Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-76500: Cisco APIC may mishandle resources over its lifetime

CVE-2026-76500 · published 2 days ago
Summary

The Cisco Application Policy Infrastructure Controller contains several internal flaws that can cause it to lose proper control of system resources as it runs. This could lead to reduced stability or unintended access to data. Install the October 2026 hardening update as soon as possible to correct the problem.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
cisco cisco application policy infrastructure controller (apic) 5.2(1g)
Original advisory text
Cisco Application Policy Infrastructure Controller Hardening Release: October 2026 - Improper Control of a Resource Through its Lifetime Vulnerabilities
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.  

The vulnerabilities tracked by CVE-2026-76500 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-664Improper Control of a Resource Through its Lifetime
Timeline
Published7 Oct 2026
Updated9 Oct 2026
First seen7 Oct 2026
Sources
CVE-2026-76500 · MITRE
Track software like this
Free during beta