CVE-2026-20199General(cisco / thousandeyes_virtual_appliance)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to execute commands on the underlying operating system as the root user. This vulnerability is due to insufficient validation of user-supplied input. An authenticated attacker could exploit this vulnerability by uploading a crafted certificate to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system. To exploit this vulnerability, the attacker must have valid administrative credentials.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • thousandeyes_virtual_appliance

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-20); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
thousandeyes_virtual_appliance

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-20: 1Mentions · 2026-07-23: 105-2007-23
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-201
General1
2026-07-231
Disclosure1
Full discourse2 posts
  • Israel@f1tym1
    General

    CVE-2026-20199 | Cisco ThousandEyes Enterprise Agent SSL Certificate injection (cisco-sa-tevacert-rce-RMJVEym5) https://ift.tt/D95zYov A vulnerability was found in Cisco ThousandEyes Enterprise Agent and classified as critical. This affects an unknown function of the component…

    Post summary

    A new critical vulnerability (CVE-2026-20199) affecting Cisco ThousandEyes Enterprise Agent has been disclosed, highlighting potential SSL certificate injection, but current documentation lacks detailed technical or mitigation information.

    01000105
    974 followersView on X
  • MalwareObserver@MalwareObserver
    Disclosure

    🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-20199](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/ci... https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-tevacert-rce-RMJVEym5 #Vulnerability #CVE #ZeroDay

    Post summary

    The post announces CVE-2026-20199 and links to a Cisco advisory, but provides no details on exploitation, patches, or technical characteristics.

    0000045
    13 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appciscothousandeyes_virtual_appliance---

Explore more