Cisco Meraki hardening release fixes 7 CVEs, up to CVSS 9.6
At a glance
| Severity | CRITICAL |
|---|---|
| CVSS | CVE-2026-76463: 8.8, CVE-2026-76464: 9.6, CVE-2026-76467: 7.5 |
| In CISA KEV (exploited) | No |
| Vendor | Cisco |
| CVE IDs | CVE-2026-76463, CVE-2026-76464, CVE-2026-76467, CVE-2026-76468, CVE-2026-76469, CVE-2026-76470 |
Cisco has published a Meraki security hardening release for October 2026 that addresses seven CVEs across its Meraki product line, with a highest base score of 9.6 and a Critical rating on the advisory. Cisco says the flaws were found in internal testing and are not known to be actively exploited, and that no workarounds exist, so the update is the only fix. These Cisco Meraki vulnerabilities affect devices regardless of configuration.
What happened
Cisco’s networking engineering team ran an internal security review and shipped software hardening releases for the issues it found. Rather than publish dozens of separate entries, Cisco grouped the problems by vulnerability class (Common Weakness Enumeration, or CWE) and assigned one CVE to each group. The advisory ID is cisco-sa-hardening-meraki-os-drbEX9GH, first published on 7 October 2026 and updated on 8 October 2026 (version 1.1, final).
Because each CVE covers a whole class, its score reflects the single most severe underlying bug in that class, not an average. Individual flaws inside a group may be less serious.
Am I affected?
Cisco states the following products are vulnerable regardless of device configuration:
- Meraki Campus Gateways
- Meraki MG Cellular Gateways
- Meraki MR Wireless Access Points
- Meraki MS Series Switches
- Meraki MV Smart Cameras
- Meraki MX Security and SD-WAN Appliances
Only the products listed in the advisory are known to be affected. The specific fixed software releases are in the Fixed Software section of the Cisco advisory; they are not included in the data we reviewed, so check the advisory for your model.
Technical details
The advisory lists seven CVEs: CVE-2026-76463, CVE-2026-76464, CVE-2026-76467, CVE-2026-76468, CVE-2026-76469, CVE-2026-76470 and CVE-2026-76472. The classes named in the advisory are CWE-119, CWE-20, CWE-284, CWE-664, CWE-682, CWE-691 and CWE-74. Details for the three CVEs below are confirmed in the source data; scores and descriptions for the others are in the advisory.
| CVE | Class | Highest CVSS |
|---|---|---|
| CVE-2026-76464 | CWE-119, improper restriction of operations within a memory buffer (overflows, out-of-bounds writes) | 9.6 |
| CVE-2026-76463 | CWE-284, improper access control (authorization, authentication, privilege bypasses) | 8.8 |
| CVE-2026-76468 | CWE-20, improper input validation | 8.2 |
| CVE-2026-76467 | CWE-664, improper control of a resource through its lifetime | 7.5 |
The NVD vector for CVE-2026-76464 is CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. In plain terms, the attacker must be on the adjacent network (AV:A), needs no privileges and no user interaction, and the scope changes, with high impact on confidentiality, integrity and availability. CVE-2026-76463 has the same adjacent-network vector. CVE-2026-76467 is rated as network-reachable (AV:N) with high availability impact only.
None of the CVEs appears in the CISA Known Exploited Vulnerabilities catalog in our data, and no EPSS data was available. Cisco says exploitation is not known.
Why this matters
Analysis, not reported fact. An adjacent-network vector means an attacker generally needs a foothold on the same network segment, such as guest Wi-Fi, a shared LAN or a compromised host. That lowers the odds of internet-wide exploitation but matters for branch offices, retail sites and any place where untrusted devices share a segment with Meraki hardware. The network-reachable CVE-2026-76467 is an availability issue, so the likely worst case there is a device outage.
Meraki devices sit at the network edge and carry trust, so memory-corruption and access-control bugs there deserve a faster schedule than routine firmware. With no known exploitation and no KEV listing, a prompt but orderly rollout, starting with MX appliances and the segments with untrusted users, is reasonable. If any of these CVEs is later added to KEV, treat it as a patch-within-hours item.
What to do: fix Cisco Meraki vulnerabilities
- Inventory your Meraki estate: gateways, MG, MR, MS, MV and MX devices, and their current firmware versions.
- Open the Cisco advisory and find the Fixed Software section for the fixed releases for each model.
- Schedule the upgrade. Cisco states there are no workarounds, so mitigation by configuration is not an option.
- Prioritise devices on segments reachable by guests, contractors or unmanaged devices.
- Confirm after the upgrade that each device reports the fixed version in the Meraki dashboard.
Detection and hunting ideas
No indicators of compromise were published. Reasonable checks that follow from the facts: review dashboard event logs for unexpected device reboots or crashes (consistent with memory or resource bugs), unexplained configuration or administrator changes (consistent with access-control bugs), and unfamiliar devices on the same segments as Meraki infrastructure.
Sources
- Cisco Meraki Security Hardening Release: October 2026 (cisco-sa-hardening-meraki-os-drbEX9GH)
- NVD: CVE-2026-76464
- NVD: CVE-2026-76463
- NVD: CVE-2026-76467
