CVE-2026-76437
A vulnerability in the web-based user interface of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. This vulnerability is due to improper validation of user-supplied content within configurations that are submitted to the web-based management interface. An attacker could exploit this vulnerability by updating configurations within the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges. To exploit this vulnerability, the attacker must have valid administrative credentials.
1 article across 1 outlet · first covered Oct 7, 2026 · latest Oct 7, 2026
Coverage timeline
-
Cisco Patches Critical Flaw That Could Break License On-Prem Securitysecurityonline.info · Oct 7, 2026