Cisco License On-Prem flaws enable root takeover
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
Cisco patched eight vulnerabilities in License On-Prem, including a CVSS 10.0 flaw letting unauthenticated attackers reset passwords or execute root commands.
NCSC-NL published an advisory describing eight vulnerabilities fixed by Cisco in its License On-Prem product, affecting the web-based management interface and API endpoints. The flaws span multiple weakness classes: relative path traversal, OS command injection, SQL injection, missing authorization, code injection, missing authentication for a critical function, improper verification of cryptographic signatures, and insufficiently protected credentials.
Unauthenticated attackers can exploit several of these issues to reset passwords, write arbitrary files, or cause denial-of-service conditions. Authenticated attackers with administrator privileges can escalate further, executing arbitrary commands with root privileges and leveraging SQL injection to access internal database contents. Collectively the flaws threaten confidentiality, integrity and availability of affected deployments. CVSS scores range up to 10.0, with several in the critical (9.1-10.0) and high (8.8) range.
Cisco has released updates addressing all eight CVEs. NCSC-NL advises against exposing the License On-Prem management interface or API publicly, and recommends isolating such interfaces in separate management networks with additional access controls even on internal networks. No evidence of active in-the-wild exploitation is mentioned in the advisory; defenders should prioritize patching given the severity and remote unauthenticated attack vectors.
Mentioned in this report
Detection guidance
Web Server or App Runtime Spawning Shell with Download or Reverse-Shell Commands
Detects a web server or application runtime process on Linux spawning a shell that runs download, staging or reverse-shell commands, as seen after OS command injection in a web management interface. Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.
title: Web Server or App Runtime Spawning Shell with Download or Reverse-Shell Commands
description: Detects web server or application runtime processes (nginx, httpd, apache2,
gunicorn, uwsgi, java, python, php-fpm, node) spawning a shell with -c and download,
staging or reverse-shell content. Typical post-exploitation of OS command injection
in appliance web UIs and APIs, including those running with root privileges.
tags:
- attack.execution
- attack.t1059
- attack.initial-access
- attack.t1190
logsource:
category: process_creation
product: linux
detection:
selection_parent:
ParentImage|endswith:
- /nginx
- /httpd
- /apache2
- /gunicorn
- /uwsgi
- /java
- /php-fpm
- /node
- /python
- /python3
selection_shell:
Image|endswith:
- /sh
- /bash
- /dash
CommandLine|contains: ' -c'
selection_payload:
CommandLine|contains:
- curl
- wget
- /dev/tcp/
- mkfifo
- 'nc '
- ncat
- base64 -d
- chmod +x
- chmod 777
condition: selection_parent and selection_shell and selection_payload
falsepositives:
- Appliance health-check or update scripts that call curl from a Python or Java service
wrapper
- Application deployment hooks that download artifacts via a shell from the app runtime
level: medium
id: ac0bf0c8-9270-53ec-aa9d-6ea6e2f67fb6
status: experimental
author: Vorant
references:
- https://advisories.ncsc.nl/2026/ncsc-2026-0407.html
Behavioural rules are generated from public reporting — validate in your environment before deploying.
Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0407.html
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 11,021 reports from 148 sources, 479 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs