347 improper cryptographic signature verification), CVE-2026-76483 (insufficiently protected credentials) and CVE-2026-76484. Two admin-only issues, command injection executing as root (CVE-2026-76437) and SQL injection (CVE-2026-76452), score 4.9. Secondary reporting disagrees on which of CVE-2026-76480/76482 is the missing-authentication flaw (CWE-306) and which is the signature-verification flaw (CWE-347); consult the Cisco advisory per CVE. No workaround exists; the fixed release is 10-202608 or later (10-202609 confirmed not vulnerable), and 9.x deployments must migrate.
Cisco NX-OS: 14 vulnerabilities, 7 critical. NGOAM flaws (CVE-2026-76485, CVE-2026-76486, CVE-2026-76501; CVSS 9.8, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, CWE-121 stack-based buffer overflow) stem from improper input validation of IP traffic when the NGOAM feature is enabled on Nexus 3000 and 9000 (standalone NX-OS mode) switches, allowing unauthenticated remote code execution as root or denial of service. NGOAM status can be checked with 'show feature | include ngoam'; the mitigation is 'no feature ngoam' or a Live Protect shield. CVE-2026-76471 (NX-API, CVSS 9.8, CWE-122 heap-based overflow) is an unauthenticated crafted-HTTP-request flaw on Nexus 3000/9000 when NX-API is enabled (disabled by default there; enabled by default on UCS 6300, where valid low-privileged credentials are needed; fixed in UCS 6300 4.3(6j)). CVE-2026-76465 is an MPLS OAM remote code execution flaw (CVSS 9.8). The NX-OS hardening release (CVE-2026-76455, 76459, 76456, 76457, 76458, 76453; CVSS 9.8) covers improper access control and out-of-bounds writes.
Cisco APIC: the hardening release fixes CVE-2026-76498 (improper access control, CWE-284), CVE-2026-76499 (OS injection / improper neutralization, CWE-707) and CVE-2026-76500 (improper resource control, CWE-664), each CVSS 9.8, fixed in 6.0(9h), 6.1(6g) and 6.2(3g) with no workarounds.
Cisco Meraki: the security hardening release covers seven CVEs (CVE-2026-76463, 76464, 76467, 76468, 76469, 76470, 76472) across Campus Gateways, MG cellular gateways, MR access points, MS switches, MV cameras and MX appliances. The worst, CVE-2026-76464 (CVSS 9.6, CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, CWE-119), is a memory-corruption/buffer-overflow issue reachable from an adjacent network. Sample fixed versions: MX 26.1.7 / 26.2.3, MR 30.7.3 / 33.1.3, Campus Gateway 32.2.5 (late Oct 2026). No workarounds.
Cisco Finesse: CVE-2026-20362 is a server-side request forgery in the web management interface (CVSS 7.2 High, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N, CWE-918) reachable with a crafted HTTP request and exposing information from associated services. Cisco PSIRT is aware of a public announcement. Affected: Finesse 12.6 and earlier and 15.0; Packaged/Unified CCE earlier than 15.0 and 15.0; Unified CCX 12.5 and earlier and 15.0. Fixes are scheduled (Finesse 15.0(1) SU3 Feb 2027, CCE 15.0(1)ES202701 Jan 2027, CCX 15.0(1) SU2 Feb 2027); no workaround.
Defender guidance: although unexploited, these are unauthenticated, network-reachable flaws in management-plane and data-center fabric controllers, which historically attract rapid reverse engineering of patches. Prioritize upgrading SSM On-Prem, NX-OS with NGOAM/NX-API enabled, and APIC, restrict management-plane exposure, and monitor for the behaviors listed in the IOC section.
MITRE ATT&CK techniques used in TL-2026-3108
Collection
Execution
T1059 Command and Scripting Interpreter; T1059.006 Command and Scripting Interpreter: Python
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Persistence
Initial Access
T1190 Exploit Public-Facing Application
Impact
T1499.004 Endpoint Denial of Service: Application or System Exploitation
Credential Access
Defense Evasion
Affected products and versions in Cisco October 2026 Security Advisories
- Cisco — License (Smart Software Manager) On-Prem
Vulnerable versions: all releases prior to 10-202608; 9.x
Fixed in: 10-202608 and later; 10-202609 - Cisco — NX-OS (Nexus 3000/9000 standalone mode; UCS 6300 for NX-API)
Vulnerable versions: releases with NGOAM, NX-API or MPLS OAM exposure; see Cisco Software Checker
Fixed in: UCS 6300 4.3(6j); Nexus per Cisco Software Checker - Cisco — Application Policy Infrastructure Controller (APIC)
Vulnerable versions: releases prior to 6.0(9h), 6.1(6g), 6.2(3g)
Fixed in: 6.0(9h); 6.1(6g); 6.2(3g) - Cisco — Meraki (Campus Gateway, MG, MR, MS, MV, MX)
Vulnerable versions: MX 26.1 before 26.1.7; MR 30.7 before 30.7.3; Campus Gateway 32.2 before 32.2.5
