Exploitation observed; activity peaked at 26 mentions and remains active
Immediate actions
Patch cisco smart_software_manager_on-prem systems immediately
Assume compromise if assets are exposed
Recommended action window: Immediate (within 24h)
NVD description
A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host.
This vulnerability is due to the unintentional exposure of an internal service. An attacker could exploit this vulnerability by sending a crafted request to the API of the exposed service. A successful exploit could allow the attacker to execute commands on the underlying operating system with root-level privileges.
🚨 We reversed a critical RCE in Cisco Smart Software Manager On-Prem (CVE-2026-20160).
It exposes root access through an internal service that shouldn’t be reachable. https://t.co/rAHlQdKlxC
Post summary
Cisco Smart Software Manager On‑Prem contains a critical remote code execution vulnerability (CVE‑2026‑20160) that can grant root access through an unintended internal service.
Cisco Patches Two Critical Vulnerabilities CVE-2026-20160 and CVE-2026-20093 https://hostingtech.net/cisco-patches-two-critical-vulnerabilities-cve-2026-20160-and-cve-2026-20093/ via @HostingTech https://t.co/WwSxw7H7uh
Post summary
A Cisco patch has been released for two critical vulnerabilities, CVE-2026-20160 and CVE-2026-20093, but the tweet does not provide technical details, exploit references, or evidence of active exploitation.
Directoratul Național de Securitate Cibernetică@DNSC_RO·
Disclosure
🚨 ALERTĂ: Vulnerabilitate critică la nivelul Cisco Smart Software Manager
🔎 CVE-2026-20160 reprezintă o vulnerabilitate critică, având un scor de severitate CVSS v3.1 de 9.8, ceea ce indică un nivel de risc foarte ridicat.
👉 https://www.dnsc.ro/citeste/alerta-vulnerabilitate-critica-la-nivelul-cisco-smart-software-manager
#DNSC#Alert#CVE https://t.co/uwiTiEsL1m
Post summary
The tweet alerts readers to a critical vulnerability (CVE-2026-20160) in Cisco Smart Software Manager, citing its CVSS 9.8 score and linking to a detailed article, without providing PoC, exploit, or mitigation information.
Cisco reporta dos fallas críticas (CVE-2026-20093 y CVE-2026-20160) que permiten a atacantes no autenticados ejecutar comandos, escalar privilegios y obtener acceso administrativo
Mas información: https://www.ecucert.gob.ec/wp-content/uploads/2026/04/Al-2026-017-Fallas-criticas-en-Cisco-IMC-y-SSM-On-Prem-CVE-2026-20093-y-CVE-2026-20160.pdf
#PorUnEcuadorCiberseguro@Arcotel_ec@CsirtCEDIA@CsirtEPN https://t.co/7fmMdJ6LNK
Post summary
The tweet announces two critical Cisco vulnerabilities (CVE‑2026‑20093 and CVE‑2026‑20160) that enable unauthenticated attackers to execute arbitrary commands and elevate privileges, with no PoC, exploit tool, active exploitation, or patch information provided.
⚠️ Vulnerabilidades en productos Cisco
❗ CVE-2026-20160
❗ CVE-2026-20094
❗ CVE-2026-20093
➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-cisco-13/ https://t.co/4iMQautx5v
Post summary
The post lists three Cisco CVE identifiers and links to a CERT page for more information, but provides no further details about exploitation, patches, or vulnerability specifics.
The article announces a critical Cisco SSM On‑Prem flaw that permits unauthenticated attackers to execute commands with root privileges, underscoring the importance of addressing the missing API authentication checks.
3/5
CVE-2026-20160 — SSM On-Prem RCE
An internal API that should never be reachable... is.
One crafted request = root shell on the license server.
Found by accident during a support case.
Post summary
The post discloses CVE-2026-20160 as a Remote Code Execution flaw in an SSM On-Prem internal API that can grant a root shell on the license server via a crafted request, but provides no PoC, exploit code, active exploitation, or patch information.
