Cisco Meraki MR26 EoL: Migrate to Catalyst CW9164I
The Meraki MR26 passed Last Day of Support on May 9, 2023 — it gets no PSIRT fixes, no firmware, and no RMA. Here is what that means for an 802.11n fleet still in your ceilings and how to refresh cleanly to the Wi-Fi 6E Catalyst CW9164I on the Meraki dashboard.

If you still have Cisco Meraki MR26 access points (PID MR26-HW) mounted in ceilings, you are running infrastructure that is already past its support floor. The MR26 went End of Sale on May 9, 2016, and it crossed its Last Day of Support (LDoS) on May 9, 2023. That date is in the rear-view mirror — Cisco ships no firmware, no PSIRT security fixes, and no TAC support or RMA hardware replacement for this model today. The radios keep associating clients, which is precisely why these 802.11n units survive in remote closets and back-office areas long after they should have been retired. This guide explains what the MR26 actually was, why an already-LDoS access point is a live compliance and security liability, and how to refresh to the recommended Wi-Fi 6E Catalyst CW9164I while keeping your Meraki dashboard operating model intact.
What the MR26 actually was
The MR26 was an early dual-band, dual-concurrent 802.11n (Wi-Fi 4) cloud-managed indoor access point aimed at small and midsize deployments. It runs a 3x3:3 MIMO design on both bands — a 2.4 GHz radio and a 5 GHz radio operating simultaneously — for a peak PHY rate around 450 Mbps per radio. It also carries a dedicated third radio for spectrum analysis and security scanning (the basis of Meraki's Air Marshal WIPS and RF analytics) plus an integrated Bluetooth/RF sensor. Uplink is a single 10/100/1000 Gigabit Ethernet port, and it is powered by 802.3af (PoE) or a DC adapter, with integrated omnidirectional antennas. For 2013-era laptops and phones it was a capable mainstream AP.
The problem is generational, not cosmetic. The MR26 is 802.11n only — it predates 802.11ac entirely, so it has no 80/160 MHz channels, no MU-MIMO, no OFDMA, no BSS coloring, and obviously no 6 GHz band. Against a modern client mix of Wi-Fi 6/6E phones and laptops, a 3x3:3 802.11n AP becomes the slowest, most airtime-hungry device on the floor, dragging down the cell for every client it serves. A single MR26 cannot saturate even its own 1 Gbps uplink, but it will happily starve a dense room of airtime.
Why acting now matters
The risk of an end-of-life access point is not that it stops working. It is that it keeps passing traffic while the support floor has already disappeared beneath it. Because the MR26 is past LDoS, all three of these exposures are live today, not pending:
- No PSIRT security fixes. The MR26 firmware branch is frozen. Any wireless, driver, or management vulnerability disclosed against this hardware will never receive a patched build — the CVE is permanent on these units. WPA2/802.11n-era cryptographic and key-management weaknesses are exactly the class of issue that no longer gets remediated here.
- No TAC or RMA. A failed MR26 cannot be opened as a support case or swapped under any contract. Your only recovery is a cold spare you already own or a gray-market unit of the same dead-end, unpatchable model.
- Audit and compliance exposure. FedRAMP, CMMC 2.0, the HIPAA Security Rule, PCI DSS 4.0, and CISA directives all assume supported, patchable infrastructure. An access point that has been past LDoS since 2023 and can no longer receive a security fix is a documented audit finding — and 'the vendor stopped shipping firmware three years ago' is not a defensible remediation plan.
There is also a licensing reality unique to Meraki. The MR26 requires an active Meraki license to function on the dashboard at all. Every renewal you pay against this hardware is a subscription spent keeping an unsupported, unpatchable device online — the worst of both worlds. Aligning the refresh with your next license cycle stops you from renewing a subscription on gear with zero support runway.
What each milestone means in practice
- End of Sale (2016-05-09): the last day Cisco accepted new MR26 orders. Everything after this date has been consuming the support tail.
- End of software maintenance (not separately listed): unlike IOS-XE platforms, Meraki cloud APs do not publish a distinct software-maintenance milestone; firmware support effectively ran to LDoS, after which the branch froze.
- Last Day of Support / LDoS (2023-05-09): the hard wall, now three years behind us. No firmware, no PSIRT fixes, no TAC, no RMA. Every MR26 still online is operating with no safety net.
