AI analysis
CVE-2026-76484 covers insufficient protection against code injection (CWE-94) in Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem). Cisco found the issues in an internal security review and is addressing them in software hardening releases; the advisory data does not describe a specific injection point or list affected version ranges. CVSS 3.1 rates the flaw 8.8 (high): a network attacker with low privileges and no user interaction can fully compromise confidentiality, integrity, and availability of the affected system. The product is an on-premises Cisco licensing appliance used by organizations that manage smart licenses locally. It is not listed in CISA KEV, and no public proof-of-concept is known.
What to do: Install the Cisco software hardening releases for Cisco License On-Prem (formerly SSM On-Prem) as soon as Cisco publishes them for your deployment, and confirm the running build against the Cisco PSIRT advisory. Until patched, restrict network access to the appliance to trusted administrators and monitor Cisco security advisories, since no specific fixed version range is stated in the source data.
Affected
| Cisco License On-Prem (formerly Cisco Smart Software Manager On-Prem / SSM On-Prem) | — |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76484 are related to issues with insufficient protection against code injection that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-94.