cbcvebase.
CVE-2026-20160
published 2026-04-01

CVE-2026-20160: A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the…

PriorityP274critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.91%
56.1th percentile
A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host. This vulnerability is due to the unintentional exposure of an internal service. An attacker could exploit this vulnerability by sending a crafted request to the API of the exposed service. A successful exploit could allow the attacker to execute commands on the underlying operating system with root-level privileges.

Affected

6 ranges
VendorProductVersion rangeFixed in
ciscocisco_smart_software_manager_on-prem
ciscocisco_smart_software_manager_on-prem
ciscocisco_smart_software_manager_on-prem
ciscocisco_smart_software_manager_on-prem
ciscosmart
ciscosmart_software_manager_on-prem>= 9-202502 < 9-2026019-202601

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit vector: crafted request sent to the API of an unintentionally exposed internal service on SSM On-Prem; detect anomalous/unexpected API calls to internal service endpoints on SSM On-Prem hosts from external/unauthenticated sources
  • Successful exploitation results in OS command execution with root-level privileges; monitor SSM On-Prem hosts for unexpected root-level process spawning or OS command execution originating from the SSM On-Prem application process
  • Root cause is unintentional exposure of an internal service; audit network exposure of SSM On-Prem and alert on connections to internal service ports/APIs that should not be externally reachable
  • Cisco internal Bug ID CSCws84279 can be used to cross-reference vendor advisories and threat intelligence feeds for this vulnerability
  • ·Fixed version for Cisco SSM On-Prem is 9-202601; systems running versions prior to this are vulnerable and have no available workaround — patching is the only remediation
  • ·No workaround exists for this vulnerability; all unpatched SSM On-Prem deployments are exposed regardless of configuration
  • ·No in-the-wild exploitation or public proof-of-concept has been confirmed at time of disclosure, but related Cisco CVEs have been actively weaponized by threat actors including ransomware groups

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_cisco3.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.