logo

Technical Details Released for Critical Cisco SSM Command Execution Vulnerability

ID: 9ec02dbe-ce7d-5377-8fd3-1545c8e6307f

STIX ID: report--9ec02dbe-ce7d-5377-8fd3-1545c8e6307f

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-04-09

Date Updated: 2026-04-22

Author: Divya

...
...

**Critical unauthenticated RCE in Cisco Smart Software Manager On-Prem (CVE-2026-20160)** — A near-maximum severity (CVSS 9.8) vulnerability allows remote, unauthenticated attackers to execute commands as root on SSM On-Prem appliances; no workarounds exist and Cisco has issued a fixed release (9-202601 and later) for affected versions 9-202502 through 9-202510. The appliance typically resides in trusted internal networks and contains deployment data, so successful exploitation can provide a high-privilege foothold for lateral movement, persistence, and data theft; researchers have reverse-engineered the flaw and published a detection test to verify exposure and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.