high Cisco · Exploits

Cisco Patches Four License On-Prem Flaws, Including a CVSS 10.0 Signature Bug

Data graphic: Cisco License On-Prem is patched for four flaws, led by CVE-2026-76482 at CVSS 10.0 Critical improper cryptographic signature verification . Fix is 10-202609 or later, no workaround, Cisco PSIRT knows of no malicious use.
AK

Threat intelligence editor · Published Oct 9, 2026, 9:40 PM EDT

Cisco License On-Prem (formerly SSM On-Prem) has four flaws up to CVSS 10.0, no workaround. Upgrade to 10-202609; version 9 must migrate. No known exploitation.

Cisco patches four flaws in License On-Prem, including a CVSS 10.0 signature-verification bug

Cisco has released a hardening update for Cisco License On-Prem, the server formerly called Smart Software Manager (SSM) On-Prem, fixing four vulnerabilities rated up to CVSS 10.0. There is no workaround, and the only fix is to upgrade. Cisco's PSIRT says it is not aware of public announcements or malicious use. None of the four CVEs appears in CISA's Known Exploited Vulnerabilities catalog as of the 2026-10-08 release.

What was fixed

The advisory, cisco-sa-hardening-ssm-Ph77wdhf, was published on 2026-10-07 and rated Critical. Cisco grouped the findings by weakness class and assigned one CVE to each class. Each score therefore reflects the most severe single flaw within that class, not an average.

CVECVSSWeakness
CVE-2026-7648210.0CWE-347, improper verification of cryptographic signature
CVE-2026-764809.8CWE-306, missing authentication for critical function
CVE-2026-764839.1CWE-522, insufficiently protected credentials
CVE-2026-764848.8CWE-94, improper control of code generation (code injection)

NVD's records for all four CVEs (status "Awaiting Analysis", scores supplied by Cisco's PSIRT) give the vectors:

CVEVectorPrivileges needed
CVE-2026-76482AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HNone; scope changed
CVE-2026-76480AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HNone
CVE-2026-76483AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NNone
CVE-2026-76484AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HLow (an authenticated account)

So three of the four need no login, and the code-injection flaw (CVE-2026-76484) needs a low-privileged account. CISA's SSVC entries in the NVD records rate exploitation "none" for CVE-2026-76480, -76482 and -76483, with automatable "yes" and technical impact "total"; CVE-2026-76484 is rated automatable "no". Cisco's public text does not say which endpoint or function each flaw sits in, and we have not seen a proof of concept.

Who is exposed

Data graphic: Cisco License On-Prem release status. 9-202601 and earlier: migrate. 10-202608 and earlier: vulnerable. 10-202609 and later: fixed. Four CVEs scored 10.0, 9.8, 9.1 and 8.8 CVSS.

Affected releases and CVSS scores for the four CVEs.

Release trainStatusAction
9-202601 and earlierVulnerableMigrate to a fixed release
10-202608 and earlierVulnerableUpgrade to 10-202609
10-202609 and laterNot vulnerableNone

Cisco Smart Licensing Utility is not affected. Cisco says the flaws affect License On-Prem "regardless of the software configuration", so no setting takes an instance out of scope, and older releases called SSM On-Prem are affected too. Anyone running the on-premises License server in either release train is in scope. Version 9 has no in-train fix, so those deployments need a move to version 10.

Cisco says the flaws were found during internal security testing using existing processes as well as frontier AI models. The advisory does not name the models or say which of the four flaws they surfaced.

Why a license server matters

A licensing server can look like back-office plumbing. It is worth treating as more than that, though the following is our inference rather than something Cisco states. On-prem license managers typically sit inside the management network and exchange data with the devices they license. A server that accepts forged signed data (CWE-347), exposes a function without authentication (CWE-306), or leaks stored credentials (CWE-522) is a plausible foothold from which an attacker could reach other systems. The advisory does not describe any such chain. What it does tell us is that CVE-2026-76482 is scored with a changed scope, which is reason enough to treat the server as a sensitive asset. (We covered similar Cisco management-plane flaws in the SD-WAN Manager authentication bypass, the Nexus NX-OS root RCEs and the Cisco ISE zero-day.)

The credential and code-injection classes compound the risk. If credentials stored on the server can be recovered, an attacker who gets in once may keep access after the immediate bug is closed. Rotation after patching is a reasonable precaution, though Cisco does not require it.

What defenders should do

  1. Find every instance. Inventory Cisco License On-Prem and legacy SSM On-Prem servers, including test and lab copies. Check the installed release string against the table above.
  2. Upgrade to 10-202609 or later. This also covers the companion advisory. For version 9 installations, plan the migration now. No workaround exists, so mitigations such as disabling a feature are not on offer.
  3. Restrict access in the meantime. Limit network reach to the server's web interface and API to the management hosts and licensed devices that need it. This does not fix the flaws, and Cisco does not list it as a mitigation, but it reduces who can attempt the unauthenticated paths.
  4. Review for compromise on older builds. Look for unexpected administrator accounts, changed configuration, or unfamiliar outbound connections from the server. Rotate credentials stored on or used by the server after upgrading.
  5. Watch for changes in status. Re-check the advisory and the KEV catalog. Public technical details tend to follow a Critical fix, and exploitation status can change quickly.

Related advisory

Cisco published a second advisory for the same product on the same day, cisco-sa-ssm-access-nttb2dhE, covering four more CVEs. Its fixed-release table matches the first: 9-202601 and earlier must migrate to a fixed release, releases earlier than 10-202608 should go to 10-202608, and 10-202609 is not vulnerable. So 10-202609 or later closes all eight CVEs published on 7 October.

  • CVE-2026-20328 (Critical, 9.1): an unauthenticated attacker can reset the password of any account, including administrators.
  • CVE-2026-76454 (Critical, 9.1): an unauthenticated flaw in the Smart Licensing Utility API of Cisco License On-Prem. This is a component of the server, not the separate Cisco Smart Licensing Utility product, which both advisories treat as unaffected.
  • CVE-2026-76437 (command injection) and CVE-2026-76452 (SQL injection), both Medium at 4.9, need administrator credentials.

Cisco credits outside reporters for this batch: Gabriele Paris of NATO Cyber Security Centre for CVE-2026-20328, -76437 and -76452, and Trung Nguyen of CyStack for CVE-2026-76454.

What we could not confirm

  • Which AI models were used, and which flaws they found.
  • Which component each of the four flaws sits in; Cisco does not say.

Sources

Keep reading

All latest →
  1. highExploitsSplunk Enterprise search head clusters exposed to critical unauthenticated RCE in Patroni API (CVE-2026-76268)5 min
  2. criticalExploitsAtlassian Patches Unauthenticated File Read CVE-2026-21589 Across Eight Data Center Products7 min
  3. highExploitsCitrix NetScaler SAML Memory Flaw CVE-2026-88779 Added to CISA KEV, and Last Month's Patch Does Not Cover It5 min
  4. watchExploitsNext.js Dev Server MCP Flaw CVE-2026-94486 Lets Malicious Sites Read Source Snippets and Logs5 min
  5. elevatedExploitsWindows Cross Device flaw gives local users SYSTEM, with a public PoC5 min
  6. criticalExploitsArista VeloCloud Orchestrator Exploited at CVSS 10.0, With No Fix Listed for Two Release Trains4 min