Threat reportVulnerabilityTL-2026-3108

Cisco October 2026 Security Advisories: Critical Flaws in Meraki, License (SSM) On-Prem, NX-OS, APIC and Finesse (CVE-2026-76464, CVE-2026-20328, CVE-2026-76485 and others)

criticalPATCHED

Cisco October 2026 Security Advisories (TL-2026-3108), also tracked as Cisco October 2026 Security Advisory Bundle, is a critical-severity software vulnerability scored CVSS 10, first published 2026-10-09. It has no confirmed attribution, affects Cisco License (Smart Software Manager) On-Prem, references 35 CVEs (CVE-2026-76464, CVE-2026-76463, CVE-2026-76467), maps to 9 MITRE ATT&CK techniques (T1005, T1059, T1059.006), and is covered by 9 detection rules and 18 indicators of compromise.

CVSS
10/10Critical
CVEs
35Referenced vulnerabilities
Techniques
9MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
18Indicators of compromise

Key facts for TL-2026-3108

Threat ID
TL-2026-3108
Also known as
Cisco October 2026 Security Advisory Bundle
Severity
CRITICAL
CVSS
10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
enterprise, telecoms, data-center, government administration, finance, contact-center
Target regions
Global
Detection rules
9
Indicators of compromise
18
Updates
2026-10-09 · revalidated 1× · latest source

How Cisco October 2026 Security Advisories works

On October 7, 2026 Cisco published advisories covering 35 vulnerabilities, including over a dozen rated critical, across Meraki, License (Smart Software Manager) On-Prem, NX-OS (Nexus 3000/9000), APIC and Finesse. Cisco says it is not aware of exploitation in the wild; the Finesse SSRF (CVE-2026-20362) has been publicly announced.

Cisco's October 2026 advisory cycle (published 2026-10-07, reported by SecurityWeek on 2026-10-08) fixes 35 vulnerabilities across network-infrastructure and contact-center products. Cisco PSIRT states it is not aware of malicious exploitation of any of them. This record covers the critical and high issues; no network or file IOCs exist because there is no observed exploitation.

Cisco License (Smart Software Manager) On-Prem: the SSM On-Prem advisories carry a top score of CVSS 10.0. Reported issues include an unauthenticated arbitrary account password reset caused by improper checks in the reset process (CVE-2026-20328, CVSS 9.1, CWE-862), an unauthenticated API flaw permitting file writes (path traversal, CWE-23) or denial of service (CVE-2026-76454, CVSS 9.1), and the hardening-release issues CVE-2026-76480, CVE-2026-76482 (reported at CVSS 10.0, CWE-347 improper cryptographic signature verification), CVE-2026-76483 (insufficiently protected credentials) and CVE-2026-76484. Two admin-only issues, command injection executing as root (CVE-2026-76437) and SQL injection (CVE-2026-76452), score 4.9. Secondary reporting disagrees on which of CVE-2026-76480/76482 is the missing-authentication flaw (CWE-306) and which is the signature-verification flaw (CWE-347); consult the Cisco advisory per CVE. No workaround exists; the fixed release is 10-202608 or later (10-202609 confirmed not vulnerable), and 9.x deployments must migrate.

Cisco NX-OS: 14 vulnerabilities, 7 critical. NGOAM flaws (CVE-2026-76485, CVE-2026-76486, CVE-2026-76501; CVSS 9.8, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, CWE-121 stack-based buffer overflow) stem from improper input validation of IP traffic when the NGOAM feature is enabled on Nexus 3000 and 9000 (standalone NX-OS mode) switches, allowing unauthenticated remote code execution as root or denial of service. NGOAM status can be checked with 'show feature | include ngoam'; the mitigation is 'no feature ngoam' or a Live Protect shield. CVE-2026-76471 (NX-API, CVSS 9.8, CWE-122 heap-based overflow) is an unauthenticated crafted-HTTP-request flaw on Nexus 3000/9000 when NX-API is enabled (disabled by default there; enabled by default on UCS 6300, where valid low-privileged credentials are needed; fixed in UCS 6300 4.3(6j)). CVE-2026-76465 is an MPLS OAM remote code execution flaw (CVSS 9.8). The NX-OS hardening release (CVE-2026-76455, 76459, 76456, 76457, 76458, 76453; CVSS 9.8) covers improper access control and out-of-bounds writes.

Cisco APIC: the hardening release fixes CVE-2026-76498 (improper access control, CWE-284), CVE-2026-76499 (OS injection / improper neutralization, CWE-707) and CVE-2026-76500 (improper resource control, CWE-664), each CVSS 9.8, fixed in 6.0(9h), 6.1(6g) and 6.2(3g) with no workarounds.

Cisco Meraki: the security hardening release covers seven CVEs (CVE-2026-76463, 76464, 76467, 76468, 76469, 76470, 76472) across Campus Gateways, MG cellular gateways, MR access points, MS switches, MV cameras and MX appliances. The worst, CVE-2026-76464 (CVSS 9.6, CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, CWE-119), is a memory-corruption/buffer-overflow issue reachable from an adjacent network. Sample fixed versions: MX 26.1.7 / 26.2.3, MR 30.7.3 / 33.1.3, Campus Gateway 32.2.5 (late Oct 2026). No workarounds.

Cisco Finesse: CVE-2026-20362 is a server-side request forgery in the web management interface (CVSS 7.2 High, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N, CWE-918) reachable with a crafted HTTP request and exposing information from associated services. Cisco PSIRT is aware of a public announcement. Affected: Finesse 12.6 and earlier and 15.0; Packaged/Unified CCE earlier than 15.0 and 15.0; Unified CCX 12.5 and earlier and 15.0. Fixes are scheduled (Finesse 15.0(1) SU3 Feb 2027, CCE 15.0(1)ES202701 Jan 2027, CCX 15.0(1) SU2 Feb 2027); no workaround.

