Vulnerabilities · 4h ago

Cisco License On-Prem flaws hit the control plane

NCSC-NL said on Oct. 8 that Cisco fixed eight vulnerabilities in Cisco License On-Prem and Cisco Smart Software Manager On-Prem, including critical flaws in the web interface and API. The advisory covers both unauthenticated bugs and authenticated paths to higher-impact access.

The weak point is the management surface itself. Unauthenticated attackers can reset passwords, write files, or trigger denial of service, while authenticated admins can reach paths that allow root-level command execution and access to internal database content.

For anyone exposing this appliance on a management network, the issue is not just availability. A reachable instance sits in the control plane, so compromise can turn a licensing server into a foothold for credential, file, and system-control abuse.

CVEs in this update

8 CVEs

Across Cisco License On-Prem.

5 critical · 1 high · 2 medium · 0 low

0 in CISA KEV · 0 with EPSS above 1%

Highest severity: CVE-2026-76482 · 10.0 CRITICAL

Timeline

Sources

3 sources covering this story

Entities

Vendor digest: Cisco

Part of the PlainSec briefing for 2026-10-08

Editions

Related stories