Skip to content

CVE-2026-76498 CVE-2026-76499 CVE-2026-76500

Cisco APIC hardening release fixes access control, neutralization and resource flaws (CVE-2026-76498, CVE-2026-76499, CVE-2026-76500)

Critical 9.8 Vendor: Cisco Published

Cisco's October 2026 APIC hardening release fixes multiple internally discovered vulnerabilities rated 9.8, exploitable over the network without credentials. No workaround; Cisco advises applying the fixed release for affected 5.2 versions.

What happened

On 7 October 2026 Cisco published a security hardening release for Cisco Application Policy Infrastructure Controller (APIC) following an internal security review. Three vulnerability groups are tracked under the release: CVE-2026-76498 covers improper access control (CWE-284), CVE-2026-76499 covers improper neutralization (CWE-707), and CVE-2026-76500 covers improper control of a resource through its lifetime (CWE-664).

Each has a CVSS 3.1 base score of 9.8 (Critical) with the same network vector: low attack complexity, no privileges required, no user interaction, and high impact on confidentiality, integrity and availability. An unauthenticated attacker who can reach APIC over the network could therefore exploit them without credentials.

Cisco PSIRT states it is not aware of any public announcements or malicious use of these vulnerabilities.

Who is affected

The affected product is Cisco Application Policy Infrastructure Controller (APIC). Cisco lists these releases as affected: 5.2(1g), 5.2(2e), 5.2(2f), 5.2(2g), 5.2(2h), 5.2(3f), 5.2(3e), and 5.2(3g). If you run APIC, compare the installed version against this list and against the fixed release information in Cisco's advisory.

What to do now

  1. Apply Cisco's October 2026 security hardening release. The fixed software releases are listed in Cisco's advisory; use the release that corresponds to your version.
  2. Treat this as urgent. The vulnerabilities carry a CVSS 3.1 base score of 9.8 and require no credentials or user interaction.
  3. Until patching is complete, restrict network access to APIC to trusted management networks or jump hosts. Cisco states there are no workarounds that address these vulnerabilities, so this is containment rather than mitigation.
  4. After applying the update, verify the installed APIC version is no longer one of the affected releases listed above.

Beyond the patch

Beyond the patch, the score and network vector make exposure the immediate concern: an APIC reachable from the wrong network is the kind of open service that Virtual CISO Services (vCISO) helps identify and close before an advisory lands. Cisco's release also sets the patch-cycle clock for your software estate; Supply Chain Defense & Third-Party Risk tracks the software you run and how quickly vendors fix what you depend on.

Affected and fixed versions

ProductAffectedFixed in
CVE-2026-76498, CVE-2026-76499, CVE-2026-76500
Cisco Application Policy Infrastructure Controller (APIC)
5.2(1g)
5.2(2e)
5.2(2f)
5.2(2g)
5.2(2h)
5.2(3f)
5.2(3e)
5.2(3g)
No fixed version listed yet

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.