Defender guidance: although unexploited, these are unauthenticated, network-reachable flaws in management-plane and data-center fabric controllers, which historically attract rapid reverse engineering of patches. Prioritize upgrading SSM On-Prem, NX-OS with NGOAM/NX-API enabled, and APIC, restrict management-plane exposure, and monitor for the behaviors listed in the IOC section.

MITRE ATT&CK techniques used in TL-2026-3108

Collection

T1005 Data from Local System

Execution

T1059 Command and Scripting Interpreter; T1059.006 Command and Scripting Interpreter: Python

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Persistence

T1098 Account Manipulation

Initial Access

T1190 Exploit Public-Facing Application

Impact

T1499.004 Endpoint Denial of Service: Application or System Exploitation

Credential Access

T1552 Unsecured Credentials

Defense Evasion

T1599 Network Boundary Bridging

Affected products and versions in Cisco October 2026 Security Advisories

  • Cisco — License (Smart Software Manager) On-Prem
    Vulnerable versions: all releases prior to 10-202608; 9.x
    Fixed in: 10-202608 and later; 10-202609
  • Cisco — NX-OS (Nexus 3000/9000 standalone mode; UCS 6300 for NX-API)
    Vulnerable versions: releases with NGOAM, NX-API or MPLS OAM exposure; see Cisco Software Checker
    Fixed in: UCS 6300 4.3(6j); Nexus per Cisco Software Checker
  • Cisco — Application Policy Infrastructure Controller (APIC)
    Vulnerable versions: releases prior to 6.0(9h), 6.1(6g), 6.2(3g)
    Fixed in: 6.0(9h); 6.1(6g); 6.2(3g)
  • Cisco — Meraki (Campus Gateway, MG, MR, MS, MV, MX)
    Vulnerable versions: MX 26.1 before 26.1.7; MR 30.7 before 30.7.3; Campus Gateway 32.2 before 32.2.5
    Fixed in: MX 26.1.7 / 26.2.3; MR 30.7.3 / 33.1.3; Campus Gateway 32.2.5
  • Cisco — Finesse / Packaged CCE / Unified CCE / Unified CCX
    Vulnerable versions: Finesse 12.6 and earlier, 15.0; CCE earlier than 15.0, 15.0; CCX 12.5 and earlier, 15.0
    Fixed in: Finesse 15.0(1) SU3; CCE 15.0(1)ES202701; CCX 15.0(1) SU2

Remediation for Cisco October 2026 Security Advisories

Patches

  • SSM On-Prem 10-202608 / 10-202609
  • APIC 6.0(9h), 6.1(6g), 6.2(3g)
  • Meraki MX 26.1.7 / 26.2.3, MR 30.7.3 / 33.1.3, Campus Gateway 32.2.5
  • UCS 6300 4.3(6j); Nexus 3000/9000 per Cisco Software Checker
  • Finesse 15.0(1) SU3, CCE 15.0(1)ES202701, CCX 15.0(1) SU2 (scheduled Jan-Feb 2027)

Immediate actions

  • Upgrade Cisco License (SSM) On-Prem to release 10-202608 or later (9.x must migrate)
  • On Nexus 3000/9000 run 'show feature | include ngoam' and 'show feature | include nxapi'; disable unneeded features with 'no feature ngoam'
  • Restrict management-plane and NX-API/NGOAM reachability to trusted management networks
  • Upgrade APIC to 6.0(9h), 6.1(6g) or 6.2(3g)

Workarounds

  • NGOAM: 'no feature ngoam' or Live Protect shield (temporary, not a full fix)
  • NX-API: Live Protect shield pending upgrade
  • No workarounds exist for SSM On-Prem, APIC, Meraki hardening or Finesse SSRF

Longer-term hardening

  • Use the Cisco Software Checker to map every NX-OS release to its fixed version
  • Segment Meraki adjacent-network (Layer 2) exposure and monitor firmware compliance
  • Subscribe to Cisco PSIRT notifications and track KEV for later exploitation of these CVEs

CVEs associated with Cisco October 2026 Security Advisories

Weaknesses (CWE) in Cisco October 2026 Security Advisories

CWE-119, CWE-121, CWE-122, CWE-23, CWE-284, CWE-306, CWE-347, CWE-664, CWE-707, CWE-78

Timeline of Cisco October 2026 Security Advisories

  • SSM On-Prem fixed in release 10-202608 and later; 10-202609 confirmed not vulnerable. No workarounds.
  • Cisco notes a public announcement exists for the Finesse SSRF (CVE-2026-20362); no malicious exploitation confirmed.
  • Cisco PSIRT publishes the October 2026 advisories covering Meraki, SSM On-Prem, NX-OS, APIC and Finesse.
  • GovCERT.HK publishes alert A26-10-14 consolidating the 14 Cisco advisories of 2026-10-07 and urging administrators to apply vendor patches.
  • SecurityWeek reports 35 vulnerabilities patched, including over a dozen critical; Cisco is not aware of exploitation in the wild.
  • Threadlinqs analysis of the advisory bundle completed; no IOCs or exploitation observed.
  • Campus Gateway 32.2.5 fix scheduled for late October 2026 per Cisco hardening advisory (approximate date).
  • Fixes for Finesse SSRF scheduled: CCE 15.0(1)ES202701 in Jan 2027, Finesse 15.0(1) SU3 and CCX 15.0(1) SU2 in Feb 2027 (approximate).

Update history for TL-2026-3108

Sources cited for Cisco October 2026 Security Advisories

Detection coverage for TL-2026-3108

As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3108 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
18 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats