Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-76499: Cisco APIC may allow unauthorized actions
CVE-2026-76499 · published 2 days ago
Summary
The Cisco Application Policy Infrastructure Controller (APIC) software contains coding errors that could let an attacker bypass normal checks and perform actions they shouldn’t be able to. This could lead to altered network policies or other unintended changes. Apply the October 2026 hardening update from Cisco as soon as possible to fix the issue.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| cisco | cisco application policy infrastructure controller (apic) | 5.2(1g) |
Original advisory text
Cisco Application Policy Infrastructure Controller Hardening Release: October 2026 - Improper Neutralization Vulnerabilities
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.
The vulnerabilities tracked by CVE-2026-76499 are related to improper neutralization issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-707.
The vulnerabilities tracked by CVE-2026-76499 are related to improper neutralization issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-707.
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-707Improper Neutralization
Timeline
Published7 Oct 2026
Updated8 Oct 2026
First seen7 Oct 2026
Track software like this
Free during beta