Skip to content
Brief Security & Trust ·

Cisco patches 35 flaws, more than a dozen rated critical

The fixes cover NX-OS, Meraki, License On-Prem and other products, and Cisco knows of no attacks so far.

In brief
  • Cisco released fixes on October 7, 2026, and told customers to upgrade. SecurityWeek counts 35 flaws, more than a dozen rated critical.
  • Cisco is not aware of any attacks using these flaws. The sources do not say how many devices are exposed.

Cisco's security response team published a batch of advisories on October 7, 2026. It strongly urged customers to upgrade to the fixed software. SecurityWeek reported on October 8 that the fixes cover 35 vulnerabilities, with more than a dozen rated critical. The advisories cover NX-OS (the software on Nexus network switches), the Application Policy Infrastructure Controller, License On-Prem, Meraki and Finesse. Cisco gives the License On-Prem flaws a severity score of 10.0 out of 10. The NX-OS and controller flaws score 9.8, and the Meraki ones 9.6.

SecurityWeek said Cisco is not aware of any of these flaws being used in attacks. It also reported that two NX-OS bugs could let a remote attacker without a login run code as root or crash the system. Three other NX-OS bugs only apply to Nexus 3000 and 9000 switches with the NGOAM feature turned on. SecurityWeek added that the high-rated Finesse flaw had already been made public. The sources do not say how many devices run the affected versions.

Teams that run Cisco network gear or license servers should check which advisories cover their products. Cisco says the remedy is to upgrade, and each advisory lists the fixed releases.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: Cisco Systems.