Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2026-20160— Cisco Smart Software Manager On-Prem Arbitrary Command Execution Vulnerability

CVSS 9.8 · Critical EPSS 0.25% · P48
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-20160

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cisco Smart Software Manager On-Prem Arbitrary Command Execution Vulnerability
Source: NVD (National Vulnerability Database)
Vulnerability Description
A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host. This vulnerability is due to the unintentional exposure of an internal service. An attacker could exploit this vulnerability by sending a crafted request to the API of the exposed service. A successful exploit could allow the attacker to execute commands on the underlying operating system with root-level privileges.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
将资源暴露给错误范围
Source: NVD (National Vulnerability Database)
Vulnerability Title
Cisco Smart Software Manager On-Prem 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Cisco Smart Software Manager On-Prem(Cisco SSM On-Prem)是美国思科(Cisco)公司的一款用于Cisco产品许可证管理的组件。 Cisco Smart Software Manager On-Prem存在安全漏洞,该漏洞源于内部服务无意暴露,可能导致未经验证的远程攻击者在受影响主机上执行任意命令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

VendorProductAffected VersionsCPESubscribe
CiscoCisco Smart Software Manager On-Prem 9-202502 -

II. Public POCs for CVE-2026-20160

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-20160

登录查看更多情报信息。

Same Patch Batch · Cisco · 2026-04-01 · 16 CVEs total

CVE-2026-200939.8 CRITICALCisco Integrated Management Controller Authentication Bypass Vulnerability
CVE-2026-200948.8 HIGHCisco Integrated Management Controller Command Injection Vulnerability
CVE-2026-201558.0 HIGHCisco Evolved Programmable Network Manager Improper Authorization Vulnerability
CVE-2026-201517.3 HIGHCisco Smart Software Manager On-Prem Privilege Escalation Vulnerability
CVE-2026-200966.5 MEDIUMCisco Integrated Management Controller Command Injection Vulnerability
CVE-2026-200976.5 MEDIUMCisco Integrated Management Controller Remote Code Execution Vulnerability
CVE-2026-200956.5 MEDIUMCisco Integrated Management Controller Command Injection Vulnerability
CVE-2026-200426.5 MEDIUMCisco Nexus Dashboard Configuration REST API Unauthorized Access Vulnerability
CVE-2026-200856.1 MEDIUMCisco Integrated Management Controller Cross-Site Scripting Vulnerability
CVE-2026-200416.1 MEDIUMCisco Nexus Dashboard Server Side Request Forgery Vulnerability
CVE-2026-201744.9 MEDIUMCisco Nexus Dashboard Insights Arbitrary File Write Vulnerability
CVE-2026-200904.8 MEDIUMCisco Integrated Management Controller Cross-Site Scripting Vulnerability
CVE-2026-200894.8 MEDIUMCisco Integrated Management Controller Cross-Site Scripting Vulnerability
CVE-2026-200874.8 MEDIUMCisco Integrated Management Controller Cross-Site Scripting Vulnerability
CVE-2026-200884.8 MEDIUMCisco Integrated Management Controller Cross-Site Scripting Vulnerability

IV. Related Vulnerabilities

V. Comments for CVE-2026-20160

No comments yet


Leave a comment