Cisco fixed critical and high-severity flaws
ID: a2086f69-22ac-5954-bfe1-05e04d7d1560
STIX ID: report--a2086f69-22ac-5954-bfe1-05e04d7d1560
Feed Name: Security Affairs
Cisco released patches for multiple critical and high-severity vulnerabilities — notably CVE-2026-20093 (IMC authentication bypass, CVSS 9.8) and CVE-2026-20160 (SSM On-Prem unauthenticated root command execution, CVSS 9.8) — which could allow attackers to change passwords, execute code, escalate privileges, and access sensitive data; the vendor advises immediate updates. The report also references a prior critical RCE zero-day (CVE-2026-20131, CVSS 10.0) that was exploited by Interlock ransomware and added to CISA's Known Exploited Vulnerabilities catalog.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
