CVE-2026-76454: Cisco License On-Prem

Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.

A vulnerability in the Cisco Smart Licensing Utility API of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an unauthenticated, remote attacker to write arbitrary files to the system or cause a DoS condition on an affected application. This vulnerability is due to improper input validation and a lack of authentication in the management API. An attacker could exploit this vulnerability by sending a crafted request to the affected API. A successful exploit could allow the attacker to modify system files or cause a DoS condition.

Affected products

  • Cisco Cisco License On-Prem: version 7-202001 only; version 1.1 only; version 6.3.0 only; version 8-202004 only; version 8-202006 only; version 1.2 only; …

Published 2026-10-07. Last modified 2026-10-08.