# Cisco October 2026 Security Advisories: Critical Flaws in Meraki, License (SSM) On-Prem, NX-OS, APIC and Finesse (CVE-2026-76464, CVE-2026-20328, CVE-2026-76485 and others)

> On October 7, 2026 Cisco published advisories covering 35 vulnerabilities, including over a dozen rated critical, across Meraki, License (Smart Software Manager) On-Prem, NX-OS (Nexus 3000/9000), APIC and Finesse. Cisco says it is not aware of exploitation in the wild; the Finesse SSRF (CVE-2026-20362) has been publicly announced.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-09T14:05:08.687Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3108
- **ID:** TL-2026-3108
- **Severity:** CRITICAL (CVSS 10)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 18 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-76464, CVE-2026-76463, CVE-2026-76467, CVE-2026-76468, CVE-2026-76469, CVE-2026-76470, CVE-2026-76472, CVE-2026-20328, CVE-2026-76454, CVE-2026-76482, CVE-2026-76480, CVE-2026-76483, CVE-2026-76484, CVE-2026-76437, CVE-2026-76452, CVE-2026-76455, CVE-2026-76459, CVE-2026-76456, CVE-2026-76457, CVE-2026-76458, CVE-2026-76453, CVE-2026-76471, CVE-2026-76465, CVE-2026-76485, CVE-2026-76486, CVE-2026-76501, CVE-2026-76498, CVE-2026-76499, CVE-2026-76500, CVE-2026-20362, CVE-2026-20032, CVE-2026-20038, CVE-2026-20173, CVE-2026-20321, CVE-2026-76488

## Description

Cisco's October 2026 advisory cycle (published 2026-10-07, reported by SecurityWeek on 2026-10-08) fixes 35 vulnerabilities across network-infrastructure and contact-center products. Cisco PSIRT states it is not aware of malicious exploitation of any of them. This record covers the critical and high issues; no network or file IOCs exist because there is no observed exploitation.

Cisco License (Smart Software Manager) On-Prem: the SSM On-Prem advisories carry a top score of CVSS 10.0. Reported issues include an unauthenticated arbitrary account password reset caused by improper checks in the reset process (CVE-2026-20328, CVSS 9.1, CWE-862), an unauthenticated API flaw permitting file writes (path traversal, CWE-23) or denial of service (CVE-2026-76454, CVSS 9.1), and the hardening-release issues CVE-2026-76480, CVE-2026-76482 (reported at CVSS 10.0, CWE-347 improper cryptographic signature verification), CVE-2026-76483 (insufficiently protected credentials) and CVE-2026-76484. Two admin-only issues, command injection executing as root (CVE-2026-76437) and SQL injection (CVE-2026-76452), score 4.9. Secondary reporting disagrees on which of CVE-2026-76480/76482 is the missing-authentication flaw (CWE-306) and which is the signature-verification flaw (CWE-347); consult the Cisco advisory per CVE. No workaround exists; the fixed release is 10-202608 or later (10-202609 confirmed not vulnerable), and 9.x deployments must migrate.

Cisco NX-OS: 14 vulnerabilities, 7 critical. NGOAM flaws (CVE-2026-76485, CVE-2026-76486, CVE-2026-76501; CVSS 9.8, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, CWE-121 stack-based buffer overflow) stem from improper input validation of IP traffic when the NGOAM feature is enabled on Nexus 3000 and 9000 (standalone NX-OS mode) switches, allowing unauthenticated remote code execution as root or denial of service. NGOAM status can be checked with 'show feature | include ngoam'; the mitigation is 'no feature ngoam' or a Live Protect shield. CVE-2026-76471 (NX-API, CVSS 9.8, CWE-122 heap-based overflow) is an unauthenticated crafted-HTTP-request flaw on Nexus 3000/9000 when NX-API is enabled (disabled by default there; enabled by default on UCS 6300, where valid low-privileged credentials are needed; fixed in UCS 6300 4.3(6j)). CVE-2026-76465 is an MPLS OAM remote code execution flaw (CVSS 9.8). The NX-OS hardening release (CVE-2026-76455, 76459, 76456, 76457, 76458, 76453; CVSS 9.8) covers improper access control and out-of-bounds writes.

