Cisco has disclosed CVE-2026-76500, a set of internally discovered vulnerabilities in the Cisco Application Policy Infrastructure Controller (APIC) that Cisco scores CVSS 9.8 (Critical).
What Is It
Cisco's APIC engineering team ran a full internal security review of the product. The review found multiple vulnerabilities, and Cisco has released software hardening releases to address them. CVE-2026-76500 tracks the issues involving improper control of a resource through its lifetime. These fall under the Common Weakness Enumeration (CWE) Pillar CWE-664.
The advisory does not give technical details about the individual flaws. NVD published the record on 2026-10-07, and its status is currently "Received."
Why It Matters
Cisco PSIRT, as the CNA, scored this CVE at 9.8 (Critical) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That score means:
- Network-reachable, with low attack complexity
- No privileges and no user interaction required
- High impact to confidentiality, integrity, and availability
APIC is the central controller in Cisco's data center fabric. If these flaws can be exploited remotely without authentication, as the CVSS vector indicates, they are a serious risk to the network infrastructure APIC manages.
Exploitation status: CVE-2026-76500 is not currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. The supplied data contains no confirmation of active exploitation and no KEV-mandated remediation deadline.
What's Vulnerable
The affected product is Cisco Application Policy Infrastructure Controller (APIC). Cisco lists affected releases across five software trains:
- 5.2: 5.2(1g) through 5.2(8i), including the 5.2(2x), 5.2(3x), 5.2(4x), 5.2(5x), 5.2(6x), 5.2(7x) and 5.2(8x) builds
- 5.3: 5.3(1d), 5.3(2a), 5.3(2b), 5.3(2c), 5.3(2d), 5.3(2e), 5.3(2f)
- 6.0: 6.0(1g) through 6.0(9f), including the 6.0(2x) through 6.0(8x) builds
- 6.1: 6.1(1f), 6.1(2f), 6.1(2g), 6.1(3f), 6.1(3g), 6.1(4h), 6.1(5e)
- 6.2: 6.2(1f), 6.2(1g), 6.2(2e)
For any version not listed, the record sets the default status to "unknown." Treat unlisted APIC builds with caution until you've checked them against Cisco's advisory.
Patch Status
Cisco says it has published software hardening releases that fix these vulnerabilities. The NVD record does not name the fixed release numbers.
APIC administrators should:
- Check the Cisco advisory linked below for fixed releases in their software train.
- Find every APIC deployment running an affected version.
- Upgrade to the hardened release Cisco recommends.
Cisco's CVSS vector rates the flaw as network-exploitable with no privileges required, though the advisory gives no technical details that confirm this. Until patching is finished, limit network access to APIC management interfaces as a precaution.
Sources
- Cisco Security Advisory: cisco-sa-hardening-apic-UOXWtfh
- NVD: CVE-2026-76500
- CISA Known Exploited Vulnerabilities Catalog (not listed at time of writing)