Security appliances software versions MX 26.2.4 changelogExecutive summaryResolved restart issues affecting passthrough-mode MX250 and MX450 HA pairs and wireless-enabled Z4 appliances running MX 26.2.3.Corrected routing and policy behavior in VRF deployments, including Auto VPN subnet advertisements, BGP path selection, and Content Filtering.Improved VPN behavior for Client VPN authentication and IPsec uplink balancing.What's newAdded IPv6 endpoint support for Advanced Malware Protection cloud connectivity. (MX-54601)Bug fixes - general fixesFixed an issue that could cause IKEv2 Client VPN RADIUS authentication traffic to be blocked by an upstream MX when short usernames were used. (MX-54059)Fixed an issue that could provide Cisco Secure Client VPN users with a previously configured secondary DNS server after administrators removed it. (MX-54023)Restored per-flow balancing across multiple IPsec VPN uplinks when ECMP hashing was enabled. (MX-53461)Improved initialization times for deployments with large numbers of third-party IPsec VPN tunnels. (MX-53644)Fixed an issue that could advertise subnets for IPsec VPN tunnels with tunnel health checks to MP-BGP peers. (MX-54575)Fixed an issue that could incorrectly block web traffic from clients in non-default VRFs when Content Filtering was enabled. (MX-52754)Restored delivery of downloaded security and content-control lists to policy enforcement services. (MX-53537)Corrected an issue that could advertise a subnet enabled for Auto VPN from the wrong VRF over iBGP when overlapping subnets were configured in multiple VRFs. (MX-50757)Resolved an issue that could advertise a subnet enabled for Auto VPN from the wrong VRF over eBGP when overlapping subnets were configured in multiple VRFs. (MX-51801)Fixed an issue that could cause spokes using BGP with VRFs to prefer an unexpected path when routes were learned from multiple Auto VPN hubs. (MX-52635)Resolved an issue that could strip BGP communities received from eBGP peers by default, potentially advertising routes beyond their intended peers. (MX-53142)Resolved persistent route churn in MP-BGP deployments combining route-reflector and non-route-reflector sessions. (MX-54070)Corrected BGP event log entries so Dashboard displays the associated VRF name and identifier. (MX-51227)Corrected Dashboard routing table results that could display only a subset of BGP routes learned through Auto VPN when multiple paths existed for the same prefix. (MX-52636)Restored iBGP default routes in Dashboard routing table results when filtering by VRF and route type. (MX-51578)As part of Cisco's ongoing commitment to proactive security and product quality, the MX engineering team has conducted a comprehensive internal security review. This review resulted in one or more software hardening release(s) that address(e)s multiple internally discovered vulnerabilities.Bug fixes - limited platform fixesFixed an issue that could cause MX95 and MX105 appliances to restart unexpectedly after concurrent local web service restarts. (MX-52511)Fixed an issue on MX68CW appliances that could prevent integrated wireless clients from communicating with wired clients on the same VLAN. (MX-53387)Fixed an issue on C8455-G2-MX secure routers that could cause Dashboard connectivity loss during network movement or HA configuration when all convertible LAN ports were configured as uplinks. (MX-45649)Resolved an issue that could leave obsolete VPN subnet translations active on MX85 appliances after VPN NAT was disabled. (MX-52825)Corrected SNMP interface names on C8455-G2-MX secure routers to match physical port numbering. (MX-52731)Resolved an issue that could cause passthrough-mode MX250 and MX450 appliances configured as HA pairs to restart unexpectedly shortly after booting. (MX-54712)Fixed an issue that could prevent 1 Gbps optical SFP links from establishing reliable bidirectional connectivity when port speed was set to Auto on C8355-G2-MX and C8455-G2-MX secure routers. (MX-52813)Restored expected traffic throughput on C8455-G2-MX secure routers after a software regression reduced performance under high-throughput workloads. (MX-54329)Fixed an issue that could cause Z4 appliances with wireless enabled to restart repeatedly. (MX-55272)Legacy products noticeWhen configured for this version, MX64(W), MX65(W), MX84, MX100, and vMX100 appliances will run MX 18.107.13.Known issuesOn MX appliances in HA with a virtual IP, enabling multiple uplinks for a Non-Meraki VPN peer may prevent all Non-Meraki VPN tunnels from establishing. (MX-49849)Dashboard may display only one next hop for BGP routes using ECMP, although traffic continues to use all equal-cost paths. (MX-50932)Certain custom intrusion prevention rules may prevent WAN Uplink Sharing from establishing shared uplinks. (MX-51442)In some WAN Uplink Sharing deployments, iBGP sessions may remain down after uplink sharing is enabled even though AutoVPN is established. (MX-50729)
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | A new Generally Available MX Security & SD-WAN firmware is now available | 0 | 8.59 | 05-10-2026 |
| 2 | Re: A new Generally Available MX Security & SD-WAN firmware is now | 0 | 12.31 | 05-10-2026 |
| 3 | Upcoming Security Advisory Includes Meraki Products | 0 | 9.26 | 06-10-2026 |
| 4 | Exchange security updates for on-prem systems - install now | 0 | 15.78 | 02-10-2026 |
| 5 | Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager | 0 | 9.95 | 30-09-2026 |
| 6 | Re: IOS XE 26.2.1: What's New for Cisco Switching | 0 | 8.82 | 07-10-2026 |
| 7 | IOS firmware for Catalyst 2060c does not load entirely after upgrade | 0 | 6.96 | 06-10-2026 |
| 8 | [IOS-XE] AES password encryption setting is not reflected from GUI | 0 | 12.35 | 07-10-2026 |
| 9 | CSAF and CVE Record list different affected versions for same advisory | 0 | 7.78 | 05-10-2026 |