The recommended replacement: Catalyst CW9164I
Cisco's migration path moves the MR26 to a Catalyst CW9164I (PID CW9164I-MR), managed from the same Meraki dashboard. That is the detail that makes the refresh painless operationally: the Catalyst CW91xx Wi-Fi 6E access points run in cloud-managed mode under Meraki, so you keep the dashboard, the maps, the SSIDs, and the workflows your team already knows — while jumping the air interface forward by two-plus full generations (802.11n to 802.11ax/6E). The hardware delta is enormous:
- Wi-Fi 6E and three bands. The CW9164I is a tri-radio AP serving 2.4, 5, and 6 GHz, with a fourth dedicated dual-band scanning radio for security and RF analytics. The MR26 had no 6 GHz and no 802.11ac. The 6 GHz band alone adds up to 1,200 MHz of fresh, interference-free spectrum and seven additional 160 MHz channels — capacity the MR26 simply cannot reach.
- OFDMA, MU-MIMO, and modern efficiency. 802.11ax brings downlink and uplink OFDMA, MU-MIMO, BSS coloring, and Target Wake Time. These features pack far more clients into the same airtime — directly fixing the airtime starvation an 802.11n MR26 causes in any room with modern devices.
- Far higher throughput and uplink. The CW9164I uses 4x4 on 5/6 GHz (2x2 on 2.4 GHz) and ships a Multigigabit uplink (2.5G/5G mGig) versus the MR26's single 1 Gbps port. Aggregate client throughput moves from hundreds of megabits on the MR26 to multiple gigabits.
- Better radios and power. The CW9164I delivers full radio capability on 802.3at (PoE+), with 802.3bt (PoE++) unlocking maximum performance and peripherals. The MR26 ran on 802.3af. Confirm your switch PoE budget during planning (see the migration plan below).
Licensing: cloud-managed Catalyst on Meraki
The CW9164I is dual-managed: it can run under Catalyst 9800 / Catalyst Center with Smart Licensing, or in cloud-managed mode under the Meraki dashboard. For an MR26 fleet, cloud-managed is the natural path — you continue with Meraki licensing tied to your Meraki organization. Confirm two things before you order: that your dashboard organization and network are on a firmware track that supports CW91xx adoption, and that your license claim/migration is sequenced so new APs come online licensed on day one. This is the single most common thing teams overlook, and it is the difference between a clean cutover and APs sitting dark in the dashboard.
A practical migration plan
1. Assessment and inventory
Export an exact count of MR26-HW units from the dashboard and capture, per AP: physical location and mount, switch port and PoE class drawn, VLAN/SSID mappings, RF profile, channel/power plan, and current firmware. Flag any MR26s co-located with other EoL Meraki models (MR18, MR24, MR34) so you size one combined refresh rather than several piecemeal projects. Browse current Catalyst wireless options in our catalog while you scope quantities.
2. License and dashboard transition
Verify your Meraki org firmware supports CW9164I adoption, then sequence license claiming so the new APs license cleanly as they join. Because management stays on Meraki, your network templates, group policies, and SSID configs largely carry forward — but plan to build new RF profiles, because the MR26 had no 802.11ac or 6 GHz settings to migrate from in the first place.
3. Config and feature parity
Build a new RF profile that enables the 6 GHz band (WPA3 is mandatory on 6 GHz — confirm client support before you broadcast it), and modernize your SSID security off any WEP/WPA legacy modes the MR26 era tolerated. Map the old 2.4/5 GHz channel and power plans onto the richer tri-band layout, then re-test location analytics, BLE beacons, and Air Marshal/WIPS policy on the new scanning radio.
4. Physical: PoE, uplinks, and cabling
This is where an old fleet bites you. The MR26 ran on 802.3af and a 1 Gbps drop, so the access layer behind it may be a 1G PoE switch. The CW9164I wants a Multigigabit (2.5G/5G) port and 802.3at/bt power — on a 1G/af switch it will run but cap well below potential. Verify each switch port speed and the total PoE budget (a switch fully loaded with 6E APs can exceed an older switch's wattage), and plan Cat6/6A cabling to sustain mGig over distance. In many cases the MR26 access switch is itself EoL and should be refreshed in the same project.
