Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-76470 are related to incorrect calculation issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-682.
Published: 2026-10-07
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Incorrect calculation vulnerabilities that may lead to device misconfiguration or service disruption
Action: Apply Patch
AI Analysis

Impact

The disclosed issues involve erroneous arithmetic or logical calculations, catalogued as CWE-682, which can produce unexpected results within Cisco networking products. In practice, such miscalculations may alter configuration parameters, routing tables, or firmware operation, potentially causing devices to behave incorrectly or become unavailable. The adverse effects are limited to the affected device or device cluster and could lead to degraded network performance or temporary denial of service if the faulty calculations persist.

Affected Systems

Affected products include Cisco Campus Gateway Software along with the Meraki family devices: MR wireless access points, MV firmware, and MX firmware. No specific firmware or software version numbers are specified in the advisory; therefore, all releases that contain the hardening code are presumed vulnerable until the update is applied, and earlier releases lacking the hardening code remain at risk.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, implying that no active exploitation has been documented. Based on the nature of the vulnerability, the likely attack vector involves management or configuration traffic sent to the device that can trigger the erroneous calculation logic. The risk is moderate to high for environments where device configuration is accessible without strict controls.

Generated by OpenCVE AI on October 7, 2026 at 19:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the Cisco Meraki Hardening Release that corrects the calculation problems on all affected devices
  • Restrict management traffic to trusted IP addresses and enforce role‑based access controls
  • Enable detailed logging of configuration changes and monitor logs for anomalous routing or calculation errors

Generated by OpenCVE AI on October 7, 2026 at 19:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 16:30:00 +0000

Type Values Removed Values Added
Description As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76470 are related to incorrect calculation issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-682.
Title Cisco Meraki Hardening Release - Incorrect Calculation Vulnerabilities
Weaknesses CWE-682
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-10-07T18:05:06.738Z

Reserved: 2026-08-19T12:02:03.638Z

Link: CVE-2026-76470

cve-icon Vulnrichment

Updated: 2026-10-07T18:01:53.966Z

cve-icon NVD

Status : Received

Published: 2026-10-07T17:17:00.043

Modified: 2026-10-07T19:17:40.830

Link: CVE-2026-76470

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T19:15:14Z

Weaknesses