AI analysis
Cisco Application Policy Infrastructure Controller (APIC) is affected by vulnerabilities tracked as CVE-2026-76500, which Cisco groups under CWE-664 (improper control of a resource through its lifetime) after an internal security review. The published description does not name a specific trigger, component, or fixed release; the issues are addressed in software hardening releases. CVSS 3.1 scores the issue 9.8 (critical) with network access, low attack complexity, no privileges required, no user interaction, and high impact to confidentiality, integrity, and availability, so a remote unauthenticated attacker could fully compromise an affected controller if the flaws are reachable as scored. Organizations that run Cisco APIC as the controller for Application Centric Infrastructure (ACI) fabrics are in scope, though affected version ranges are not stated in the data provided. There is no CISA KEV listing and no public proof of concept is known, so exploitation is not known to be occurring in the wild.
What to do: Review Cisco’s PSIRT advisory for CVE-2026-76500 and install the APIC software hardening release Cisco identifies as fixed; do not assume a version that is not listed there. Until that release is applied, keep APIC management interfaces off the public internet and restrict them to trusted administrative networks. Re-check the advisory for the affected and fixed version matrix before treating a fabric as patched.
Affected
| Cisco Application Policy Infrastructure Controller (APIC) | — |
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76500 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.