Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.6

CVE-2026-76464: Cisco Meraki devices may crash or be tampered

CVE-2026-76464 · published 4 days ago
Summary

Cisco campus gateways, Meraki wireless access points, camera (MV) and security appliance (MX) firmware contain memory‑handling flaws that could let an attacker make the device stop working or alter its data. The problem is fixed in a new software hardening update released in October 2026. Apply the latest update from Cisco as soon as possible to remove the risk.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
cisco cisco campus gateway software CG 33.1.3
cisco cisco meraki mr wireless access points software MR 33.1.2
cisco cisco meraki mv firmware 4.20
cisco cisco meraki mx firmware 16.2
Original advisory text
Cisco Meraki Hardening Release October 2026 - Buffer Management Vulnerabilities
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.

The vulnerabilities tracked by this CVE-2026-76464 are related to buffer management issues that are grouped under the Common Weakness Enumeration (CWE) CWE-119.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.6 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-119Buffer Overflow
Timeline
Published7 Oct 2026
Updated8 Oct 2026
First seen7 Oct 2026
Sources
CVE-2026-76464 · MITRE
Track software like this
Free during beta