Vulnerabilities · 4h ago

Cisco Splits APIC and Meraki Fixes Across the Stack

Cisco issued separate October advisories for Cisco Application Policy Infrastructure Controller (APIC) and Cisco Meraki, covering one authenticated APIC file-access flaw and a Meraki hardening release that spans MR access points, MV cameras, and MX appliances. Cisco says none of the issues are known to be actively exploited.

The APIC bug lets an admin submit crafted values in the export-policy interface and reach files the controller should not expose. Cisco says that can leak sensitive files, including key material that may be reused to gain root on APIC and the switches it manages. The Meraki advisory is broader: Cisco bundled multiple internally found flaws into one release across many firmware trains.

For operators, the practical point is that this is not one patch target. If APIC sits in front of managed switching, exposed key material can widen the blast radius beyond the controller itself; Meraki shops may need to line up separate firmware changes across different device classes in the same maintenance window.

CVEs in this update

16 CVEs

Across Cisco NX-OS Software, Cisco Application Policy Infrastructure Controller (APIC), Cisco Meraki MR Wireless Access Points Software, and related packages.

5 critical · 11 high · 0 medium · 0 low

0 in CISA KEV · 0 with EPSS above 1%

Highest severity: CVE-2026-76455 · 9.8 CRITICAL

Showing the top 10 by KEV, EPSS, and severity.

Timeline

Sources

3 sources covering this story

Entities

Vendor digest: Cisco

Part of the PlainSec briefing for 2026-10-07

Editions

Related stories