Skip to content

Weekly roundup

Cisco vulnerabilities, week 41 of 2026: unauthenticated NX-OS, Splunk and License On-Prem flaws lead 59 CVEs

Critical 10.0 Vendor: Cisco 59 CVEs in scope Published

Cisco's week 41 2026 release covers 59 CVEs across Splunk Enterprise, NX-OS, License On-Prem and others. No CVE is listed in CISA KEV. Eighteen critical flaws, many unauthenticated over the network, make NX-OS and exposed Splunk or License On-Prem the top patching priority.

The release at a glance

Cisco published 59 CVEs for week 41 of 2026, covering 5 October to 11 October 2026. The severity split is 18 critical, 15 high, 25 medium and 1 unscored. Products with the most entries are Splunk Enterprise (22), Cisco NX-OS Software (13), Cisco License On-Prem (8), Cisco Campus Gateway Software (7) and Cisco Application Policy Infrastructure Controller (APIC) (5). Smaller numbers affect Cisco Finesse, Cisco NX-OS System Software in ACI Mode, Splunk MCP Server and Jabber for Android. No CVE in this release is listed in CISA KEV. Cisco PSIRT says it is not aware of public announcements or malicious use of the vulnerabilities covered by its NX-OS, License On-Prem and APIC advisories. Several of the critical items are unauthenticated, network-reachable remote code execution or hardening issues in NX-OS, Splunk Enterprise and License On-Prem, which sets the prioritisation for this week.

What matters most

Splunk Enterprise. CVE-2026-76268 is a missing authentication flaw in the Patroni REST API on search head cluster members. An unauthenticated user with network access to the interface could execute operating-system commands. Splunk Enterprise 10.0.x and 9.4.x are not affected; fixed versions are 10.4.3 and 10.2.7. CVE-2026-76284 is a critical improper neutralisation group, fixed in 10.4.3, 10.2.7, 10.0.10 and 9.4.15. Both are rated CVSS 9.8 with a network attack vector, no privileges and no user interaction.

Cisco NX-OS Software. CVE-2026-76471 is unauthenticated remote code execution or denial of service through the NX-API. CVE-2026-76465 is remote code execution or denial of service through MPLS OAM on Nexus 3000 and 9000 Series switches. CVE-2026-76485 and CVE-2026-76486 are remote code execution or denial of service through VXLAN OAM (NGOAM). All are CVSS 9.8, require no privileges and no user interaction, and an attacker with network access could run code with root privileges or force a reload. Separate NX-OS hardening advisories cover improper access control and out-of-bounds writes.

Cisco License On-Prem. CVE-2026-76482, rated CVSS 10, covers improper input verification. CVE-2026-76480, rated CVSS 9.8, covers improper authentication. Both are part of the October 2026 security hardening release for the product formerly known as Smart Software Manager On-Prem.

Cisco APIC. The October 2026 APIC hardening release includes critical network-reachable improper access control and improper neutralisation vulnerabilities; the table on this page lists the relevant CVE entries.

Patch in this order

  1. Start with Splunk Enterprise search head cluster members. For CVE-2026-76268, upgrade affected 10.4 and 10.2 releases to 10.4.3 or 10.2.7; Splunk Enterprise 10.0.x and 9.4.x are not affected. For CVE-2026-76284, upgrade affected trains to 10.4.3, 10.2.7, 10.0.10 or 9.4.15. Prioritise systems where the Patroni REST API or search head cluster management interface is reachable from untrusted networks.
  2. Patch Cisco NX-OS devices with NX-API, MPLS OAM or VXLAN OAM enabled, especially Nexus 3000 and 9000 Series switches. The relevant advisories cover CVE-2026-76471, CVE-2026-76465, CVE-2026-76485 and CVE-2026-76486. These are unauthenticated, remote code execution or denial of service flaws; confirm the appropriate fixed version for your train in each Cisco advisory.
  3. Upgrade Cisco License On-Prem, formerly Smart Software Manager On-Prem, to the October 2026 security hardening release. This addresses CVE-2026-76482 and CVE-2026-76480, which affect the older version lines listed in the advisory.
  4. Apply the October 2026 APIC hardening release to affected Cisco Application Policy Infrastructure Controller deployments.
  5. Then work through the remaining high- and medium-severity items, led by exposed Cisco Campus Gateway Software and the Splunk Enterprise medium-severity cluster, according to your exposure management data.

Beyond the patch

A release dominated by unauthenticated, network-reachable flaws is best managed by knowing which management planes, APIs and cluster interfaces are actually reachable before patch day. Virtual CISO Services (vCISO) builds that exposure view and the patching order. Should any of these flaws be exploited, code execution, privileged account activity and unusual process behaviour leave telemetry that Managed Detection & Response (MDR) is built to detect and respond to.

