# Cisco patches multiple IOS XE vulnerabilities

Published: 2026-10-09 · Severity: routine · Sectors: technology, telecommunications, infrastructure
Canonical: https://vorant.io/reports/88d10d31-6651-565a-a250-4a5887f96ad3/cisco-patches-multiple-ios-xe-vulnerabilities

> NCSC-NL advisory covers seven Cisco IOS XE vulnerabilities, internally discovered, affecting autonomous/controller mode devices; patches available, no known exploitation.

NCSC-NL published an advisory summarizing seven vulnerabilities fixed in Cisco IOS XE Software, discovered internally by Cisco's engineering teams during security reviews rather than through external research or active exploitation. The flaws affect IOS XE when running in autonomous mode or controller mode, regardless of device configuration, and include issues such as out-of-bounds read, integer overflow/wraparound, improper access control, buffer management errors, improper resource control, and improper input validation.

CVSS scores range from 7.4 to 9.6, with CVE-2026-76464 (9.6) being the most severe. Cisco has released software hardening updates to address all seven CVEs. There is no indication in the advisory of in-the-wild exploitation; this is a proactive patch release. Defenders running Cisco IOS XE in autonomous or controller mode should prioritize patching per Cisco's official advisories, particularly for the higher-CVSS entries, and verify device mode and configuration to determine exposure.

## Mentioned in this report

- Vulnerabilities: CVE-2026-76463, CVE-2026-76464, CVE-2026-76467, CVE-2026-76468, CVE-2026-76469, CVE-2026-76470, CVE-2026-76472

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0411.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/88d10d31-6651-565a-a250-4a5887f96ad3/cisco-patches-multiple-ios-xe-vulnerabilities.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