Cisco has issued a critical security warning for a vulnerability in its Smart Software Manager On-Prem (SSM On-Prem), tracked as CVE-2026-20160, with a CVSS score of 9.8.
https://cybersecuritynews.com/cisco-smart-software-manager-vulnerability/
Post summary
Cisco released a critical security warning for CVE-2026-20160, highlighting its high CVSS score of 9.8, but no proof‑of‑concept, exploit code, or evidence of active exploitation is mentioned.
Warning: Critical flaws in #Cisco products. #CVE-2026-20160 CVSS: 9.8. #CVE-2026-20094 #CVE-2026-20095 #CVE-2026-20096 #CVE-2026-20097 and #CVE-2026-20155. These can lead to #RCE, root compromise, or exposure of sensitive session data! https://ccb.belgium.be/advisories/warning-remote-code-execution-vulnerabilities-multiple-cisco-products-patch-immediately #Patch#Patch#Patch
Post summary
Advisory highlights multiple high‑severity Cisco RCE vulnerabilities and urges users to apply patches immediately.
⚠️ **Vulnerability Alert:** Multiple Cisco Vulnerabilities: authentication bypass, remote code execution, privilege escalation, information disclosure
📅 **Timeline:** Disclosure: 2026-04-01, Patch: Not Available
🆔 **CVE-2026-20160** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: Not Available%
🆔 **CVE-2026-20093** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: Not Available%
🛠️ **Exploit Maturity:** Not Available
📂 **Affected Versions:** SSM On-Prem, EPNM, IMC, UCS C-series/E-series, UCS-based appliances
🫨 **Attack Vectors:**
- Network: crafted API/HTTP requests to exposed services (remote, unauthenticated)
- Web-based management interface input validation leading to command execution
- Password change functionality abuse to bypass authentication and change credentials
📝 **Summary:**
Two critical vulnerabilities (CVE-2026-20160, CVE-2026-20093) allow unauthenticated remote command execution and password-change based account takeover across multiple Cisco management and UCS platforms, enabling full system compromise. Cisco reports no known exploitation at disclosure, but successful attacks can yield root/admin access, data disclosure, credential theft, and network disruption.
📈 **Impact Scope:** Affects more than two dozen enterprise networking products (including Cisco UCS C-series/E-series and related appliances); full system compromise and network/service disruption possible.
🛡️ **Recommended Actions:**
- Apply Cisco advisories/patches immediately
- Inventory and isolate externally facing SSM, IMC, EPNM, and UCS systems; prioritize remediation
- Restrict management interface access (ACLs, VPN, segmentation) and monitor logs for suspicious API/HTTP activity
- Rotate/force-reset administrative credentials after patching; deploy IDS/IPS and EDR; forensically image suspected hosts
🪢 **Related Resources:**
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ssm-cli-execution-cHUcWuNr
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-auth-bypass-AgG2BxTn
🏷 **Tags:** #Cybersecurity#Cisco#UCS
Post summary
The bulletin announces two critical Cisco vulnerabilities (CVE‑2026‑20160 and CVE‑2026‑20093) that enable unauthenticated remote code execution and privilege escalation across multiple management platforms, outlines their attack vectors and impact, and urges immediate patching and mitigation controls.
Thanks for the heads-up, @BleepingComputer 
Cisco just dropped urgent patches — and CVE-2026-20093 is nasty.
Unauthenticated attackers can bypass IMC/CIMC auth with a single crafted HTTP request, reset any password (including Admin), and take full control.
It’s out-of-band, so it works even if the OS is crashed or the server is powered off.
No workarounds. Patch now.
Also fixed: critical root RCE in SSM On-Prem (CVE-2026-20160) and the FMC zero-day (CVE-2026-20131) already exploited in the wild by Interlock ransomware + added to CISA’s KEV list.
Cisco’s own dev environment getting hit via stolen Trivy creds shows how supply-chain risks cascade fast.
Admins running UCS C/E-Series: check your IMC versions today.
Have you patched yet?
Post summary
Cisco has released urgent patches for CVE‑2026‑20093, which allows unauthenticated attackers to reset passwords and take full control via a single HTTP request; other critical CVEs are already exploited in the wild, prompting administrators to apply the updates immediately.
