Security Advisory Desk
criticalQCS priority 100/100Cisco

Cisco Meraki Security Hardening Release: October 2026

Cisco's engineering teams performed a thorough internal security review of their Meraki product line and discovered several security weaknesses that could affect multiple devices. These problems were found during testing and are not currently being exploited by attackers. Cisco has released software updates to strengthen security and fix these issues. There are no known workarounds, so customers should update their devices to the fixed software versions to protect against potential risks.

QCS published 8/10/2026, 6:44:29 am ISTVendor disclosure 8/10/2026, 5:48:38 am ISTVerified 8/10/2026, 6:44:29 am ISTRevision 1

In plain language

What this advisory means

Cisco's engineering teams performed a thorough internal security review of their Meraki product line and discovered several security weaknesses that could affect multiple devices. These problems were found during testing and are not currently being exploited by attackers. Cisco has released software updates to strengthen security and fix these issues. There are no known workarounds, so customers should update their devices to the fixed software versions to protect against potential risks.

Technical explanation

How the issue affects the environment

During internal testing, Cisco identified multiple vulnerabilities across Cisco Meraki products, including access control flaws (CWE-284), memory buffer restrictions violations (CWE-119), improper resource lifetime management (CWE-664), input validation errors (CWE-20), insufficient control flow management (CWE-691), incorrect arithmetic calculations (CWE-682), and improper neutralization of special elements leading to injection risks (CWE-74). These vulnerabilities carry high CVSS scores up to 9.6, indicating severe risk potential. No public exploitation or announcements have been observed. Cisco has released software updates addressing these CWEs with fixed versions specified per product line. No workarounds are available to mitigate these vulnerabilities short of upgrading to fixed software.

Operational impact

Why teams should care

If unaddressed, these vulnerabilities could allow attackers to bypass access controls, cause memory corruption, execute arbitrary code, or escalate privileges on affected Meraki devices. This can result in loss of data confidentiality, integrity, and availability, potentially disrupting business operations and undermining network security. Proactively installing the fixes reduces risk and helps maintain secure and reliable network infrastructure.

Immediate action

Administrators should promptly upgrade affected Cisco Meraki devices to the designated fixed software releases listed in the advisory. This upgrade is the only effective mitigation, as no workarounds exist. Carefully verify each device model and software version, then follow Cisco’s upgrade instructions. After updating, verify that the devices operate correctly and monitor for any irregularities.

Affected and fixed releases

Affected versionsConfirm in the official vendor advisory
Fixed versionsMeraki Campus Gateway 32.2.5 (late Oct 2026) and later, Meraki MG Cellular Gateway 26.1.4 and later, Meraki MR Wireless Access Point 30.7.3, 31.1.8.1, 32.2.5, 33.1.3 and later, Meraki MS Series Switch 18.1.9 and later, Meraki MV Smart Camera 8.0 and later, Meraki MX Security and SD-WAN Appliance 18.107.14*, 19.2.9*, 26.1.7, 26.2.3 and later

Temporary risk reduction

The advisory explicitly states that no workarounds are available for these vulnerabilities. Remediation requires applying the fixed software releases.

Evidence and validation checklist

  • Cisco PSIRT published advisory (2026-10-07) with detailed CWE and CVE listings
  • No known public exploitation or announcement per Cisco PSIRT
  • Fixed software releases specified per product and version
  • No workarounds exist as stated in the advisory
  • Internal discovery during security testing, including frontier AI models

Authoritative reference

Cisco PSIRT Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source