Weekly roundup
Cisco vulnerabilities, week 41 of 2026: unauthenticated NX-OS, Splunk and License On-Prem flaws lead 59 CVEs
Cisco's week 41 2026 release covers 59 CVEs across Splunk Enterprise, NX-OS, License On-Prem and others. No CVE is listed in CISA KEV. Eighteen critical flaws, many unauthenticated over the network, make NX-OS and exposed Splunk or License On-Prem the top patching priority.
The release at a glance
Cisco published 59 CVEs for week 41 of 2026, covering 5 October to 11 October 2026. The severity split is 18 critical, 15 high, 25 medium and 1 unscored. Products with the most entries are Splunk Enterprise (22), Cisco NX-OS Software (13), Cisco License On-Prem (8), Cisco Campus Gateway Software (7) and Cisco Application Policy Infrastructure Controller (APIC) (5). Smaller numbers affect Cisco Finesse, Cisco NX-OS System Software in ACI Mode, Splunk MCP Server and Jabber for Android. No CVE in this release is listed in CISA KEV. Cisco PSIRT says it is not aware of public announcements or malicious use of the vulnerabilities covered by its NX-OS, License On-Prem and APIC advisories. Several of the critical items are unauthenticated, network-reachable remote code execution or hardening issues in NX-OS, Splunk Enterprise and License On-Prem, which sets the prioritisation for this week.
What matters most
Splunk Enterprise. CVE-2026-76268 is a missing authentication flaw in the Patroni REST API on search head cluster members. An unauthenticated user with network access to the interface could execute operating-system commands. Splunk Enterprise 10.0.x and 9.4.x are not affected; fixed versions are 10.4.3 and 10.2.7. CVE-2026-76284 is a critical improper neutralisation group, fixed in 10.4.3, 10.2.7, 10.0.10 and 9.4.15. Both are rated CVSS 9.8 with a network attack vector, no privileges and no user interaction.
Cisco NX-OS Software. CVE-2026-76471 is unauthenticated remote code execution or denial of service through the NX-API. CVE-2026-76465 is remote code execution or denial of service through MPLS OAM on Nexus 3000 and 9000 Series switches. CVE-2026-76485 and CVE-2026-76486 are remote code execution or denial of service through VXLAN OAM (NGOAM). All are CVSS 9.8, require no privileges and no user interaction, and an attacker with network access could run code with root privileges or force a reload. Separate NX-OS hardening advisories cover improper access control and out-of-bounds writes.
Cisco License On-Prem. CVE-2026-76482, rated CVSS 10, covers improper input verification. CVE-2026-76480, rated CVSS 9.8, covers improper authentication. Both are part of the October 2026 security hardening release for the product formerly known as Smart Software Manager On-Prem.
Cisco APIC. The October 2026 APIC hardening release includes critical network-reachable improper access control and improper neutralisation vulnerabilities; the table on this page lists the relevant CVE entries.
Patch in this order
- Start with Splunk Enterprise search head cluster members. For CVE-2026-76268, upgrade affected 10.4 and 10.2 releases to 10.4.3 or 10.2.7; Splunk Enterprise 10.0.x and 9.4.x are not affected. For CVE-2026-76284, upgrade affected trains to 10.4.3, 10.2.7, 10.0.10 or 9.4.15. Prioritise systems where the Patroni REST API or search head cluster management interface is reachable from untrusted networks.
- Patch Cisco NX-OS devices with NX-API, MPLS OAM or VXLAN OAM enabled, especially Nexus 3000 and 9000 Series switches. The relevant advisories cover CVE-2026-76471, CVE-2026-76465, CVE-2026-76485 and CVE-2026-76486. These are unauthenticated, remote code execution or denial of service flaws; confirm the appropriate fixed version for your train in each Cisco advisory.
- Upgrade Cisco License On-Prem, formerly Smart Software Manager On-Prem, to the October 2026 security hardening release. This addresses CVE-2026-76482 and CVE-2026-76480, which affect the older version lines listed in the advisory.
- Apply the October 2026 APIC hardening release to affected Cisco Application Policy Infrastructure Controller deployments.
- Then work through the remaining high- and medium-severity items, led by exposed Cisco Campus Gateway Software and the Splunk Enterprise medium-severity cluster, according to your exposure management data.
