Cisco Patches 14 Vulnerabilities in NX-OS Software, Four Rated Critical
Cisco Systems has released security updates to address 14 vulnerabilities in its Cisco NX-OS Software, the operating system powering many enterprise network devices. The company published seven security advisories on October 7, 2026, covering the issues.
Four advisories received a Critical severity rating and three were rated Medium. The critical advisories primarily affect Cisco Nexus 3000 Series and Cisco Nexus 9000 Series switches, targeting the network operations monitoring feature NGOAM, MPLS OAM, and the NX-API management interface.
Seven individual vulnerabilities received CVSSv3.1 base scores of 9.0 or higher. The flaws CVE-2026-76485, CVE-2026-76486, and CVE-2026-76501 result from insufficient input validation in NGOAM. Crafted IP packets can lead to remote code execution with root privileges or denial-of-service conditions. Exploitation of some issues requires specific SRv6 or NV Overlay configurations.
Additional advisories address control plane denial-of-service conditions, Python sandbox escape vulnerabilities, and an endpoint group contract bypass affecting Nexus 9000 Series Fabric Switches in ACI mode.
Related articles
HPE Networking ClearPass Policy Manager Hit by 28 Vulnerabilities Including 10 Rated Critical
Hewlett Packard Enterprise has disclosed 28 vulnerabilities in its HPE Networking ClearPass Policy Manager product and released security updates to address them. The issues span the web management interface, APIs, endpoint agents, and client software components. Ten of the flaws received a Critical severity rating. Notable issues include SQL injection, multiple authentication bypasses, unsafe deserialization leading to remote code execution, and path traversal. No public exploit code or active discussions were observed at the time the advisory was published on October 6, 2026. The company urges customers to apply the available patches promptly.
Attackers Exploit Critical Atlassian Data Center Flaw CVE-2026-21589 Hours After PoC Release
Exploitation attempts against CVE-2026-21589 began almost immediately after technical details and a Nuclei template were published. The vulnerability allows unauthenticated arbitrary file read in multiple Atlassian Data Center products and carries a CVSS v4.0 score of 9.3. In environments integrated with Crowd, attackers who obtain crowd.properties can extract plaintext credentials and escalate to administrator privileges via the Crowd API. The flaw stems from improper handling of double-colon sequences in a shared web resource library, enabling path traversal against plugin resource endpoints. Affected products include Bitbucket Data Center, Confluence Data Center, Jira Software Data Center, Jira Service Management Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian urges immediate patching outside normal cycles and recommends WAF rules or Tomcat RewriteValve configurations to block traversal patterns. Organizations should also review access logs for double-decoded URLs containing .., /, \, or :: sequences.
LibreOffice and Apache OpenOffice Flaw Enables Remote Code Execution via Malicious Calc Tables Without Macro Warnings
Researchers have demonstrated an attack against LibreOffice and Apache OpenOffice users that executes arbitrary Java code simply by opening a malicious spreadsheet, without requiring macro permissions or triggering any security prompts. The vulnerability requires Java support to be enabled in the office suite and exploits legitimate features in the Calc component that automatically fetch data from external database sources. When a crafted document is opened, Calc loads a linked database file that references a malicious Java driver, allowing the attacker’s code to run inside the office process. LibreOffice has already patched the issue tracked as CVE-2026-63277 with the release of versions 26.2.5 and 26.8.0 on October 5, while Apache OpenOffice remains vulnerable up to version 4.1.16 under CVE-2026-59265 with a fix expected in 4.1.17. The attack chain works on both Windows and Linux and bypasses macro protections entirely because no user consent dialog appears. Although only a proof-of-concept exploit that launches the calculator has been published so far, the same technique can execute any Java payload. Users of OpenOffice are advised to disable Java or avoid untrusted files until the patch is available.
Atlassian Fixes Critical Path Traversal Flaw CVE-2026-21589 Exposing Files in Jira and Confluence
Atlassian has patched CVE-2026-21589, a CVSS 9.3 path traversal vulnerability that allows unauthenticated attackers to read files across eight products including Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible and Fisheye in Data Center editions. The flaw accepts manipulated paths where traversal sequences appear adjacent to forward slashes, backslashes or double colons, including URL-encoded variants. Attackers must know the exact file name and path because the vulnerability does not permit directory listing and is restricted to the web application root directory of each product. Configuration files located in predictable locations remain accessible to attackers familiar with the products. Patches have been released in specific versions such as Bitbucket 10.5.1, Confluence 10.2.19, Jira Software and Jira Service Management 11.3.12, Bamboo 12.1.12, Crowd 7.2.4 and Crucible and Fisheye 4.9.15. Atlassian found no evidence of exploitation in its cloud products, though the advisory does not address on-premises customer installations.