CVE-2026-20096Medium· 6.5▾ SunlitA vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands a…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 29.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.7%
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands as the root user.
This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending crafted commands to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user. Cisco has assigned this vulnerability a Security Impact Rating (SIR) of High, rather than Medium as the score indicates, because additional security implications could occur once the attacker has become root.
enterprise_nfv_infrastructure_software = 3.3.1enterprise_nfv_infrastructure_software = 3.4.1enterprise_nfv_infrastructure_software = 3.5.1enterprise_nfv_infrastructure_software = 3.5.2enterprise_nfv_infrastructure_software = 3.6.1enterprise_nfv_infrastructure_software = 3.6.2enterprise_nfv_infrastructure_software = 3.6.3enterprise_nfv_infrastructure_software = 3.7.1enterprise_nfv_infrastructure_software = 3.8.1enterprise_nfv_infrastructure_software = 3.9.1enterprise_nfv_infrastructure_software = 3.9.2enterprise_nfv_infrastructure_software = 3.10.1enterprise_nfv_infrastructure_software = 3.10.2enterprise_nfv_infrastructure_software = 3.10.3enterprise_nfv_infrastructure_software = 3.11.1enterprise_nfv_infrastructure_software = 3.11.2enterprise_nfv_infrastructure_software = 3.11.3enterprise_nfv_infrastructure_software = 3.12.1enterprise_nfv_infrastructure_software = 3.12.1aenterprise_nfv_infrastructure_software = 3.12.1benterprise_nfv_infrastructure_software = 3.12.2enterprise_nfv_infrastructure_software = 3.12.3enterprise_nfv_infrastructure_software = 4.1.1enterprise_nfv_infrastructure_software = 4.1.2enterprise_nfv_infrastructure_software = 4.2.1enterprise_nfv_infrastructure_software = 4.2.2enterprise_nfv_infrastructure_software = 4.4.1enterprise_nfv_infrastructure_software = 4.4.2enterprise_nfv_infrastructure_software = 4.4.3enterprise_nfv_infrastructure_software = 4.5.1enterprise_nfv_infrastructure_software = 4.6.1enterprise_nfv_infrastructure_software = 4.6.2enterprise_nfv_infrastructure_software = 4.6.2-fc2enterprise_nfv_infrastructure_software = 4.6.2-fc3enterprise_nfv_infrastructure_software = 4.6.3enterprise_nfv_infrastructure_software = 4.6.3-fc4enterprise_nfv_infrastructure_software = 4.6.4enterprise_nfv_infrastructure_software = 4.6.5-es1enterprise_nfv_infrastructure_software = 4.7.1enterprise_nfv_infrastructure_software = 4.8.1enterprise_nfv_infrastructure_software = 4.8.2enterprise_nfv_infrastructure_software = 4.9.1enterprise_nfv_infrastructure_software = 4.9.2enterprise_nfv_infrastructure_software = 4.9.2-fc5enterprise_nfv_infrastructure_software = 4.9.3enterprise_nfv_infrastructure_software = 4.9.4enterprise_nfv_infrastructure_software = 4.9.4-es8enterprise_nfv_infrastructure_software = 4.9.4-es9enterprise_nfv_infrastructure_software = 4.9.4-fc3enterprise_nfv_infrastructure_software = 4.9.5enterprise_nfv_infrastructure_software = 4.9.6enterprise_nfv_infrastructure_software = 4.10.1enterprise_nfv_infrastructure_software = 4.11.1enterprise_nfv_infrastructure_software = 4.12.1enterprise_nfv_infrastructure_software = 4.12.2enterprise_nfv_infrastructure_software = 4.12.3enterprise_nfv_infrastructure_software = 4.12.4enterprise_nfv_infrastructure_software = 4.12.5enterprise_nfv_infrastructure_software = 4.12.6enterprise_nfv_infrastructure_software = 4.13.1enterprise_nfv_infrastructure_software = 4.14.1enterprise_nfv_infrastructure_software = 4.15.1enterprise_nfv_infrastructure_software = 4.15.2enterprise_nfv_infrastructure_software = 4.15.3enterprise_nfv_infrastructure_software = 4.15.4enterprise_nfv_infrastructure_software = 4.16.1enterprise_nfv_infrastructure_software = 4.18.1enterprise_nfv_infrastructure_software = 4.18.2enterprise_nfv_infrastructure_software = 4.18.2aunified_computing_system = 3.1(1d)unified_computing_system = 3.1(2b)unified_computing_system = 3.1(2c)unified_computing_system = 3.1(2d)unified_computing_system = 3.1(2e)unified_computing_system = 3.1(2g)unified_computing_system = 3.1(2i)unified_computing_system = 3.1(3a)unified_computing_system = 3.1(3b)unified_computing_system = 3.1(3c)unified_computing_system = 3.1(3d)unified_computing_system = 3.1(3g)unified_computing_system = 3.1(3h)unified_computing_system = 3.1(3i)unified_computing_system = 3.1(3j)unified_computing_system = 3.1(3k)unified_computing_system = 4.0(1.240)unified_computing_system = 4.0(1a)unified_computing_system = 4.0(1b)unified_computing_system = 4.0(1c)unified_computing_system = 4.0(1d)unified_computing_system = 4.0(1e)unified_computing_system = 4.0(1g)unified_computing_system = 4.0(1h)unified_computing_system = 4.0(2c)unified_computing_system = 4.0(2d)unified_computing_system = 4.0(2f)unified_computing_system = 4.0(2g)unified_computing_system = 4.0(2h)unified_computing_system = 4.0(2i)unified_computing_system = 4.0(2k)Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-20095Medium· 6.5A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands a…
CVE-2026-20094High· 8.8A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command injection attacks on an affected system and execute arbitrary commands as the r…
CVE-2026-20176Critical· 9.1A vulnerability in Cisco ISE could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device
CVE-2026-20325Critical· 9.9As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review
CVE-2026-20090Medium· 4.8A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due …
CVE-2026-20089Medium· 4.8A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due …