Cisco Smart Software Manager On-Prem Arbitrary Command Execution Vulnerability
CVE: CVE-2026-20160
PT ID: PT-2026-29563
Vendor: Cisco
Product: Cisco Smart Software Manager On-Prem
CVSS: 9.8
Credits: n/a
Description:
A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host.
This vulnerability is due to the unintentional exposure of an internal service. An attacker could exploit this vulnerability by sending a crafted request to the API of the exposed service. A successful exploit could allow the attacker to execute commands on the underlying operating system with root-level privileges.
References:
• https://dbugs.ptsecurity.com/vulnerability/CVE-2026-20160
• https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ssm-cli-execution-cHUcWuNr
#dbugs_vuln
Post summary
The advisory announces a high‑severity (CVSS 9.8) remote command execution flaw in Cisco Smart Software Manager On‑Prem, enabling unauthenticated attackers to run arbitrary OS commands via a crafted API request.
CVE-2026-20160: Cisco SSM On-Prem Remote Command Execution Vulnerability - What It Means for Your Business and How to Respond
https://hubs.li/Q04bmSdl0
Post summary
A brief article title and link about Cisco SSM On‑Prem Remote Command Execution (CVE‑2026‑20160), with no detailed technical, exploit, or patch information provided.
Cisco just patched a 9.8 unauth root RCE in Smart Software Manager On-Prem (CVE-2026-20160). Root cause: an internal service that was unintentionally exposed to the network.
https://www.lunatech.xyz/blog/cve-2026-20160-cisco-ssm-on-prem-rce/
Post summary
Cisco issued a patch for CVE-2026-20160, an unauthenticated root Remote Code Execution flaw in Smart Software Manager On-Prem caused by an unintentionally exposed internal service.
⚠️ **Vulnerability Alert:** Cisco IMC Authentication Bypass (CVE-2026-20093) and SSM On-Prem Command Injection (CVE-2026-20160)
📅 **Timeline:** Disclosure: 2026-04-01, Patch: 2026-04-01
🆔 **CVE-2026-20093** | 📊 CVSS: 9.8 (Critical 🔴) | 📈 EPSS: 8.755%
🆔 **CVE-2026-20160** | 📊 CVSS: 9.8 (Critical 🔴) | 📈 EPSS: 38.753%
🛠️ **Exploit Maturity:** Not Available
📂 **Affected Versions:** Cisco NFVIS (5000 Series ENCS) ≤4.15, Cisco NFVIS (Catalyst 8300) ≤4.16, Cisco NFVIS 4.18, UCS C-Series IMC 4.3 and earlier, Cisco SSM On-Prem releases 9-202502–9-202510
🔧 **Fixed Versions:** Cisco NFVIS 4.15.5, Cisco NFVIS (Catalyst) 4.18.3, UCS C-Series M5 4.3(2.260007), UCS C-Series M6 4.3(6.260017)/6.0(1.250174), Cisco SSM On-Prem 9-202601
🫨 **Attack Vectors:**
- Unauthenticated remote HTTP request to IMC leading to authentication bypass
- Unauthenticated crafted API request to exposed internal SSM On-Prem service leading to root command execution
📝 **Summary:**
Unauthenticated attackers can bypass IMC authentication via crafted password-change HTTP requests (CVE-2026-20093) enabling account takeover and administrative control. Separately, crafted requests to an exposed SSM On‑Prem API (CVE-2026-20160) can achieve root command execution — both can fully compromise management infrastructure and tamper hardware configs.
📈 **Impact Scope:** Successful exploitation can yield administrative access to IMC (password changes, account takeover), root command execution on SSM On‑Prem hosts, hardware configuration tampering, persistence via altered accounts, and full system compromise of management infrastructure.
🛡️ **Recommended Actions:**
- Apply vendor patches listed in Fixed Versions immediately
- Isolate management interfaces from untrusted networks and restrict access via ACLs/VPN
- Audit IMC and SSM On‑Prem logs for suspicious password-change requests and unexpected API calls; rotate credentials and inspect local accounts
- Implement network segmentation and monitoring; backup configs and prepare incident response playbook
🪢 **Related Resources:**
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-auth-bypass-AgG2BxTn
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ssm-cli-execution-cHUcWuNr
🏷 **Tags:** #Cybersecurity#Cisco#IMC
Post summary
Cisco released critical CVEs CVE-2026-20093 and CVE-2026-20160 that allow authentication bypass and root command injection in IMC and SSM On‑Prem; they are patched in the specified firmware releases.
