CVE-2026-20160
published 2026-04-01CVE-2026-20160: A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the…
PriorityP274critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.91%
56.1th percentile
A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host.
This vulnerability is due to the unintentional exposure of an internal service. An attacker could exploit this vulnerability by sending a crafted request to the API of the exposed service. A successful exploit could allow the attacker to execute commands on the underlying operating system with root-level privileges.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | cisco_smart_software_manager_on-prem | — | — |
| cisco | cisco_smart_software_manager_on-prem | — | — |
| cisco | cisco_smart_software_manager_on-prem | — | — |
| cisco | cisco_smart_software_manager_on-prem | — | — |
| cisco | smart | — | — |
| cisco | smart_software_manager_on-prem | >= 9-202502 < 9-202601 | 9-202601 |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit vector: crafted request sent to the API of an unintentionally exposed internal service on SSM On-Prem; detect anomalous/unexpected API calls to internal service endpoints on SSM On-Prem hosts from external/unauthenticated sources ↗
- →Successful exploitation results in OS command execution with root-level privileges; monitor SSM On-Prem hosts for unexpected root-level process spawning or OS command execution originating from the SSM On-Prem application process ↗
- →Root cause is unintentional exposure of an internal service; audit network exposure of SSM On-Prem and alert on connections to internal service ports/APIs that should not be externally reachable ↗
- →Cisco internal Bug ID CSCws84279 can be used to cross-reference vendor advisories and threat intelligence feeds for this vulnerability ↗
- ·Fixed version for Cisco SSM On-Prem is 9-202601; systems running versions prior to this are vulnerable and have no available workaround — patching is the only remediation ↗
- ·No workaround exists for this vulnerability; all unpatched SSM On-Prem deployments are exposed regardless of configuration ↗
- ·No in-the-wild exploitation or public proof-of-concept has been confirmed at time of disclosure, but related Cisco CVEs have been actively weaponized by threat actors including ransomware groups ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_cisco3.1
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Cisco Smart Software Manager On-Prem 9-202502/9-202504/9-202507/9-202510 API exposure of resource (cisco-sa-ssm-cli-execution-cHUcWuNr / Nessus ID 307357)
vuldb·2026-04-18·CVSS 9.8
CVE-2026-20160 [CRITICAL] Cisco Smart Software Manager On-Prem 9-202502/9-202504/9-202507/9-202510 API exposure of resource (cisco-sa-ssm-cli-execution-cHUcWuNr / Nessus ID 307357)
A vulnerability labeled as very critical has been found in Cisco Smart Software Manager On-Prem 9-202502/9-202504/9-202507/9-202510. This affects an unknown function of the component API. The manipulation results in exposure of resource.
This vulnerability is cataloged as CVE-2026-20160. The attack may be launched remotely. There is no exploit available.
The affected component should be upgraded.
GHSA
GHSA-wmm4-pvrx-wvv8: A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on
ghsa_unreviewed·2026-04-01
CVE-2026-20160 [CRITICAL] CWE-668 GHSA-wmm4-pvrx-wvv8: A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on
A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host.
This vulnerability is due to the unintentional exposure of an internal service. An attacker could exploit this vulnerability by sending a crafted request to the API of the exposed service. A successful exploit could allow the attacker to execute commands on the underlying operating system with root-level privileges.
Cisco
Cisco Smart Software Manager On-Prem Arbitrary Command Execution Vulnerability
vendor_cisco·CVSS 3.1
CVE-2026-20160 Cisco Smart Software Manager On-Prem Arbitrary Command Execution Vulnerability
CVE-2026-20160: Cisco Smart Software Manager On-Prem Arbitrary Command Execution Vulnerability
A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host. This vulnerability is due to the unintentional exposure of an internal service. An attacker could exploit this vulnerability by sending a crafted request to the API of the exposed service. A successful exploit could allow the attacker to execute commands on the underlying operating system with root -level privileges. Cisco has released software updates that address this vulnerability. There are no
CVSS: 3.1
CWE: CWE-668, CWE-668
Bug IDs: CSCws84279
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: Axios Hack, Chrome 0-Day, Fortinet Exploits, Paragon Spyware and More
blogs_hackernews·2026-04-06
⚡ Weekly Recap: Axios Hack, Chrome 0-Day, Fortinet Exploits, Paragon Spyware and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Axios Hack, Chrome 0-Day, Fortinet Exploits, Paragon Spyware and More
This week had real hits. The key software got tampered with. Active bugs showed up in the tools people use every day. Some attacks didn’t even need much effort because the path was already there.
One weak spot now spreads wider than before. What starts small can reach a lot of systems fast. New bugs, faster use, less time to react.
That’s this week. Read through it.
## ⚡ Threat of the Week
Axios npm Package Compromised by N. Korean Hackers —Threat actors with ties to North Korea seized control of the npm account belonging to the lead m
Hackernews
Cisco Patches 9.8 CVSS IMC and SSM Flaws Allowing Remote System Compromise
blogs_hackernews·2026-04-02·CVSS 9.8
[CRITICAL] Cisco Patches 9.8 CVSS IMC and SSM Flaws Allowing Remote System Compromise
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Cisco Patches 9.8 CVSS IMC and SSM Flaws Allowing Remote System Compromise
Cisco has released updates to address a critical security flaw in the Integrated Management Controller (IMC) that, if successfully exploited, could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system with elevated privileges.
The vulnerability, tracked as CVE-2026-20093, carries a CVSS score of 9.8 out of a maximum of 10.0.
"This vulnerability is due to incorrect handling of password change requests," Cisco said in an advisory released Wednesday. "An attacker could exploit this vulnerability by sending a c
Bleepingcomputer
Critical Cisco IMC auth bypass gives attackers Admin access
blogs_bleepingcomputer·2026-04-02·CVSS 9.8
[CRITICAL] Critical Cisco IMC auth bypass gives attackers Admin access
## Critical Cisco IMC auth bypass gives attackers Admin access
## Sergiu Gatlan
Cisco has released security updates to address several critical and high-severity vulnerabilities, including an Integrated Management Controller (IMC) authentication bypass that allows attackers to gain Admin access.
Also known as CIMC, Cisco IMC is a hardware module embedded on the motherboard of Cisco servers that provides out-of-band management (even if the operating system is powered off or crashed) for UCS C-Series and E-Series servers via multiple interfaces, including XML API, web (WebUI), and command-line (CLI).
Tracked as CVE-2026-20093 , the vulnerability was found in the Cisco IMC password change functionality and can be remotely exploited by unauthenticated attackers to bypass authentication and
2026-04-01
Published