All CVEs
Vulnerability intelligence

CVE-2026-76437

Cisco Cisco License On-Prem CWE-78

A vulnerability in the web-based user interface of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. This vulnerability is due to improper validation of user-supplied content within configurations that are submitted to the web-based management interface. An attacker could exploit this vulnerability by updating configurations within the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges. To exploit this vulnerability, the attacker must have valid administrative credentials.

CVSS Score
4.9
Medium
EPSS — Exploit Probability
—
Awaiting FIRST.org data · checked 2026-10-07
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
NVD entry PoC / advisory

1 article across 1 outlet · first covered Oct 7, 2026 · latest Oct 7, 2026

Coverage timeline

Related CVEs — Cisco