Cyber & AI intelligence
Wasteland.
Briefs indexed3048
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-76500 2026-10-07

CVE-2026-76500: Critical Resource-Control Flaws in Cisco APIC Found in Internal Review

"Cisco has disclosed CVE-2026-76500, a set of internally discovered vulnerabilities in the Cisco Application Policy Infrastructure Controller (APIC) that Cisco scores CVSS 9.8 (Critical)."

Cisco has disclosed CVE-2026-76500, a set of internally discovered vulnerabilities in the Cisco Application Policy Infrastructure Controller (APIC) that Cisco scores CVSS 9.8 (Critical).

What Is It

Cisco's APIC engineering team ran a full internal security review of the product. The review found multiple vulnerabilities, and Cisco has released software hardening releases to address them. CVE-2026-76500 tracks the issues involving improper control of a resource through its lifetime. These fall under the Common Weakness Enumeration (CWE) Pillar CWE-664.

The advisory does not give technical details about the individual flaws. NVD published the record on 2026-10-07, and its status is currently "Received."

Why It Matters

Cisco PSIRT, as the CNA, scored this CVE at 9.8 (Critical) with the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. That score means:

APIC is the central controller in Cisco's data center fabric. If these flaws can be exploited remotely without authentication, as the CVSS vector indicates, they are a serious risk to the network infrastructure APIC manages.

Exploitation status: CVE-2026-76500 is not currently listed in CISA's Known Exploited Vulnerabilities (KEV) catalog. The supplied data contains no confirmation of active exploitation and no KEV-mandated remediation deadline.

What's Vulnerable

The affected product is Cisco Application Policy Infrastructure Controller (APIC). Cisco lists affected releases across five software trains:

For any version not listed, the record sets the default status to "unknown." Treat unlisted APIC builds with caution until you've checked them against Cisco's advisory.

Patch Status

Cisco says it has published software hardening releases that fix these vulnerabilities. The NVD record does not name the fixed release numbers.

APIC administrators should:

  1. Check the Cisco advisory linked below for fixed releases in their software train.
  2. Find every APIC deployment running an affected version.
  3. Upgrade to the hardened release Cisco recommends.

Cisco's CVSS vector rates the flaw as network-exploitable with no privileges required, though the advisory gives no technical details that confirm this. Until patching is finished, limit network access to APIC management interfaces as a precaution.

Sources