CVE-2026-20185Disclosure

LOWCVSS 7.7 · HIGH

Exploit discussion active in current signal (8 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco 350 Series Managed Switches (SG350) and Cisco 350X Series Stackable Managed Switches (SG350X) firmware could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.  This vulnerability is due to improper error handling when parsing response data for a specific SNMP request. An attacker could exploit this vulnerability by sending a specific SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition. This vulnerability affects SNMP versions 1, 2c, and 3. To exploit this vulnerability through SNMPv2c or earlier, the attacker must know a valid read-write or read-only SNMP community string for the affected system. To exploit this vulnerability through SNMPv3, the attacker must have valid SNMP user credentials for the affected system.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

RISING

Threat summary

  • Public PoC is present in monitored signal
  • 13 mentions across 5 observed days
  • Momentum state: rising

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 9 signals
  • Disclosure: 9 classified signals
  • General: 4 classified signals
  • Peaked at 8 mentions on most recent observed day (2026-06-06)
  • 13 total mentions across 5 days

Deep dive

Activity timeline13 mentions / 5d
02468Mentions · 2026-05-06: 2Mentions · 2026-05-07: 1Mentions · 2026-05-18: 1Mentions · 2026-05-29: 1Mentions · 2026-06-06: 8PoC Mentioned / Linked · 2026-06-06: 1Technical Details · 2026-05-06: 2Technical Details · 2026-05-07: 1Technical Details · 2026-06-06: 605-0605-0705-1805-2906-06
Signal classification2 categories
Disclosure
969.2%
General
430.8%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-05-062
Disclosure2
2026-05-071
Disclosure1
2026-05-181
General1
2026-05-291
General1
2026-06-068
Disclosure6General2
Full discourse13 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    The Silent Network Edge: Cisco 350 Series SNMP Vulnerability (CVE-2026-20185) Allows Authenticated DoS. Cisco disclosed a high-severity vulnerability CVE-2026-20185, CVSS 7.7 in the SNMP subsystem of its 350 Series managed switches.

    Post summary

    The post announces the disclosure of CVE-2026-20185, a high‑severity DoS vulnerability in the SNMP subsystem of Cisco 350 Series switches, with a CVSS score of 7.7.

    1000036
    247 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    On May 6, 2026, Cisco released security advisories addressing multiple vulnerabilities across its enterprise portfolio. Among them: CVE-2026-20185, a denial-of-service (DoS) flaw in the Simple Network Management Protocol (SNMP) subsystem of Cisco Small Business 350 Series…

    Post summary

    Cisco has announced a DoS vulnerability (CVE-2026-20185) affecting the SNMP subsystem on its Small Business 350 Series, with no PoC, exploit, or patch details provided in the excerpt.

    1000043
    247 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Cisco disclosed a high-severity vulnerability (CVE-2026-20185, CVSS 7.7) in the SNMP subsystem of its 350 Series managed switches. The flaw allows authenticated remote attackers to crash affected devices via improper error handling in SNMP response parsing. While…

    Post summary

    Cisco disclosed CVE‑2026‑20185, a high‑severity flaw in the SNMP subsystem of its 350 Series switches that can crash devices via improper SNMP response parsing, but no PoC, exploit, active exploitation, remediation, or debunking is reported.

    1000034
    247 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Cisco disclosed a high-severity vulnerability (CVE-2026-20185, CVSS 7.7) in the SNMP subsystem of its 350 Series managed switches. The flaw allows authenticated remote attackers to crash affected devices via improper error handling in SNMP response parsing. While…

    Post summary

    Cisco has disclosed a high‑severity authenticated remote denial‑of‑service vulnerability (CVE‑2026‑20185) affecting the SNMP subsystem of its 350 Series managed switches, but no exploit or patch details are included.

    1000037
    247 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    The Silent Network Edge: Cisco 350 Series SNMP Vulnerability Enables Authenticated DoS Cisco disclosed a high-severity vulnerability CVE-2026-20185, CVSS 7.7 in the SNMP subsystem of its 350 Series managed switches.

    Post summary

    Cisco has announced CVE-2026-20185, a high‑severity authenticated DoS vulnerability in the SNMP subsystem of its 350 Series managed switches, with a CVSS score of 7.7.

    1000034
    247 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2026-20185 · 7.7 The Silent Network Edge: Cisco 350 Series SNMP Vulnerability Enables Authenticated DoS

    Post summary

    A new Cisco 350 series SNMP vulnerability (CVE-2026-20185) that allows authenticated DoS is disclosed, with technical details but no PoC, patch, or indication of active exploitation.

    1000034
    247 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    【脆弱性情報】 CVE-2026-20185 CiscoのCisco 350 Series Managed Switches, Cisco 350X Series Stackable Managed Switchesの脆弱性について https://www.cybernote.click/2026/05/21/%e3%80%90%e8%84%86%e5%bc%b1%e6%80%a7%e6%83%85%e5%a0%b1%e3%80%91-cve-2026-20185-cisco%e3%81%aecisco-350-series-managed-switches-cisco-350x-series-stackable-managed-switches%e3%81%ae%e8%84%86%e5%bc%b1/ #IT #Security #cybersecurity

    Post summary

    A concise announcement referencing the CVE-2026-20185 vulnerability on Cisco 350 Series switches, linking to an external article but lacking detailed technical or actionable information.

    00010195
    208 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-20185 A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco 350 Series Managed Switches (SG350) and Cisco 350X Series Stackable Managed S… https://www.cve.org/CVERecord?id=CVE-2026-20185

    Post summary

    A brief mention of CVE-2026-20185 indicating a vulnerability in the SNMP subsystem of Cisco 350 Series switches, with a link to the CVE record but no further technical or exploit details.

    00010126
    57.4K followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/2026-05-07-cisco-snmp-sg350-cve-2026-20185 #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The tweet shares a link to a research article on CVE-2026-20185 with no further details.

    0000022
    247 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/2026-05-07-cisco-snmp-sg350-cve-2026-20185 #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The post merely references a research link for CVE-2026-20185 without providing any substantive details on the vulnerability or its exploitation status.

    0000023
    247 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Cisco ❗ CVE-2026-20185 ❗ CVE-2026-20167 ❗ CVE-2026-20034 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-cisco-15/ https://t.co/713Xur4qkJ

    Post summary

    The post lists several Cisco CVEs and provides links for further information, but does not give detailed technical data, patches, or exploitation evidence.

    00000145
    6.7K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    CVE-2026-20185 Cisco SG350 and SG350X Series Managed Switches SNMP Denial of Service Vulnerability https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sg350-snmp-dos-GEFZr2Tj

    Post summary

    The provided text shares a Cisco security advisory for CVE‑2026‑20185, highlighting a SNMP‑based denial‑of‑service flaw in SG350/SG350X switches; no proof‑of‑concept, exploit code, or active exploitation is noted.

    00000354
    6.8K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-20185 A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco 350 Series Managed Switches (SG350) and Cisco 350X Series Stackable Managed S… https://www.cve.org/CVERecord?id=CVE-2026-20185 ----- Traducción: CVE-2026-20185 Una vuln… http://infoflow.cloud`

    Post summary

    The post discloses CVE‑2026‑20185 as affecting the SNMP subsystem on Cisco 350 series switches, but offers no PoC, exploit code, or patch information.

    0000038
    75 followersView on X

Explore more