Cisco License On-Prem Exposes Unauthenticated Password Reset
Vulnerable License On-Prem installations allow unauthenticated password reset, according to Cisco’s 7 October advisory. The operational priority is to identify the appliance, restrict unnecessary management access and choose a release that addresses the complete security picture.
Which product needs attention?
The release notes identify Cisco License On-Prem as the redesigned Smart Software Manager On-Prem, or SSM On-Prem. It manages products and licences locally rather than requiring licensed devices to connect directly to Cisco License Central. Smart Licensing Utility is unaffected.
An inventory entry that says only “Smart Licensing” is too vague. Confirm the product name on the appliance, record the installed release and assign an owner before choosing a remediation path. A familiar vendor name is not enough to determine exposure.
Four distinct access paths
These are independent vulnerabilities, not a demonstrated exploit chain.
- CVE-2026-20328 allows remote password reset without authentication, including administrators.
- CVE-2026-76454 permits unauthenticated API file writes or denial of service.
- CVE-2026-76437 requires administrator credentials for root commands; the additional privilege is shutdown.
- CVE-2026-76452 requires administrator credentials to read otherwise restricted database contents.
Keep the distinctions intact when writing an incident ticket. File modification is not, by itself, evidence that an attacker obtained a shell. Likewise, an administrator-only issue should not be described as an unauthenticated attack.
Why stopping at the first fix is insufficient
Release 10-202608 fixes these four issues; 9-202601 and earlier require migration. Cisco lists 10-202609 as unaffected.
However, a separate October security-hardening advisory still affects 10-202608 and earlier and identifies 10-202609 as the fix. It covers authentication, signature verification, credential protection and code-injection weaknesses found during internal testing. Cisco says these issues were not known to be actively exploited. They are separate from the four vulnerabilities discussed above.
BlackTree’s recommendation is therefore to assess both advisories together when selecting the target release. Closing the password-reset ticket at the first fixed build can leave a separate security task unresolved. Do not treat “fixed for this advisory” as “fully current”.
Plan the migration, not just the patch
The release notes list a direct upgrade to 10-202609 from 10-202608, not from every older build. They advise contacting Cisco TAC when the current release is absent from the supported path. Before upgrading a virtual-machine deployment, Cisco recommends a database backup. After a problematic move from version 9 to 10-202606 or later, it warns against reverting a version-9 snapshot and instead directs customers to TAC for supported recovery.
This makes the maintenance plan part of the security decision. Record the starting build, supported intermediate steps, backup evidence and recovery contact before the change. A download alone does not establish a safe migration path.
What defenders should verify
- Check management exposure. Establish which interfaces accept traffic from untrusted networks. Reducing unnecessary reachability can lower immediate risk, but it does not repair vulnerable software.
- Review account activity. Examine privileged-account changes and relevant authentication history. Rotate credentials where evidence or local policy warrants it; a successful upgrade cannot explain earlier account activity.
- Investigate without overstating. Review unexpected file changes, service interruption, configuration changes, shutdown events and unusual database access as defensive checks, not as proof of compromise.
- Verify the running build. Record the installed release after maintenance and compare it with both advisories. A completed change ticket is not evidence that the appliance loaded the intended software.
No workaround is available. At publication, Cisco reported no known public announcements or malicious use. That is a dated statement about Cisco’s awareness, not a guarantee that exploitation has never occurred.
The operational checks above are BlackTree recommendations, not completed tests or evidence of an incident. Updated on 8 October 2026 to complete the product, vulnerability and upgrade guidance.
Our Cisco SD-WAN admin-access analysis covers a different product and advisory. The shared lesson is methodological: match product, release and access prerequisites before deciding what a patch closes.