Beyond the patch
A release dominated by unauthenticated, network-reachable flaws is best managed by knowing which management planes, APIs and cluster interfaces are actually reachable before patch day. Virtual CISO Services (vCISO) builds that exposure view and the patching order. Should any of these flaws be exploited, code execution, privileged account activity and unusual process behaviour leave telemetry that Managed Detection & Response (MDR) is built to detect and respond to.
Every CVE in this release
| CVE | Product | Severity | |
|---|---|---|---|
| CVE-2026-76482 | Cisco License On-Prem | Critical 10.0 | Advisory → |
| CVE-2026-76268 | Splunk Enterprise | Critical 9.8 | Advisory → |
| CVE-2026-76284 | Splunk Enterprise | Critical 9.8 | Advisory → |
| CVE-2026-76465 | Cisco NX-OS Software | Critical 9.8 | Advisory → |
| CVE-2026-76455 | Cisco NX-OS Software | Critical 9.8 | Advisory → |
| CVE-2026-76471 | Cisco NX-OS Software | Critical 9.8 | Advisory → |
| CVE-2026-76459 | Cisco NX-OS Software | Critical 9.8 | Advisory → |
| CVE-2026-76480 | Cisco License On-Prem | Critical 9.8 | Advisory → |
| CVE-2026-76485 | Cisco NX-OS Software | Critical 9.8 | Advisory → |
| CVE-2026-76486 | Cisco NX-OS Software | Critical 9.8 | Advisory → |
| CVE-2026-76499 | Cisco Application Policy Infrastructure Controller (APIC) | Critical 9.8 | Advisory → |
| CVE-2026-76498 | Cisco Application Policy Infrastructure Controller (APIC) | Critical 9.8 | Advisory → |
| CVE-2026-76500 | Cisco Application Policy Infrastructure Controller (APIC) | Critical 9.8 | Advisory → |
| CVE-2026-76501 | Cisco NX-OS Software | Critical 9.8 | Advisory → |
| CVE-2026-76464 | Cisco Campus Gateway Software | Critical 9.6 | Advisory → |
| CVE-2026-76454 | Cisco License On-Prem | Critical 9.1 | Advisory → |
| CVE-2026-20328 | Cisco License On-Prem | Critical 9.1 | Advisory → |
| CVE-2026-76483 | Cisco License On-Prem | Critical 9.1 | Advisory → |
| CVE-2026-76282 | Splunk Enterprise | High 8.8 | |
| CVE-2026-76453 | Cisco NX-OS Software | High 8.8 | Advisory → |
| CVE-2026-76484 | Cisco License On-Prem | High 8.8 | Advisory → |
| CVE-2026-76463 | Cisco Campus Gateway Software | High 8.8 | Advisory → |
| CVE-2026-76470 | Cisco Campus Gateway Software | High 8.8 | Advisory → |
| CVE-2026-76472 | Cisco Campus Gateway Software | High 8.8 | Advisory → |
| CVE-2026-76456 | Cisco NX-OS Software | High 8.6 | Advisory → |
| CVE-2026-76457 | Cisco NX-OS Software | High 8.6 | Advisory → |
| CVE-2026-76458 | Cisco NX-OS Software | High 8.6 | Advisory → |
| CVE-2026-76468 | Cisco Campus Gateway Software | High 8.2 | Advisory → |
| CVE-2026-76266 | Splunk Enterprise | High 7.7 | |
| CVE-2026-76283 | Splunk Enterprise | High 7.6 | |
| CVE-2026-76467 | Cisco Campus Gateway Software | High 7.5 | Advisory → |
| CVE-2026-76469 | Cisco Campus Gateway Software | High 7.4 | Advisory → |
| CVE-2026-20362 | Cisco Finesse | High 7.2 | |
| CVE-2026-76271 | Splunk Enterprise | Medium 6.5 | |
| CVE-2026-76274 | Splunk Enterprise | Medium 6.5 | |
