CISCO has issued four advisories covering 18 CVEs across its License On-Prem, APIC and Meraki portfolios, with the most severe hitting License On-Prem itself. The updates include a CVSS 10 vulnerability tied to cryptographic signature verification (CVE-2026-76482) as well as an unauthenticated password-reset flaw (CVE-2026-20328). Cisco says none of the issues are known to be exploited at present, but the company urges rapid patching. In total, the advisory set ranks 9.0+ to 10.0 criticality for several flaws, with the most severe attributed to License On-Prem hardening releases.
The License On-Prem flaws include an unauthenticated password reset (CVE-2026-20328, CVSS 9.1) and an unauthenticated API weakness (CVE-2026-76454, CVSS 9.1) that can crash the app or allow file writes. Additional admin-facing flaws include a root-privilege command injection (CVE-2026-76437, CVSS 4.9) and a SQL injection that could expose parts of the internal database (CVE-2026-76452, CVSS 4.9–4.8).
The hardening releases for License On-Prem add CVE groups centred on cryptographic verification (CVE-2026-76482, CVSS 10), missing authentication for critical functions (CVE-2026-76480, CVSS 9.8) and related exposure and input-handling weaknesses. APIC and Meraki also receive hardening updates: APIC consolidates several 9.8-rated flaws (access control, injection, resource handling), while Meraki covers seven groups, including a high-severity buffer issue (CVE-2026-76464, CVSS 9.6).
Affected versions span all License On-Prem releases, APIC regardless of configuration, and Meraki across MX, MR, MS, MV, MG and Campus Gateway lines; Smart Licensing Utility is unaffected. Patches are explicitly recommended: License On-Prem should move to 10-202609 (older 9-202601 and earlier must migrate), APIC to 6.0(9h)/6.1(6g)/6.2(3g) (5.3 and earlier must migrate), and Meraki firmware updates such as MX 26.1.7 or 26.2.3 and MR 33.1.3, with mid-November 2026 targets for some Campus Gateway and MS builds. Until those land, Cisco advises tightening management interface access where possible.