Cisco
Cisco Smart License: vulnerabilities and CVEs
Cisco Smart License has 8 published vulnerabilities, 8 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.
CVEs8
Last 12 months8
Critical3
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-76501 | Critical (9.8) | — | — | Oct 7, 2026 | A vulnerability in the Segment Routing over IPv6 (SRv6) Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute… |
| CVE-2026-76486 | Critical (9.8) | — | — | Oct 7, 2026 | A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root… |
| CVE-2026-76471 | Critical (9.8) | — | — | Oct 7, 2026 | The vulnerability is due to insufficient input validation of data that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP request to the NX-API of an affected device. A… |
| CVE-2026-76456 | High (8.6) | — | — | Oct 7, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening… |
| CVE-2026-76453 | High (8.8) | — | — | Oct 7, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening… |
| CVE-2026-20173 | Medium (5.8) | — | — | Oct 7, 2026 | A vulnerability in Cisco NX-OS Software could allow an unauthenticated, remote attacker to exhaust system resources, causing a denial of service (DoS) condition. This vulnerability exists because rate limiting was… |
| CVE-2026-20038 | Medium (5.8) | — | — | Oct 7, 2026 | A vulnerability in the endpoint group (EPG) contract functionality of Cisco Nexus 9000 Series Fabric Switches in ACI Mode could allow an unauthenticated, remote attacker to bypass configured EPG contracts. This… |
| CVE-2026-20032 | Medium (4.4) | — | — | Oct 7, 2026 | A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, local attacker with low privileges to escape the Python sandbox and gain unauthorized access to the underlying operating… |
📰 Related news
- Alert Cisco patches 24 vulnerabilities across NX-OS, APIC, Meraki and License On-Prem, including one rated 10 out of 10
- Follow-up · active exploitation CISA confirms active exploitation of the critical Cisco Catalyst SD-WAN Manager flaw (CVE-2026-76504)
- Alert Cisco patches a critical Catalyst SD-WAN Manager flaw that grants admin access without credentials