AI analysis
CVE-2026-76480 covers improper authentication issues (CWE-306, missing authentication for a critical function) in Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem). Cisco found the issues in an internal security review and is addressing them in software hardening releases. The CVSS 3.1 score of 9.8 indicates a remotely reachable flaw that needs no privileges and no user interaction and can fully compromise confidentiality, integrity, and availability of the affected system. Organizations running Cisco License On-Prem or SSM On-Prem are affected; exact version ranges are not stated in the provided data. It is not listed in CISA KEV and no public proof-of-concept is known.
What to do: Install Cisco's software hardening releases for Cisco License On-Prem (formerly SSM On-Prem) as published by Cisco PSIRT, and confirm the exact fixed versions in that advisory because they are not listed in this dataset. Until the update is applied, do not expose the product to untrusted networks and restrict access to trusted management hosts only.
Affected
| Cisco License On-Prem (formerly Cisco Smart Software Manager On-Prem / SSM On-Prem) | — |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76480 are related to issues with improper authentication that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-306.