VORANT. Threat Intelligence Research Sign in Create a free account

Cisco patches dozens of flaws across product line

routine vulnerability technologytelecommunications

Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.

CERT-FR advisory details multiple Cisco vulnerabilities enabling RCE, privilege escalation, SSRF, SQLi and DoS across APIC, Meraki, NX-OS, UCS and other products.

CERT-FR has published a consolidated advisory covering numerous vulnerabilities discovered across a wide range of Cisco products, including APIC, Finesse, License On-Prem, Meraki (Campus Gateway, Cellular Gateway, Wireless AP, Switch, Smart Camera, Security/SD-WAN appliances), NX-OS, Packaged/Unified CCE, UCS, and Unified CCX. The vulnerabilities span multiple impact categories: remote code execution, privilege escalation, remote denial of service, confidentiality breaches, security policy bypass, SSRF, and SQL injection. No indication is given in this advisory that any of these flaws are being actively exploited in the wild.

Affected version ranges are extensive and product-specific, with some fixes already available and others scheduled for release as late as October 2026 through February 2027, meaning some systems will remain unpatched for an extended window. Defenders running any of the listed Cisco product lines should consult the referenced Cisco Security Advisories to identify exact affected versions and apply patches as they become available, prioritizing remote code execution and privilege escalation issues on internet-facing or management-plane systems such as APIC, NX-OS, and Meraki infrastructure.

Given the breadth of the advisory (29+ CVEs across nine separate Cisco bulletins) and no confirmed active exploitation, this is treated as a routine vendor patch cycle requiring prompt but non-emergency remediation. Organizations should track the delayed-availability patches closely and apply interim mitigations or hardening guidance from Cisco where fixes are not yet released.

Mentioned in this report

Vulnerabilities CVE-2026-20328CVE-2026-20362CVE-2026-76437CVE-2026-76452CVE-2026-76453CVE-2026-76454CVE-2026-76455CVE-2026-76456CVE-2026-76457CVE-2026-76458CVE-2026-76459CVE-2026-76463CVE-2026-76464CVE-2026-76465CVE-2026-76467CVE-2026-76468CVE-2026-76469CVE-2026-76470CVE-2026-76471CVE-2026-76472CVE-2026-76480CVE-2026-76482CVE-2026-76483CVE-2026-76484CVE-2026-76485CVE-2026-76486CVE-2026-76498CVE-2026-76499CVE-2026-76500CVE-2026-76501

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1282

What this brief leaves out

This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.

It sits in a corpus of 11,067 reports from 148 sources, 477 of them written in the last seven days, and it grows through the day.

A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.

Create a free account   What it costs