← Back to CVE intelligence
CVE intelligence

CVE-2026-76500

Vulnerability intelligence

Published Oct 7, 2026Sources checked Oct 7, 2026
9.8CRITICALCVSS out of 10
What this means

Review the available evidence

CVE-2026-76500 and is rated Critical severity with a CVSS score of 9.8. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.

What to do next

Remediation and response

Cisco Security Advisories guidance

Vendor revision: Oct 7, 2026

To remediate the vulnerabilities that were disclosed on October 7, 2026, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories.

Cisco Security Advisories guidance

Vendor revision: Oct 7, 2026

To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class ��� Common Weakness Enumeration (CWE) ��� and assigned a single Common Vulnerabilities and Exposures identifier (CVE ID) to each CWE grouping.

CISA KEVNot listedBased on the latest collected catalog
EPSSUnavailableNo current score collected
Ransomware useNot markedCISA KEV ransomware field
Threat actors0Source-linked actor relationships
Overview

What is CVE-2026-76500?

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.   The vulnerabilities tracked by CVE-2026-76500 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.

Source: NVD