5. Phased cutover and secure decommission
Cut over by zone, not all at once: replace MR26s in one area, validate roaming, throughput, and client onboarding, then move on. When you remove an MR26 permanently, unclaim it from the dashboard and wipe it from inventory so a decommissioned, unpatchable AP cannot be re-adopted or resold back into your environment. Dispose of hardware through a documented, asset-tracked process — important for regulated environments where chain of custody is auditable.
Procurement notes for regulated buyers
For federal, DoD, and SLED purchases, confirm TAA compliance and country-of-origin documentation up front, and use GSA/contract vehicles or a Government Purchase Card (GPC) where appropriate. Wi-Fi 6E hardware and mGig switching carry real lead times, and an already-past-LDoS fleet should not wait on a quarter-long backorder. Buying through an authorized Cisco partner protects your warranty, license entitlement, and supply-chain integrity — gray-market 6E APs frequently arrive with invalid or unclaimable licenses. As an authorized partner, uniqcli can validate your Meraki license migration, size the mGig and PoE requirements, and quote TAA-compliant CW9164I-MR units with full documentation.
Frequently asked questions
When did the Cisco Meraki MR26 reach end of support?
The MR26 (MR26-HW) went End of Sale on May 9, 2016, and reached its Last Day of Support (LDoS) on May 9, 2023 — it is already past support. There are no firmware updates, no PSIRT security fixes, and no TAC support or RMA hardware replacement. The AP may still adopt to the dashboard, but it is unsupported and unpatchable today.
What is the recommended replacement for the Meraki MR26?
Cisco recommends the Catalyst CW9164I (PID CW9164I-MR), a Wi-Fi 6E tri-radio access point that runs in cloud-managed mode on the same Meraki dashboard. It jumps from the MR26's 802.11n design to 802.11ax with the 6 GHz band, OFDMA, MU-MIMO, 4x4 radios, and a Multigigabit (2.5G/5G) uplink versus the MR26's single 1 Gbps port.
Can the Catalyst CW9164I be managed from the Meraki dashboard like my MR26?
Yes. The CW9164I is dual-managed and runs natively in cloud-managed mode under the Meraki dashboard, so your organization, networks, SSIDs, group policies, and maps carry forward. It can alternatively run under Catalyst 9800 / Catalyst Center with Smart Licensing if you later move to controller-based management.
Will my existing switches and PoE support the CW9164I?
Possibly not without an upgrade. The MR26 ran on 802.3af and a 1 Gbps uplink, so its access switch may be 1G/af. The CW9164I wants a Multigigabit (2.5G/5G) port and 802.3at/bt power; on a 1G/af switch it works but caps below potential. Verify each port speed and total PoE budget, plan Cat6/6A cabling, and refresh the access switch in the same project if it is also EoL.
Is it really urgent if the MR26 still passes traffic?
Yes. Because the MR26 has been past LDoS since May 2023, any new vulnerability against it is permanent — a direct finding under FedRAMP, CMMC, HIPAA, and PCI DSS. You have no RMA coverage if a unit fails, and you are still paying Meraki licensing on unsupported hardware. Refreshing to the CW9164I restores a patchable, supported, audit-clean wireless edge.
Uniqcli Team
The Uniqcli Team is an authorized Cisco partner specializing in Catalyst wireless, switching, datacenter fabric, licensing, and managed services for U.S. federal, state, local, and education customers. We scope Cisco bills of materials, validate procurement paths (TAA, FIPS, contract vehicles), and deliver design, deployment, and managed operations.
Ready to scope your Cisco build?
Build a quoteMore from Resources
View all →
GuidesArista SDN vs Cisco ACI: Data Center Fabric Automation Compared
Cisco ACI and Arista CloudVision automate the data center from opposite directions — one is a policy fabric that enforces intent in hardware, the other is a management overlay on a standards-based underlay. Here's how the philosophies, lock-in, and team skills actually differ.
July 12, 2026 · 6 min read
GuidesCisco ASA vs Palo Alto: What You're Really Comparing
ASA holdouts weighing a jump to Palo Alto need an honest starting point: classic Cisco ASA and current Palo Alto hardware are a generation apart. Here's the real decision, and what a move actually costs.
July 12, 2026 · 5 min read
GuidesCisco DNA Essentials vs Advantage: Choosing the Right Subscription Tier
Cisco DNA Essentials vs Advantage is a separate decision from the perpetual Network Essentials/Advantage choice on the switch itself. Here's how the two axes fit together, and where the retired Premier tier went.
July 12, 2026 · 7 min read