TL;DR
Cisco has published four advisories that cover 18 CVEs across License On-Prem, APIC and Meraki devices. The most severe Cisco License On-Prem vulnerabilities include a CVSS 10 signature verification flaw and an unauthenticated password reset bug. Cisco says none of the issues are known to be exploited.
- Total: 18 CVEs
- Severity: 9 Critical Β· 7 High Β· 2 Medium
- Actively exploited: None confirmed
- Highest severity: 10.0 (Critical Β· CVSSv3) β CVE-2026-76482
- Action: Apply the latest security updates now
Too many Cisco alerts in your inbox? Switch to one weekly digest, sorted by severity.
Try Team free for 14 daysNotable CVEs
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-76482 | 10 | Security Hardening Release | Not exploited |
| CVE-2026-76480 | 9.8 | Security Hardening Release | Not exploited |
| CVE-2026-76498 | 9.8 | Application Policy Infrastructure Controller Hardening Release: October 2026 - Improper Access Control | Not exploited |
| CVE-2026-76499 | 9.8 | Application Policy Infrastructure Controller Hardening Release: October 2026 - Improper Neutralization | Not exploited |
| CVE-2026-76500 | 9.8 | Application Policy Infrastructure Controller Hardening Release: October 2026 - Improper Control of a Resource Through its Lifetime | Not exploited |
| CVE-2026-76464 | 9.6 | Meraki Hardening Release October 2026 - Buffer Management | Not exploited |
| CVE-2026-20328 | 9.1 | Smart Software Manager On-Prem Arbitrary Account Password Reset | Not exploited |
| CVE-2026-76454 | 9.1 | Smart Software Manager On-Prem Unauthenticated API | Not exploited |
Why It Matters
Cisco License On-Prem, formerly Smart Software Manager On-Prem, tracks software licenses for whole fleets of Cisco gear. APIC is the controller for Cisco ACI data center fabrics. Meanwhile, Meraki devices run branch networks, Wi-Fi and SD-WAN for many firms. A takeover of any of them hands an attacker a central control point.
Three of the four advisories are “hardening releases.” Cisco found those bugs “during internal security testing using existing testing processes as well as frontier AI models.” It then grouped them by weakness class under single CVE IDs. The PSIRT “is not aware of any public announcements or malicious use” of any of these flaws.
How the Attacks Work
License On-Prem: Password Reset and API Flaws
The License On-Prem advisory lists four bugs reported by outside researchers. CVE-2026-20328 (CVSS 9.1) stems from “improper checks during the password reset process.” An unauthenticated attacker could reset the password of any account, “including high-privileged administrative user accounts.” Next, CVE-2026-76454 (9.1) lets an unauthenticated attacker write files or crash the app through an API that lacks authentication.
Gabriele Paris of the NATO Cyber Security Centre reported the password reset bug and two admin-only flaws. Trung Nguyen of CyStack reported the API bug.
The two admin-only flaws rate Medium at 4.9. CVE-2026-76437 is a command injection that runs with root privileges. Even so, Cisco notes that the only extra power it grants an admin is “the ability to turn off the system.” CVE-2026-76452 is a SQL injection that can expose parts of the internal database.
License On-Prem: Hardening Release
The License On-Prem hardening release adds four more CVE groups. CVE-2026-76482 covers improper verification of cryptographic signatures and scores a maximum 10.0. CVE-2026-76480 (9.8) covers missing authentication for critical functions. Others cover exposed credentials and code injection.
APIC and Meraki
The APIC hardening release brings three CVE groups, each rated 9.8. They cover access control, injection and resource handling flaws. Separately, the Meraki hardening release lists seven groups. The worst, CVE-2026-76464 (9.6), covers buffer overflows reachable from an adjacent network. The other six range from 7.4 to 8.8 and cover access control, integer errors, command injection, input validation, resource handling and control flow.
Cloud-managed Catalyst switches are handled separately. For those, Cisco points admins to its August 2026 IOS XE hardening advisory.
Affected Versions
The Cisco License On-Prem vulnerabilities affect all releases “regardless of the software configuration,” including older SSM On-Prem builds. APIC is affected regardless of configuration. The Meraki release hits MX, MR, MS, MV, MG and Campus Gateway devices. Cisco Smart Licensing Utility is not affected.
Patch and Mitigation Steps
Cisco lists no workarounds for any of the four advisories, so upgrading is the only fix:
- License On-Prem: upgrade to 10-202609. Releases 9-202601 and earlier must migrate.
- APIC: move to 6.0(9h), 6.1(6g) or 6.2(3g). Version 5.3 and earlier must migrate.
- Meraki: apply the listed firmware, such as MX 26.1.7 or 26.2.3 and MR 33.1.3.
Some Meraki fixes are not out yet. Campus Gateway 33.1.4 is due in mid-November 2026, and MS 18.1.9 is due in mid-October. Until those builds land, limit access to management interfaces. For License On-Prem, though, the fixed build is ready, so the Cisco License On-Prem vulnerabilities should top the patch list.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!