CVE-2026-20160 is a critical vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) that allows an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system. Rated 9.8 Critical on the CVSS scale, this flaw stems from an unintentionally exposed internal service, enabling attackers to achieve root-level privileges with low attack complexity. While no public exploit code is currently available, the vulnerability is on the "Hot List: Active" and has garnered significant community attention, with alerts urging immediate patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9-202502, < 9-202601CPE matchmatch criteria | cpe:2.3:a:cisco:smart_software_manager_on-prem:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.