Summary
- Two Cisco advisories address License On-Prem management software.
- The hardening release includes CVE-2026-76480 and other issues with maximum severity.
- Cisco reported no known malicious exploitation when the advisory was published.
Cisco has released fixes for critical vulnerabilities affecting its License On-Prem management software, including weaknesses carrying a maximum severity rating and requiring customers to move to supported fixed releases.
The 7 October advisories concern License On-Prem, formerly Smart Software Manager On-Prem, which organisations use to administer software licensing in their own environments. One security hardening advisory groups four CVEs, including CVE-2026-76480, and carries a CVSS score of 10.0.
A separate advisory covers further access and application vulnerabilities. Cisco documents the affected and fixed software releases, allowing organisations to establish which versions require replacement or upgrade rather than relying solely on the aggregate severity scores.
The hardening notice states that there are no workarounds. Releases numbered 10-202608 and earlier in the relevant branch require an update to 10-202609, while legacy 9-series releases must migrate to a fixed version. Cisco advises customers to consult the published product release information for the correct upgrade path.
Management systems can create security exposure even when their immediate business function appears administrative. A licensing service may sit within networks used to operate other infrastructure, making its authentication, code execution and authorisation boundaries important to the surrounding environment.
The published severity ratings describe the consequences possible when the relevant preconditions are met. They do not establish that attackers have already used the weaknesses to compromise an organisation. Cisco said its security response team was not aware of malicious use of the vulnerability described in the hardening advisory at publication.
Cisco also says the hardening issues were found through internal security testing using established methods and frontier AI models. That statement describes the discovery process and should not be treated as evidence that the vulnerabilities arose from AI functionality in the product.
The fixes are separate from Cisco’s NX-OS switching advisories issued in the same October release cycle. Organisations operating both products have different inventories and upgrade dependencies, and the License On-Prem issues require their own assessment despite sharing a release date with the broader Cisco patch programme.
Licence-management infrastructure is a separate administrative function from the routers and switches that a company has deployed. Its compromise can still have material consequences because administrators depend on these systems to maintain inventories and software entitlements, and the systems may contain privileged information about the wider estate.
Cisco’s advisory addresses specific configurations of its on-premises management software, so the affected-product and fixed-version tables take precedence over any assumption that all Cisco products are exposed. Customers using a hosted service or a different management product cannot be placed in the affected population without checking the vendor’s stated scope.
Different vulnerability classes also carry different preconditions. Unauthorised disclosure, privilege escalation and code execution should not be presented as interchangeable outcomes. A maximum-severity score identifies a particularly serious scenario under the scoring method, but it does not establish either that attackers are already using the flaw or that every deployment is reachable from the internet.
Management planes warrant scrutiny because they are frequently given broad visibility into an organisation’s infrastructure while receiving less attention than the production devices they administer. Access restrictions, authentication arrangements and patching windows can therefore affect the practical exposure. These considerations follow from the software’s role and should not be mistaken for claims about a specific breached customer.
Cisco reported no known active exploitation in the relevant hardening advisory at publication. That statement describes the company’s knowledge at a particular moment; it does not guarantee that exploitation cannot occur or that the vulnerability is harmless. The evidence presently supports a remediation story, not an account of an ongoing attack campaign.
The separate NX-OS fixes published in the same Cisco maintenance cycle concern switching software and have already been reported by Cyber Insider. The License On-Prem package has its own affected software, privilege model and remediation guidance. Mixing their CVE lists would risk giving administrators incorrect advice about which component requires an update.