Cisco APIC: the hardening release fixes CVE-2026-76498 (improper access control, CWE-284), CVE-2026-76499 (OS injection / improper neutralization, CWE-707) and CVE-2026-76500 (improper resource control, CWE-664), each CVSS 9.8, fixed in 6.0(9h), 6.1(6g) and 6.2(3g) with no workarounds.

Cisco Meraki: the security hardening release covers seven CVEs (CVE-2026-76463, 76464, 76467, 76468, 76469, 76470, 76472) across Campus Gateways, MG cellular gateways, MR access points, MS switches, MV cameras and MX appliances. The worst, CVE-2026-76464 (CVSS 9.6, CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, CWE-119), is a memory-corruption/buffer-overflow issue reachable from an adjacent network. Sample fixed versions: MX 26.1.7 / 26.2.3, MR 30.7.3 / 33.1.3, Campus Gateway 32.2.5 (late Oct 2026). No workarounds.

Cisco Finesse: CVE-2026-20362 is a server-side request forgery in the web management interface (CVSS 7.2 High, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N, CWE-918) reachable with a crafted HTTP request and exposing information from associated services. Cisco PSIRT is aware of a public announcement. Affected: Finesse 12.6 and earlier and 15.0; Packaged/Unified CCE earlier than 15.0 and 15.0; Unified CCX 12.5 and earlier and 15.0. Fixes are scheduled (Finesse 15.0(1) SU3 Feb 2027, CCE 15.0(1)ES202701 Jan 2027, CCX 15.0(1) SU2 Feb 2027); no workaround.

Defender guidance: although unexploited, these are unauthenticated, network-reachable flaws in management-plane and data-center fabric controllers, which historically attract rapid reverse engineering of patches. Prioritize upgrading SSM On-Prem, NX-OS with NGOAM/NX-API enabled, and APIC, restrict management-plane exposure, and monitor for the behaviors listed in the IOC section.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1098 Account Manipulation
- T1552 Unsecured Credentials
- T1059.006 Command and Scripting Interpreter: Python
- T1068 Exploitation for Privilege Escalation
- T1005 Data from Local System
- T1599 Network Boundary Bridging
- T1499.004 Endpoint Denial of Service: Application or System Exploitation

## Sources

- [Cisco Patches a Dozen Critical Vulnerabilities (SecurityWeek)](https://www.securityweek.com/cisco-patches-a-dozen-critical-vulnerabilities/)
- [Cisco Advance Notification for Publication of October 7, 2026 Security Advisories](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-fBn58ELx)
- [Cisco Meraki Security Hardening Release: October 2026](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-meraki-os-drbEX9GH)
- [Cisco NX-OS NGOAM Remote Code Execution Vulnerabilities](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ngoam-rce-LWKQ4BU)
- [Cisco NX-OS NX-API Remote Code Execution Vulnerability](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-napi-rce-r2shwu2j)
- [Cisco SSM On-Prem Vulnerabilities](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ssm-access-nttb2dhE)
- [Cisco Finesse Server-Side Request Forgery Vulnerability](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-finesse-ssrf-mmSuyugS)
- [Cisco Fixes CVSS 10 License On-Prem Flaw and Ships Hardening Releases for APIC and Meraki (SecurityOnline)](https://securityonline.info/cisco-license-on-prem-vulnerabilities/)
- [Cisco Patches 35 Vulnerabilities as Critical Nexus Bugs Allow Root Access (The420.in)](https://the420.in/cisco-critical-vulnerabilities-nxos-meraki-apic-october-2026/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3108
