Cyber & AI intelligence
Wasteland.
Briefs indexed3048
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-76480 2026-10-07

Cisco License On-Prem Missing Authentication Flaw (CVE-2026-76480) Rated Critical 9.8

"Cisco has disclosed CVE-2026-76480, a critical missing-authentication issue (CWE-306) in Cisco License On-Prem that was found during an internal security review and fixed in software hardening releases."

Cisco has disclosed CVE-2026-76480, a critical missing-authentication issue (CWE-306) in Cisco License On-Prem that was found during an internal security review and fixed in software hardening releases.

What Is It

CVE-2026-76480 tracks multiple vulnerabilities in Cisco License On-Prem, which was formerly called Cisco Smart Software Manager On-Prem (SSM On-Prem). Cisco's engineering team found them during a comprehensive internal security review. Cisco groups them under CWE-306, Missing Authentication for Critical Function, and describes them as improper authentication issues.

Cisco PSIRT submitted the CVE, and NVD published it on 2026-10-07. Its NVD status is "Received," so NVD has not yet completed its own analysis.

Why It Matters

Cisco PSIRT scores this CVE at 9.8 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That means:

CISA's SSVC assessment rates the flaw as automatable with a total technical impact. The same assessment records exploitation as none. CVE-2026-76480 does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog, so KEV does not confirm active exploitation as of publication.

License servers are often central to an organization's Cisco estate. An unauthenticated critical flaw in one should get priority even before anyone sees it exploited.

What's Vulnerable

The NVD record lists Cisco License On-Prem as affected in these versions:

The record does not include any affected CPEs.

Patch Status

Cisco says it has released software hardening updates that address these vulnerabilities. The NVD record does not name the fixed versions. Administrators should check the Cisco Security Advisory below for the fixed releases and upgrade guidance, and should treat any deployment on the versions above as affected until they upgrade.

Because the CVE is not in the KEV catalog, CISA has set no required action or due date for it.

Sources