AI analysis
CVE-2026-76482 covers internally discovered improper input-verification flaws in Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), grouped under CWE-347. Cisco says the issues were found in an internal security review and addressed in software-hardening releases; the description does not specify the exact input or request that triggers them. The CVSS 3.1 score is 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H), indicating a low-complexity, unauthenticated network attack with high impact to confidentiality, integrity, and availability and a scope change. Affected version ranges are not stated in the provided data. It is not listed in CISA KEV, and no public proof-of-concept is known.
What to do: Install the Cisco software-hardening release for License On-Prem (formerly SSM On-Prem) identified in the Cisco PSIRT advisory for CVE-2026-76482; exact fixed versions are not in this dataset. Until patched, restrict network access to the on-prem license server to trusted management networks and review logs for unexpected unauthenticated requests.
Affected
| Cisco License On-Prem (formerly Smart Software Manager On-Prem / SSM On-Prem) | — |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76482 are related to issues with improper input verification that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-347.