CVE-2026-76498 CVE-2026-76499 CVE-2026-76500
Cisco APIC hardening release fixes access control, neutralization and resource flaws (CVE-2026-76498, CVE-2026-76499, CVE-2026-76500)
Cisco's October 2026 APIC hardening release fixes multiple internally discovered vulnerabilities rated 9.8, exploitable over the network without credentials. No workaround; Cisco advises applying the fixed release for affected 5.2 versions.
What happened
On 7 October 2026 Cisco published a security hardening release for Cisco Application Policy Infrastructure Controller (APIC) following an internal security review. Three vulnerability groups are tracked under the release: CVE-2026-76498 covers improper access control (CWE-284), CVE-2026-76499 covers improper neutralization (CWE-707), and CVE-2026-76500 covers improper control of a resource through its lifetime (CWE-664).
Each has a CVSS 3.1 base score of 9.8 (Critical) with the same network vector: low attack complexity, no privileges required, no user interaction, and high impact on confidentiality, integrity and availability. An unauthenticated attacker who can reach APIC over the network could therefore exploit them without credentials.
Cisco PSIRT states it is not aware of any public announcements or malicious use of these vulnerabilities.
Who is affected
The affected product is Cisco Application Policy Infrastructure Controller (APIC). Cisco lists these releases as affected: 5.2(1g), 5.2(2e), 5.2(2f), 5.2(2g), 5.2(2h), 5.2(3f), 5.2(3e), and 5.2(3g). If you run APIC, compare the installed version against this list and against the fixed release information in Cisco's advisory.
What to do now
- Apply Cisco's October 2026 security hardening release. The fixed software releases are listed in Cisco's advisory; use the release that corresponds to your version.
- Treat this as urgent. The vulnerabilities carry a CVSS 3.1 base score of 9.8 and require no credentials or user interaction.
- Until patching is complete, restrict network access to APIC to trusted management networks or jump hosts. Cisco states there are no workarounds that address these vulnerabilities, so this is containment rather than mitigation.
- After applying the update, verify the installed APIC version is no longer one of the affected releases listed above.
Beyond the patch
Beyond the patch, the score and network vector make exposure the immediate concern: an APIC reachable from the wrong network is the kind of open service that Virtual CISO Services (vCISO) helps identify and close before an advisory lands. Cisco's release also sets the patch-cycle clock for your software estate; Supply Chain Defense & Third-Party Risk tracks the software you run and how quickly vendors fix what you depend on.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| CVE-2026-76498, CVE-2026-76499, CVE-2026-76500 Cisco Application Policy Infrastructure Controller (APIC) | 5.2(1g) 5.2(2e) 5.2(2f) 5.2(2g) 5.2(2h) 5.2(3f) 5.2(3e) 5.2(3g) | No fixed version listed yet |