logo

Cisco SSM On-Prem vulnerabilities: Find impacted assets

ID: a74f3223-c19a-5d34-b7ef-41dd157213f7

STIX ID: report--a74f3223-c19a-5d34-b7ef-41dd157213f7

Feed Name: runZero Blog

Threat Score
75/100

Date Published: 2026-04-03

Date Updated: 2026-04-29

Author: Matthew Kienow

...
...

## Executive Summary Cisco disclosed two vulnerabilities in Smart Software Manager On-Prem: CVE-2026-20160, a critical (CVSS 9.8) remote unauthenticated command execution stemming from an exposed internal service that can yield root access, and CVE-2026-20151, a high (CVSS 7.3) web-interface privilege escalation allowing a System User to obtain administrative session credentials. Affected versions include 9-202502 through 9-202510 (for CVE-20160) and 9-202510 and earlier (for CVE-20151); Cisco advises upgrading to 9-202601 or later and provides a runZero query to find potentially impacted hosts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.