CVE-2026-20191General(cisco / catalyst_center)

LOWCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch cisco catalyst_center systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container.  This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to read arbitrary files from a restricted container of the affected device.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • catalyst_center
  • catalyst_center_global_manager

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 2 mentions (2026-07-09); latest day: 1
  • 7 total mentions across 6 days

Affected systems

Vendors
Products
catalyst_centercatalyst_center_global_manager

Deep dive

Activity timeline7 mentions / 6d
01122Mentions · 2026-07-01: 1Mentions · 2026-07-02: 1Mentions · 2026-07-08: 1Mentions · 2026-07-09: 2Mentions · 2026-07-10: 1Mentions · 2026-07-11: 1PoC Mentioned / Linked · 2026-07-08: 1Patch / Workaround · 2026-07-02: 1Patch / Workaround · 2026-07-08: 1Patch / Workaround · 2026-07-11: 1Technical Details · 2026-07-01: 1Technical Details · 2026-07-02: 1Technical Details · 2026-07-08: 1Technical Details · 2026-07-09: 107-0107-0207-0807-0907-1007-11
Signal classification3 categories
General
342.9%
Disclosure
228.6%
Patch
228.6%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-07-011
Disclosure1
2026-07-021
Patch1
2026-07-081
Patch1
2026-07-092
Disclosure1General1
2026-07-101
General1
2026-07-111
General1
Full discourse7 posts
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-20191 Cisco Catalyst Center Arbitrary File Read Vulnerability CVSS 7.5 Full analysis → https://sec.kaitan.id/cves/CVE-2026-20191 #Cisco #CyberSecurity #InfoSec

    Post summary

    A newly disclosed arbitrary file read vulnerability (CVE-2026-20191) in Cisco Catalyst Center has been identified with a CVSS score of 7.5; detailed analysis is available via the provided link.

    01030107
    82 followersView on X
  • Daily CyberSecurity@the_yellow_fall
    Patch

    Cisco fixes a Cisco Catalyst Center vulnerability (CVE-2026-20191, CVSS 7.5) and seven ClamAV vulnerabilities causing DoS in Secure Endpoint Connectors. #Cisco #CatalystCenter #ClamAV #CVE202620191 #CyberSecurity https://securityonline.info/cisco-catalyst-center-clamav-flaws https://t.co/OGKXv9nvSx

    Post summary

    Cisco announced a fix for CVE-2026-20191 in Catalyst Center and addressed seven ClamAV vulnerabilities that could cause denial of service in Secure Endpoint Connectors.

    02010602
    12.5K followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    CVE-2026-20191 CiscoのCatalyst Centerの脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/07/09/cve-2026-20191-catalyst-center/ #IT #Security #cybersecurity

    Post summary

    The content is a general overview of the Cisco Catalyst Center vulnerability CVE‑2026‑20191, explaining its impact and summarizing mitigation steps, without evidence of active exploitation, PoC, or detailed technical data.

    0000072
    206 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    CVE-2026-20191 CiscoのCatalyst Centerの脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/07/09/cve-2026-20191-catalyst-center/ #IT #Security #cybersecurity

    Post summary

    The text merely announces a blog post about CVE‑2026‑20191 for Cisco Catalyst Center, without detailing exploits, patches, or technical specifics.

    0000059
    206 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Cisco ❗ CVE-2026-20217 ❗ CVE-2026-20214 ❗ CVE-2026-20191 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-cisco-16/ https://t.co/AkC1AAqziU

    Post summary

    The post simply lists three Cisco CVEs and provides links for further information, without specifics on exploits, patches, or technical details.

    00000264
    6.7K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Cisco Catalyst Center の脆弱性 CVE-2026-20191 が FIX:リモートからの機密データ窃取の恐れ https://iototsecnews.jp/2026/07/02/cisco-catalyst-center-vulnerability-allows-remote-attackers-to-read-arbitrary-files/ Cisco Catalyst Center における深刻な脆弱性 CVE-2026-20191 の原因は、インターフェイスにおけるユーザー入力への不十分な検証にあります。このパス・トラバーサルと呼ばれる欠陥により、未認証の細工された HTTP リクエストを送るだけで、システム内の任意のファイルが読み取られてしまう危険性が生じています。データの改竄や停止には至りませんが、設定ファイルや認証情報といった機密性の高いデータが漏洩することで、さらなる不正アクセスにつながる恐れがあります。ご利用のチームは、ご注意ください。 #CatalystCenter #Cisco #CVE202620191 #Vulnerability

    Post summary

    The article discloses a path‑traversal flaw in Cisco Catalyst Center (CVE‑2026‑20191) that enables unauthenticated attackers to read arbitrary files, potentially exposing sensitive configuration data, but no active exploitation or remediation is reported.

    00000145
    500 followersView on X
  • MY TECH BLOG@MyTechBlogJP
    Patch

    Cisco Catalyst に未認証で悪用可能な任意ファイル読み取りの脆弱性(CVE-2026-20191)回避策なし、対策は修正版へのアップグレードのみ。 ・CVSS 7.5 だが攻撃条件はクリティカル級 ・ESXi 版は 2.3.7 系も対象、CCGM も追加 ・即時適用が難しい場合は到達性制限を https://mytech-blog.com/catalyst-center-file-read #Cisco

    Post summary

    The post announces Cisco Catalyst vulnerability CVE-2026-20191, details its severity, and advises only patching to a fixed release, with a link to further information.

    00000104
    175 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appciscocatalyst_center---
Appciscocatalyst_center_global_manager---

Explore more