Cisco License On-Prem (formerly Smart Software Manager On-Prem), 7 Oct: unauthenticated admin password reset (CVE-2026-20328) and unauthenticated file-write API (CVE-2026-76454), both CVSS 9.1, plus a hardening release with a 10.0; fixed in 10-202609
Cisco published two Critical advisories on 7 October 2026 for Cisco License On-Prem, the on-premises licensing server previously sold as Smart Software Manager (SSM) On-Prem. The first covers four bugs. CVE-2026-20328 (CVSS 9.1) is a broken check in the password-reset process of the web management interface: a remote attacker with no account can reset the password of any user, including administrators, and log in as them. CVE-2026-76454 (CVSS 9.1) is in the Smart Licensing Utility API, which lacks authentication and input validation, so a crafted request can write arbitrary files on the server or knock it over. Two lower-rated bugs, an authenticated OS command injection through submitted configuration (CVE-2026-76437) and an authenticated SQL injection (CVE-2026-76452), score 4.9 each. Gabriele Paris of the NATO Cyber Security Centre reported CVE-2026-20328, -76437 and -76452, and Trung Nguyen of CyStack reported CVE-2026-76454. The second advisory is a Critical 'security hardening release' grouping four internally found bugs (CVE-2026-76480 at 9.8, CVE-2026-76482 at 10.0, CVE-2026-76483 at 9.1, CVE-2026-76484 at 8.8). Both advisories say every configuration is affected and there are no workarounds. Cisco PSIRT knows of no public disclosure or malicious use. License On-Prem servers usually sit inside the network holding entitlement data for every Cisco device an organisation licenses, so an exposed management page is the main worry.
- Product
- Cisco License On-Prem (formerly Cisco Smart Software Manager On-Prem). Not affected: Cisco Smart Licensing Utility.
- Versions
- All configurations. SSM On-Prem 9-202601 and earlier (migrate to a fixed release); License On-Prem 10-202608 and earlier for the hardening-release bugs (releases before 10-202608 for CVE-2026-20328/76454/76437/76452).
- CVSS
- (CVE-2026-20328); 9.1 (CVE-2026-76454); 4.9 (CVE-2026-76437, CVE-2026-76452); hardening release 10.0 (CVE-2026-76482), 9.8 (CVE-2026-76480), 9.1 (CVE-2026-76483), 8.8 (CVE-2026-76484)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (CVE-2026-20328); CVSS:3.1 - Exploited in Australia?
- unknown
- Patch to
- Upgrade to Cisco License On-Prem 10-202609, which is the first release that clears both advisories (10-202608 fixes only the four-bug advisory). SSM On-Prem 9-202601 and earlier must be migrated to the License On-Prem 10 line per Cisco's release notes. No workarounds; until upgraded, keep the web management interface and API reachable only from admin networks and review admin accounts for unexpected password resets.
Primary: Cisco Security Advisory — Cisco License (Smart Software Manager) On-Prem Vulnerabilities, cisco-sa-ssm-access-nttb2dhE (7 Oct 2026) · Vendor: Cisco Security Advisory — Cisco License (Smart Software Manager) On-Prem Security Hardening Release: October 2026 (7 Oct 2026) · CVE: CVE-2026-20328, CVE-2026-76454, CVE-2026-76437, CVE-2026-76452, CVE-2026-76480, CVE-2026-76482, CVE-2026-76483, CVE-2026-76484 · Cisco — License On-Prem 10-202609 release notes (upgrade and migration)
