Advisory summary
Multiple vulnerabilities in the web-based management interface and API endpoints of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow a remote attacker to gain unauthorized access, access sensitive information, cause a denial of service (DoS) condition, or elevate privileges.
For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ssm-access-nttb2dhE For further documentation of improvements and fixes in Cisco License On-Prem, see Cisco License (Smart Software Manager) On-Prem Security Hardening Release.
Security Impact Rating: Critical CVE: CVE-2026-20328,CVE-2026-76437,CVE-2026-76452,CVE-2026-76454
What the vendor says is affected
The collected bulletin did not provide a separate affected-products list. Check the original bulletin before making an exposure decision.
What the vendor recommends
Cisco has released software updates that address these vulnerabilities.
Review the complete instructions on the vendor's siteWhen this advisory changed
- Published by Cisco
The publication date reported by the vendor.
- Added to SecurityAlert
We collected the advisory from the official source.