Cisco Patches 9.8 CVSS IMC and SSM Flaws Allowing Remote System Compromise
ID: 1e3c1c34-7548-5d4d-a0fa-56ccf6bbbc37
STIX ID: report--1e3c1c34-7548-5d4d-a0fa-56ccf6bbbc37
Feed Name: The Hacker News
Cisco released patches for two critical vulnerabilities — CVE-2026-20093 (IMC password-change handling leading to authentication bypass) and CVE-2026-20160 (SSM On-Prem internal service exposure leading to unauthenticated root command execution) — both rated CVSS 9.8. The advisory lists affected products (5000 Series ENCS, Catalyst 8300, various UCS C/E-series servers, and SSM On-Prem) and fixed versions; customers are advised to apply updates immediately as no workaround is available and there is no evidence of in-the-wild exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
