Skip to content

CVE-2026-76464 CVE-2026-76463 CVE-2026-76470 CVE-2026-76472 CVE-2026-76468 CVE-2026-76467 CVE-2026-76469

Cisco Meraki Security Hardening Release October 2026 fixes critical and high severity flaws (CVE-2026-76464 and others)

Critical 9.6 Vendor: Cisco Published

Cisco's Meraki Security Hardening Release October 2026 fixes multiple flaws in Campus Gateway, MR, MV and MX versions. CVE-2026-76464 (CVSS 9.6) lets an adjacent-network attacker fully compromise a device. Cisco sees no public exploitation; no workarounds exist. Apply the update.

What happened

Cisco has published the Meraki Security Hardening Release: October 2026 after an internal security review identified multiple vulnerabilities across its Campus Gateway, Meraki MR wireless access point, MV camera and MX security appliance products. The flaws are grouped under several weakness classes: improper control of a resource through its lifetime (CVE-2026-76467), improper input validation (CVE-2026-76468), insufficient control flow management (CVE-2026-76469), incorrect calculation (CVE-2026-76470), improper neutralization of special elements (CVE-2026-76472), improper access control (CVE-2026-76463), and buffer management (CVE-2026-76464).

The most severe, CVE-2026-76464, has a CVSS 3.1 base score of 9.6: an attacker on an adjacent network can exploit it with no privileges and no user interaction, with changed scope and high impact to confidentiality, integrity and availability. Several other flaws are also reachable without authentication from an adjacent network or the network; CVE-2026-76472 is locally exploitable with low privileges. None of the vulnerabilities require user interaction.

Cisco's Product Security Incident Response Team states it is not aware of any public announcements or malicious use of the vulnerabilities described in this advisory. The issues were internally discovered and have not been publicly disclosed.

Who is affected

Affected versions are Cisco Campus Gateway Software CG 33.1.3; Cisco Meraki MR Wireless Access Points Software MR 33.1.2, MR 30.6, MR 32.1.7, MR 32.2.3, MR 32.2.4 and MR 33.1.1; Cisco Meraki MV Firmware 4.20, 5.0, 5.1, 5.2, 5.3, 5.4, 5.4.1 and 5.5; and Cisco Meraki MX Firmware 16.2, 16.3, 16.4, 16.5, 16.6, 17.3, 17.6 and 17.7. Organisations using these products as campus gateways, wireless infrastructure, video endpoints or security appliances should verify their fleet version and deployment role.

What to do now

  1. Confirm whether your estate runs any affected version listed above.
  2. Apply Cisco's Meraki Security Hardening Release: October 2026, which Cisco has issued to address these vulnerabilities.
  3. Note that Cisco states there are no workarounds that address these vulnerabilities, so patching is the only complete remediation.
  4. If you must schedule the update, restrict management and network access to affected devices to trusted networks and monitor for unexpected configuration changes or restarts.

Beyond the patch

Meraki hardware is typically updated through vendor release cycles, so the real control here is how quickly your team discovers affected devices and deploys the October 2026 hardening release. Supply Chain Defense & Third-Party Risk maps the software and hardware you depend on, and tracks suppliers' patch cadence, so your exposure window is managed as third-party risk rather than discovered after a critical advisory.

Affected and fixed versions

ProductAffectedFixed in
CVE-2026-76464, CVE-2026-76463, CVE-2026-76470, CVE-2026-76472, CVE-2026-76468, CVE-2026-76467, CVE-2026-76469
Cisco Campus Gateway Software
CG 33.1.3No fixed version listed yet
CVE-2026-76464, CVE-2026-76463, CVE-2026-76470, CVE-2026-76472, CVE-2026-76468, CVE-2026-76467, CVE-2026-76469
Cisco Meraki MR Wireless Access Points Software
MR 33.1.2
MR 30.6
MR 32.1.7
MR 32.2.3
MR 32.2.4
MR 33.1.1
No fixed version listed yet
CVE-2026-76464, CVE-2026-76463, CVE-2026-76470, CVE-2026-76472, CVE-2026-76468, CVE-2026-76467, CVE-2026-76469
Cisco Meraki MV Firmware
4.20
5.0
5.1
5.2
5.3
5.4
5.4.1
5.5
No fixed version listed yet
CVE-2026-76464, CVE-2026-76463, CVE-2026-76470, CVE-2026-76472, CVE-2026-76468, CVE-2026-76467, CVE-2026-76469
Cisco Meraki MX Firmware
16.2
16.3
16.4
16.5
16.6
17.3
17.6
17.7
No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.