| CVE-2026-76265 | Splunk Enterprise | Medium 6.5 | |
| CVE-2026-76269 | Splunk Enterprise | Medium 6.5 | |
| CVE-2026-76270 | Splunk Enterprise | Medium 6.5 | |
| CVE-2026-20321 | Cisco Application Policy Infrastructure Controller (APIC) | Medium 6.5 | |
| CVE-2026-76488 | Cisco Application Policy Infrastructure Controller (APIC) | Medium 6.5 |
Show all 59
| CVE | Product | Severity | |
|---|---|---|---|
| CVE-2026-76280 | Splunk Enterprise | Medium 6.3 | |
| CVE-2026-20038 | Cisco NX-OS System Software in ACI Mode | Medium 5.8 | |
| CVE-2026-20173 | Cisco NX-OS Software | Medium 5.8 | |
| CVE-2026-76281 | Splunk Enterprise | Medium 5.3 | |
| CVE-2026-76286 | Splunk MCP Server | Medium 5.3 | |
| CVE-2026-101886 | Jabber for Android | Medium 5.1 | |
| CVE-2026-76452 | Cisco License On-Prem | Medium 4.9 | Advisory → |
| CVE-2026-76437 | Cisco License On-Prem | Medium 4.9 | Advisory → |
| CVE-2026-20032 | Cisco NX-OS Software | Medium 4.4 | |
| CVE-2026-76264 | Splunk Enterprise | Medium 4.3 | |
| CVE-2026-76267 | Splunk Enterprise | Medium 4.3 | |
| CVE-2026-76272 | Splunk Enterprise | Medium 4.3 | |
| CVE-2026-76273 | Splunk Enterprise | Medium 4.3 | |
| CVE-2026-76275 | Splunk Enterprise | Medium 4.3 | |
| CVE-2026-76276 | Splunk Enterprise | Medium 4.3 | |
| CVE-2026-76278 | Splunk Enterprise | Medium 4.3 | |
| CVE-2026-76279 | Splunk Enterprise | Medium 4.3 | |
| CVE-2026-76277 | Splunk Enterprise | Medium 4.1 | |
| CVE-2026-76285 | Splunk Enterprise | Not scored |
References
Vendor advisory
- Cisco License (Smart Software Manager) On-Prem Security Hardening Release: October 2026
- Cisco Nexus 3000 and 9000 Series Switches MPLS OAM Remote Code Execution Vulnerability
- Cisco NX-OS Software Security Hardening Release: October 2026
- Cisco NX-OS Software NX-API Remote Code Execution Vulnerability
- Cisco Nexus 3000 and 9000 Series Switches NGOAM Remote Code Execution Vulnerabilities
- Cisco Application Policy Infrastructure Controller Security Hardening Release: October …
CVE
- CVE-2026-76482 — cve.org
- CVE-2026-76482 — NVD
- EUVD-2026-94465 — ENISA EUVD
- CVE-2026-76268 — cve.org
- CVE-2026-76268 — NVD
- EUVD-2026-94620 — ENISA EUVD
- CVE-2026-76284 — cve.org
- CVE-2026-76284 — NVD
- EUVD-2026-94585 — ENISA EUVD
- CVE-2026-76465 — cve.org
- CVE-2026-76465 — NVD
- EUVD-2026-94457 — ENISA EUVD
- CVE-2026-76455 — cve.org
- CVE-2026-76455 — NVD
- EUVD-2026-94460 — ENISA EUVD
- CVE-2026-76471 — cve.org
- CVE-2026-76471 — NVD
- EUVD-2026-94461 — ENISA EUVD
- CVE-2026-76459 — cve.org
- CVE-2026-76459 — NVD
- EUVD-2026-94462 — ENISA EUVD
- CVE-2026-76480 — cve.org
- CVE-2026-76480 — NVD
- EUVD-2026-94464 — ENISA EUVD
- CVE-2026-76485 — cve.org
- CVE-2026-76485 — NVD
- EUVD-2026-94467 — ENISA EUVD
- CVE-2026-76486 — cve.org
- CVE-2026-76486 — NVD
- EUVD-2026-94470 — ENISA EUVD
- CVE-2026-76499 — cve.org
- CVE-2026-76499 — NVD
- EUVD-2026-94471 — ENISA EUVD
- CVE-2026-76498 — cve.org
- CVE-2026-76498 — NVD
- EUVD-2026-94472 — ENISA EUVD