Cisco Patches a Dozen Critical Vulnerabilities

Cisco’s latest security update is a massive one, with patches for 35 vulnerabilities across its products. Among these, over a dozen critical-severity bugs have been fixed, including several that could allow attackers to execute arbitrary code or cause denial-of-service (DoS) conditions without even needing to authenticate.

The most severe of these vulnerabilities is CVE-2026-76464, which affects memory management and could lead to buffer overflows or out-of-bounds writes. This type of vulnerability can be particularly nasty, as it allows attackers to execute arbitrary code on the affected system. Cisco has also resolved eight bugs in its License On-Prem product, including five critical-severity issues that could allow unauthorized access or DoS conditions.

In addition to these fixes, Cisco’s Meraki security hardening release addresses multiple bugs grouped together under seven CVEs. These vulnerabilities cover a range of weaknesses, from missing authentication and improper verification of cryptographic signatures to insufficiently protected credentials. NX-OS received patches for 14 vulnerabilities, including seven critical-severity issues that could allow remote attackers to execute arbitrary code or cause DoS conditions.

What’s particularly concerning is the fact that some of these vulnerabilities can be exploited without authentication, making them a major security threat. For example, CVE-2026-76482 and CVE-2026-76480 cover multiple security holes in License On-Prem, including missing authentication and improper verification of cryptographic signatures. Meanwhile, CVE-2026-20328 and CVE-2026-76454 could allow unauthorized access or DoS conditions.

It’s worth noting that Cisco says it is not aware of any of these vulnerabilities being exploited in the wild. However, with so many critical-severity bugs patched, it’s clear that this update is a major security priority for the company. Users are advised to review the affected products and apply the necessary patches as soon as possible.

In practical terms, this means that IT administrators should prioritize updating their systems with the latest Cisco patches. This will not only prevent potential attacks but also ensure compliance with relevant regulations and best practices. By staying up-to-date with security updates, organizations can significantly reduce their risk of being compromised by these types of vulnerabilities.


Source: SecurityWeek — 2026-10-08