Fixed in: MX 26.1.7 / 26.2.3; MR 30.7.3 / 33.1.3; Campus Gateway 32.2.5 - Cisco — Finesse / Packaged CCE / Unified CCE / Unified CCX
Vulnerable versions: Finesse 12.6 and earlier, 15.0; CCE earlier than 15.0, 15.0; CCX 12.5 and earlier, 15.0
Fixed in: Finesse 15.0(1) SU3; CCE 15.0(1)ES202701; CCX 15.0(1) SU2
Remediation for Cisco October 2026 Security Advisories
Patches
- SSM On-Prem 10-202608 / 10-202609
- APIC 6.0(9h), 6.1(6g), 6.2(3g)
- Meraki MX 26.1.7 / 26.2.3, MR 30.7.3 / 33.1.3, Campus Gateway 32.2.5
- UCS 6300 4.3(6j); Nexus 3000/9000 per Cisco Software Checker
- Finesse 15.0(1) SU3, CCE 15.0(1)ES202701, CCX 15.0(1) SU2 (scheduled Jan-Feb 2027)
Immediate actions
- Upgrade Cisco License (SSM) On-Prem to release 10-202608 or later (9.x must migrate)
- On Nexus 3000/9000 run 'show feature | include ngoam' and 'show feature | include nxapi'; disable unneeded features with 'no feature ngoam'
- Restrict management-plane and NX-API/NGOAM reachability to trusted management networks
- Upgrade APIC to 6.0(9h), 6.1(6g) or 6.2(3g)
Workarounds
- NGOAM: 'no feature ngoam' or Live Protect shield (temporary, not a full fix)
- NX-API: Live Protect shield pending upgrade
- No workarounds exist for SSM On-Prem, APIC, Meraki hardening or Finesse SSRF
Longer-term hardening
- Use the Cisco Software Checker to map every NX-OS release to its fixed version
- Segment Meraki adjacent-network (Layer 2) exposure and monitor firmware compliance
- Subscribe to Cisco PSIRT notifications and track KEV for later exploitation of these CVEs
CVEs associated with Cisco October 2026 Security Advisories
- CVE-2026-76464
- CVE-2026-76463
- CVE-2026-76467
- CVE-2026-76468
- CVE-2026-76469
- CVE-2026-76470
- CVE-2026-76472
- CVE-2026-20328
- CVE-2026-76454
- CVE-2026-76482
- CVE-2026-76480
- CVE-2026-76483
- CVE-2026-76484
- CVE-2026-76437
- CVE-2026-76452
- CVE-2026-76455
- CVE-2026-76459
- CVE-2026-76456
- CVE-2026-76457
- CVE-2026-76458
- CVE-2026-76453
- CVE-2026-76471
- CVE-2026-76465
- CVE-2026-76485
- CVE-2026-76486
- CVE-2026-76501
- CVE-2026-76498
- CVE-2026-76499
- CVE-2026-76500
- CVE-2026-20362
- CVE-2026-20032
- CVE-2026-20038
- CVE-2026-20173
- CVE-2026-20321
- CVE-2026-76488
Weaknesses (CWE) in Cisco October 2026 Security Advisories
CWE-119, CWE-121, CWE-122, CWE-23, CWE-284, CWE-306, CWE-347, CWE-664, CWE-707, CWE-78
Timeline of Cisco October 2026 Security Advisories
- SSM On-Prem fixed in release 10-202608 and later; 10-202609 confirmed not vulnerable. No workarounds.
- Cisco notes a public announcement exists for the Finesse SSRF (CVE-2026-20362); no malicious exploitation confirmed.
- Cisco PSIRT publishes the October 2026 advisories covering Meraki, SSM On-Prem, NX-OS, APIC and Finesse.
- GovCERT.HK publishes alert A26-10-14 consolidating the 14 Cisco advisories of 2026-10-07 and urging administrators to apply vendor patches.
- SecurityWeek reports 35 vulnerabilities patched, including over a dozen critical; Cisco is not aware of exploitation in the wild.
- Threadlinqs analysis of the advisory bundle completed; no IOCs or exploitation observed.
- Campus Gateway 32.2.5 fix scheduled for late October 2026 per Cisco hardening advisory (approximate date).
- Fixes for Finesse SSRF scheduled: CCE 15.0(1)ES202701 in Jan 2027, Finesse 15.0(1) SU3 and CCX 15.0(1) SU2 in Feb 2027 (approximate).
Update history for TL-2026-3108
- 2026-10-09 — Multiple Vulnerabilities in Cisco Products: APIC, NX-OS (Nexus/MDS/UCS), License On-Prem (SSM), Meraki, Finesse/CCE/CCX (GovCERT.HK A26-10-14): What changed No severity, exploitability, CVSS or status change; both reports agree on CRITICAL / NONE (no known exploitation). Scope widened: additional advisories and affected platforms (Nexus 7000, MDS 9000, UCS fabric interconnects, Nex
Sources cited for Cisco October 2026 Security Advisories
- Cisco Patches a Dozen Critical Vulnerabilities (SecurityWeek)
- Cisco Advance Notification for Publication of October 7, 2026 Security Advisories
- Cisco Meraki Security Hardening Release: October 2026
- Cisco NX-OS NGOAM Remote Code Execution Vulnerabilities
- Cisco NX-OS NX-API Remote Code Execution Vulnerability
- Cisco SSM On-Prem Vulnerabilities
- Cisco Finesse Server-Side Request Forgery Vulnerability
- Cisco Fixes CVSS 10 License On-Prem Flaw and Ships Hardening Releases for APIC and Meraki (SecurityOnline)
- Cisco Patches 35 Vulnerabilities as Critical Nexus Bugs Allow Root Access (The420.in)
Detection coverage for TL-2026-3108
As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3108 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.