⚠️ **Vulnerability Alert:** Authentication Bypass and Command Injection in Cisco IMC and SSM On-Prem
📅 **Timeline:** Disclosure: 2026-04-01, Patches: Apr–Jan 2026 (see fixes)
🆔 **CVE-2026-20093** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 8.755%
🛠️ **Exploit Maturity:** Not Available
📂 **Affected Versions:** NFVIS (ENCS/Catalyst 8300) ≤4.18, UCS C-Series M5 IMC ≤4.3, UCS C-Series M6 IMC ≤6.0, UCS E-Series M3 ≤3.2, Cisco SSM On‑Prem 9-202502–9-202510
🔧 **Fixed Versions:** NFVIS 4.15.5, NFVIS 4.18.3 (Apr 2026), IMC 4.3(2.260007), IMC 6.0(1.250174), SSM On‑Prem 9-202601
🫨 **Attack Vectors:**
- Unauthenticated remote HTTP/API requests
- Exposed internal API enabling OS command injection (root)
- No user interaction; low complexity
📝 **Summary:**
CVE-2026-20093 (auth bypass) and CVE-2026-20160 (command injection) enable unauthenticated attackers to gain administrative or root control of IMC/SSM appliances, allowing password changes, hardware control, config/license tampering, and persistent compromise. Immediate patching and isolation of management interfaces are required to prevent full system takeover.
📈 **Impact Scope:** Successful exploitation grants full administrative/root control — change passwords, manage power/BIOS/hardware, modify licensing, persist, and fully compromise affected appliances.
🛡️ **Recommended Actions:**
- Patch immediately to the fixed releases listed above
- Isolate IMC/SSM from untrusted networks and restrict access via firewalls/VPNs/ACLs
- Rotate administrative credentials and keys after patching; audit logs for unauthorized changes
- Apply network segmentation, disable unused services, and enable host-based integrity monitoring
- Contact Cisco for confirmation and additional mitigations
🪢 **Related Resources:**
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-auth-bypass-AgG2BxTn
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ssm-cli-execution-cHUcWuNr
🏷 **Tags:** #Cybersecurity#CiscoIMC#SSMOnPrem (Remove commas and spaces between tags)
🆔 **CVE-2026-20160** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 38.753%
🛠️ **Exploit Maturity:** Not Available
📂 **Affected Versions:** NFVIS (ENCS/Catalyst 8300) ≤4.18, UCS C-Series M5 IMC ≤4.3, UCS C-Series M6 IMC ≤6.0, UCS E-Series M3 ≤3.2, Cisco SSM On‑Prem 9-202502–9-202510
🔧 **Fixed Versions:** NFVIS 4.15.5, NFVIS 4.18.3 (Apr 2026), IMC 4.3(2.260007), IMC 6.0(1.250174), SSM On‑Prem 9-202601
🫨 **Attack Vectors:**
- Unauthenticated remote HTTP/API requests
- Exposed internal API enabling OS command injection (root)
- No user interaction; low complexity
📝 **Summary:**
CVE-2026-20093 (auth bypass) and CVE-2026-20160 (command injection) enable unauthenticated attackers to gain administrative or root control of IMC/SSM appliances, allowing password changes, hardware control, config/license tampering, and persistent compromise. Immediate patching and isolation of management interfaces are required to prevent full system takeover.
📈 **Impact Scope:** Successful exploitation grants full administrative/root control — change passwords, manage power/BIOS/hardware, modify licensing, persist, and fully compromise affected appliances.
