Critical 9.8 CVSS Flaw in Cisco SSM On-Prem Grants Unauthenticated Root Access
ID: 84fd705a-bacb-5562-a9bf-9a907e97a5e2
STIX ID: report--84fd705a-bacb-5562-a9bf-9a907e97a5e2
Feed Name: securityonline.info
Threat Score
Cisco released an advisory for CVE-2026-20160 affecting Smart Software Manager On-Prem: an unauthenticated, network-reachable API exposes an internal service that can be sent crafted requests to achieve remote code execution with root privileges (CVSS 9.8). Cisco provides fixed releases and states upgrade is the only mitigation; no public exploitation has been observed to date.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
