CVE-2026-20085Medium· 6.1▾ SunlitA vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. This vulnerability is due to insufficient validation…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 33.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 29.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface.
This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the browser of the targeted user or access sensitive, browser-based information.
enterprise_nfv_infrastructure_software = 3.3.1enterprise_nfv_infrastructure_software = 3.4.1enterprise_nfv_infrastructure_software = 3.5.1enterprise_nfv_infrastructure_software = 3.5.2enterprise_nfv_infrastructure_software = 3.6.1enterprise_nfv_infrastructure_software = 3.6.2enterprise_nfv_infrastructure_software = 3.6.3enterprise_nfv_infrastructure_software = 3.7.1enterprise_nfv_infrastructure_software = 3.8.1enterprise_nfv_infrastructure_software = 3.9.1enterprise_nfv_infrastructure_software = 3.9.2enterprise_nfv_infrastructure_software = 3.10.1enterprise_nfv_infrastructure_software = 3.10.2enterprise_nfv_infrastructure_software = 3.10.3enterprise_nfv_infrastructure_software = 3.11.1enterprise_nfv_infrastructure_software = 3.11.2enterprise_nfv_infrastructure_software = 3.11.3enterprise_nfv_infrastructure_software = 3.12.1enterprise_nfv_infrastructure_software = 3.12.1aenterprise_nfv_infrastructure_software = 3.12.1benterprise_nfv_infrastructure_software = 3.12.2enterprise_nfv_infrastructure_software = 3.12.3enterprise_nfv_infrastructure_software = 4.1.1enterprise_nfv_infrastructure_software = 4.1.2enterprise_nfv_infrastructure_software = 4.2.1enterprise_nfv_infrastructure_software = 4.2.2enterprise_nfv_infrastructure_software = 4.4.1enterprise_nfv_infrastructure_software = 4.4.2enterprise_nfv_infrastructure_software = 4.4.3enterprise_nfv_infrastructure_software = 4.5.1enterprise_nfv_infrastructure_software = 4.6.1enterprise_nfv_infrastructure_software = 4.6.2enterprise_nfv_infrastructure_software = 4.6.2-fc2enterprise_nfv_infrastructure_software = 4.6.2-fc3enterprise_nfv_infrastructure_software = 4.6.3enterprise_nfv_infrastructure_software = 4.6.3-fc4enterprise_nfv_infrastructure_software = 4.6.4enterprise_nfv_infrastructure_software = 4.6.5-es1enterprise_nfv_infrastructure_software = 4.7.1enterprise_nfv_infrastructure_software = 4.8.1enterprise_nfv_infrastructure_software = 4.8.2enterprise_nfv_infrastructure_software = 4.9.1enterprise_nfv_infrastructure_software = 4.9.2enterprise_nfv_infrastructure_software = 4.9.2-fc5enterprise_nfv_infrastructure_software = 4.9.3enterprise_nfv_infrastructure_software = 4.9.4enterprise_nfv_infrastructure_software = 4.9.4-es8enterprise_nfv_infrastructure_software = 4.9.4-es9enterprise_nfv_infrastructure_software = 4.9.5enterprise_nfv_infrastructure_software = 4.9.6enterprise_nfv_infrastructure_software = 4.10.1enterprise_nfv_infrastructure_software = 4.11.1enterprise_nfv_infrastructure_software = 4.12.1enterprise_nfv_infrastructure_software = 4.12.2enterprise_nfv_infrastructure_software = 4.12.3enterprise_nfv_infrastructure_software = 4.12.4enterprise_nfv_infrastructure_software = 4.12.5enterprise_nfv_infrastructure_software = 4.12.6enterprise_nfv_infrastructure_software = 4.13.1enterprise_nfv_infrastructure_software = 4.14.1enterprise_nfv_infrastructure_software = 4.15.1enterprise_nfv_infrastructure_software = 4.15.2enterprise_nfv_infrastructure_software = 4.15.3enterprise_nfv_infrastructure_software = 4.15.4enterprise_nfv_infrastructure_software = 4.16.1enterprise_nfv_infrastructure_software = 4.18.1enterprise_nfv_infrastructure_software = 4.18.2enterprise_nfv_infrastructure_software = 4.18.2aunified_computing_system = 3.1(1d)unified_computing_system = 3.1(2b)unified_computing_system = 3.1(2c)unified_computing_system = 3.1(2d)unified_computing_system = 3.1(2e)unified_computing_system = 3.1(2g)unified_computing_system = 3.1(2i)unified_computing_system = 3.1(3a)unified_computing_system = 3.1(3b)unified_computing_system = 3.1(3c)unified_computing_system = 3.1(3d)unified_computing_system = 3.1(3g)unified_computing_system = 3.1(3h)unified_computing_system = 3.1(3i)unified_computing_system = 3.1(3j)unified_computing_system = 3.1(3k)unified_computing_system = 4.0(1.240)unified_computing_system = 4.0(1a)unified_computing_system = 4.0(1b)unified_computing_system = 4.0(1c)unified_computing_system = 4.0(1d)unified_computing_system = 4.0(1e)unified_computing_system = 4.0(1g)unified_computing_system = 4.0(1h)unified_computing_system = 4.0(2c)unified_computing_system = 4.0(2d)unified_computing_system = 4.0(2f)unified_computing_system = 4.0(2g)unified_computing_system = 4.0(2h)unified_computing_system = 4.0(2i)unified_computing_system = 4.0(2l)unified_computing_system = 4.0(2n)Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-20090Medium· 4.8A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due …
CVE-2026-20089Medium· 4.8A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due …
CVE-2026-20088Medium· 4.8A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due …
CVE-2026-20087Medium· 4.8A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due …
CVE-2026-20309Medium· 6.1A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. Th…
CVE-2019-1973Medium· 4.8A vulnerability in the web portal framework of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based interface