🛡️ **Recommended Actions:**
- Patch immediately to the fixed releases listed above
- Isolate IMC/SSM from untrusted networks and restrict access via firewalls/VPNs/ACLs
- Rotate administrative credentials and keys after patching; audit logs for unauthorized changes
- Apply network segmentation, disable unused services, and enable host-based integrity monitoring
- Contact Cisco for confirmation and additional mitigations
🪢 **Related Resources:**
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-auth-bypass-AgG2BxTn
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ssm-cli-execution-cHUcWuNr
🏷 **Tags:** #Cybersecurity#CiscoIMC#SSMOnPrem (Remove commas and spaces between tags)
Post summary
The post announces critical authentication bypass and command injection vulnerabilities in Cisco IMC/SSM appliances, providing detailed technical information, affected versions, and a clear patching roadmap for immediate remediation.
Cisco patches two critical flaws: an IMC auth bypass (CVE-2026-20093) allowing password changes, and an SSM On-Prem remote code execution (CVE-2026-20160). Both score 9.8 CVSS with no workaround. #Cisco#RemoteExploit#USA
https://ift.tt/E1AWw6H
Post summary
Cisco announced patches for two high‑severity vulnerabilities (CVE-2026-20093 and CVE-2026-20160), with no workaround available but mitigation through the released updates.
⚠️ **Vulnerability Alert:** TrueConf Client: Code-Download Without Integrity Check; Multiple Cisco Critical Vulnerabilities (IMC auth bypass, SSM On‑Prem CLI RCE, Secure Firewall FMC RCE)
📅 **Timeline:** Disclosure: 2026-03-30; Patch: see vendor advisories
🆔 **CVE-2026-3502** | 📊 CVSS: 7.8 (HIGH 🟠) | 📈 EPSS: 0.90%
🆔 **CVE-2026-20093** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 8.76%
🆔 **CVE-2026-20160** | 📊 CVSS: 9.8 (CRITICAL 🔴) | 📈 EPSS: 38.75%
🆔 **CVE-2026-20131** | 📊 CVSS: 10.0 (CRITICAL 🔴) | 📈 EPSS: 69.27%
🛠️ **Exploit Maturity:** Actively Exploited
📂 **Affected Versions:** TrueConf: versions prior to 8.5, Cisco IMC: see advisory, Cisco SSM On‑Prem: see advisory, Cisco FMC: 6.4.x–10.0.0
🔧 **Fixed Versions:** TrueConf: 8.5, Cisco IMC: see advisory, Cisco SSM On‑Prem: see advisory, Cisco FMC: see advisory
🫨 **Attack Vectors:**
- CVE-2026-3502: update delivery path (man-in-the-middle, compromised server, supply-chain) — Adjacent network; attacker must influence update payload
- CVE-2026-20093: crafted HTTP request to Cisco IMC — unauthenticated network auth bypass allowing password changes
- CVE-2026-20160: crafted API request to SSM On‑Prem — unauthenticated network RCE as root
- CVE-2026-20131: crafted serialized Java object to FMC web interface — unauthenticated insecure deserialization leading to RCE as root
📝 **Summary:**
Multiple actively exploited issues: an unverified TrueConf update path enabling code execution, plus several unauthenticated Cisco management appliance vulnerabilities (IMC auth bypass, SSM On‑Prem RCE, FMC deserialization RCE) that allow admin/root compromise. These can lead to full system takeover, lateral movement, ransomware deployment, and data exfiltration — urgent mitigation required.
📈 **Impact Scope:** Remote code execution, credential compromise, admin/root privilege escalation, full compromise of endpoints and management appliances; high operational impact for enterprises using affected Cisco products.
🛡️ **Recommended Actions:**
- Apply vendor patches immediately and follow CISA KEV guidance; if unavailable, implement vendor mitigations.
- Restrict/isolate management interfaces to trusted networks only; block public access.
- Rotate credentials and audit for unauthorized changes (prioritize IMC admin accounts).
- Monitor logs, EDR, and network telemetry for exploitation indicators and hunt for lateral movement.
🪢 **Related Resources:**
- https://www.cisa.gov/news-events/alerts/2026/04/02/cisa-adds-one-known-exploited-vulnerability-catalog
- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh
🏷 **Tags:** #Cybersecurity#Cisco#TrueConf
Post summary
The text highlights several high‑severity Cisco and TrueConf vulnerabilities that are actively exploited in the wild, provides detailed technical and mitigation information, and urges immediate patching.