Vulnerabilities & Exploits · Web App Attack

Cisco License On-Prem flaws hit the control plane

NCSC-NL said on Oct. 8 that Cisco fixed eight vulnerabilities in Cisco License On-Prem and Cisco Smart Software Manager On-Prem, including critical flaws in the web interface and API. The advisory covers both unauthenticated bugs and authenticated paths to higher-impact access.

The weak point is the management surface itself. Unauthenticated attackers can reset passwords, write files, or trigger denial of service, while authenticated admins can reach paths that allow root-level command execution and access to internal database content.

For anyone exposing this appliance on a management network, the issue is not just availability. A reachable instance sits in the control plane, so compromise can turn a licensing server into a foothold for credential, file, and system-control abuse.

3 sources · 5h ago

CVEs in this update

8 CVEs

Across Cisco License On-Prem.

5 critical · 1 high · 2 medium · 0 low

0 in CISA KEV · 0 with EPSS above 1%

Highest severity: CVE-2026-76482 · 10.0 CRITICAL

Timeline

Sources

Vendor digest: Cisco

Part of the PlainSec briefing for 2026-10-08

Every edition of this story: Cisco License On-Prem flaws hit the control plane

More from today