CVE-2026-76454 is a critical (CVSS 9.1) bug in the Smart Licensing Utility API of Cisco License On-Prem that lets an unauthenticated remote attacker write arbitrary files or cause a denial of service.
What Is It
The vulnerability is in the Cisco Smart Licensing Utility API of Cisco License On-Prem, which was formerly called Cisco Smart Software Manager On-Prem (SSM On-Prem). According to Cisco, the cause is improper input validation combined with a lack of authentication in the management API. An attacker can exploit it by sending a crafted request to the affected API. If the attack works, the attacker can modify system files or cause a denial-of-service (DoS) condition.
Cisco classifies the weakness as CWE-23 (Relative Path Traversal).
Why It Matters
Cisco PSIRT scores this flaw CVSS 3.1 9.1 (Critical) with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H:
- Network-reachable: no credentials and no user interaction are needed.
- Low attack complexity: a single crafted request is enough.
- High impact on integrity and availability: an attacker can write arbitrary files to the system or take the application offline. Confidentiality impact is rated None.
CISA's SSVC assessment rates the flaw as automatable with total technical impact. That combination makes it a likely target for mass scanning once exploit details come out.
Exploitation status: CVE-2026-76454 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. CISA's SSVC record lists exploitation as "none" as of publication (2026-10-07).
What's Vulnerable
Cisco lists the following Cisco License On-Prem versions as affected:
- Release 1.x: 1.1, 1.2, 1.3, 1.4
- 6.3.0
- 7-202001
- 8-series: 8-202004 through 8-202404, including 8-202006, 8-202008, 8-202010, 8-202012, 8-202102, 8-202105, 8-202108, 8-202112, 8-202201, 8-202206, 8-202212, 8-202302, 8-202303, 8-202304 and 8-202308
- 9-series: 9-202201, 9-202406, 9-202407, 9-202410, 9-202412, 9-202501, 9-202502, 9-202504, 9-202507, 9-202510, 9-202601
- 10-202606
The release lines covered go back to the product's SSM On-Prem days, so older deployments are also affected.
Patch Status
The supplied NVD record does not name fixed versions or workarounds. Because CVE-2026-76454 is not in KEV, CISA has issued no required action or due date. Administrators should:
- Review the Cisco Security Advisory
cisco-sa-ssm-access-nttb2dhEfor fixed releases and mitigation guidance. - Treat any internet-facing or broadly reachable License On-Prem management API as high priority, since no authentication is needed to exploit it.
The NVD record is in "Received" status and has not been fully analyzed yet. Expect updates.