Every CVE in this release

CVEProductSeverity
CVE-2026-76482Cisco License On-PremCritical 10.0Advisory →
CVE-2026-76268Splunk EnterpriseCritical 9.8Advisory →
CVE-2026-76284Splunk EnterpriseCritical 9.8Advisory →
CVE-2026-76465Cisco NX-OS SoftwareCritical 9.8Advisory →
CVE-2026-76455Cisco NX-OS SoftwareCritical 9.8Advisory →
CVE-2026-76471Cisco NX-OS SoftwareCritical 9.8Advisory →
CVE-2026-76459Cisco NX-OS SoftwareCritical 9.8Advisory →
CVE-2026-76480Cisco License On-PremCritical 9.8Advisory →
CVE-2026-76485Cisco NX-OS SoftwareCritical 9.8Advisory →
CVE-2026-76486Cisco NX-OS SoftwareCritical 9.8Advisory →
CVE-2026-76499Cisco Application Policy Infrastructure Controller (APIC)Critical 9.8Advisory →
CVE-2026-76498Cisco Application Policy Infrastructure Controller (APIC)Critical 9.8Advisory →
CVE-2026-76500Cisco Application Policy Infrastructure Controller (APIC)Critical 9.8Advisory →
CVE-2026-76501Cisco NX-OS SoftwareCritical 9.8Advisory →
CVE-2026-76464Cisco Campus Gateway SoftwareCritical 9.6Advisory →
CVE-2026-76454Cisco License On-PremCritical 9.1Advisory →
CVE-2026-20328Cisco License On-PremCritical 9.1Advisory →
CVE-2026-76483Cisco License On-PremCritical 9.1Advisory →
CVE-2026-76282Splunk EnterpriseHigh 8.8
CVE-2026-76453Cisco NX-OS SoftwareHigh 8.8Advisory →
CVE-2026-76484Cisco License On-PremHigh 8.8Advisory →
CVE-2026-76463Cisco Campus Gateway SoftwareHigh 8.8Advisory →
CVE-2026-76470Cisco Campus Gateway SoftwareHigh 8.8Advisory →
CVE-2026-76472Cisco Campus Gateway SoftwareHigh 8.8Advisory →
CVE-2026-76456Cisco NX-OS SoftwareHigh 8.6Advisory →
CVE-2026-76457Cisco NX-OS SoftwareHigh 8.6Advisory →
CVE-2026-76458Cisco NX-OS SoftwareHigh 8.6Advisory →
CVE-2026-76468Cisco Campus Gateway SoftwareHigh 8.2Advisory →
CVE-2026-76266Splunk EnterpriseHigh 7.7
CVE-2026-76283Splunk EnterpriseHigh 7.6
CVE-2026-76467Cisco Campus Gateway SoftwareHigh 7.5Advisory →
CVE-2026-76469Cisco Campus Gateway SoftwareHigh 7.4Advisory →
CVE-2026-20362Cisco FinesseHigh 7.2
CVE-2026-76271Splunk EnterpriseMedium 6.5
CVE-2026-76274Splunk EnterpriseMedium 6.5
CVE-2026-76265Splunk EnterpriseMedium 6.5
CVE-2026-76269Splunk EnterpriseMedium 6.5
CVE-2026-76270Splunk EnterpriseMedium 6.5
CVE-2026-20321Cisco Application Policy Infrastructure Controller (APIC)Medium 6.5
CVE-2026-76488Cisco Application Policy Infrastructure Controller (APIC)Medium 6.5
Show all 59
CVEProductSeverity
CVE-2026-76280Splunk EnterpriseMedium 6.3
CVE-2026-20038Cisco NX-OS System Software in ACI ModeMedium 5.8
CVE-2026-20173Cisco NX-OS SoftwareMedium 5.8
CVE-2026-76281Splunk EnterpriseMedium 5.3
CVE-2026-76286Splunk MCP ServerMedium 5.3
CVE-2026-101886Jabber for AndroidMedium 5.1
CVE-2026-76452Cisco License On-PremMedium 4.9Advisory →
CVE-2026-76437Cisco License On-PremMedium 4.9Advisory →
CVE-2026-20032Cisco NX-OS SoftwareMedium 4.4
CVE-2026-76264Splunk EnterpriseMedium 4.3
CVE-2026-76267Splunk EnterpriseMedium 4.3
CVE-2026-76272Splunk EnterpriseMedium 4.3
CVE-2026-76273Splunk EnterpriseMedium 4.3
CVE-2026-76275Splunk EnterpriseMedium 4.3
CVE-2026-76276Splunk EnterpriseMedium 4.3
CVE-2026-76278Splunk EnterpriseMedium 4.3
CVE-2026-76279Splunk EnterpriseMedium 4.3
CVE-2026-76277Splunk EnterpriseMedium 4.1
CVE-2026-76285Splunk EnterpriseNot scored

References

CVE

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.