CVE-2026-20328

LOWCVSS 9.1 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability in the web-based management interface of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an unauthenticated, remote attacker to gain unauthorized access to an affected application. This vulnerability is due to improper checks during the password reset process. An attacker could exploit this vulnerability by sending a malicious request to the web-based management interface. A successful exploit could allow the attacker to reset the password of an arbitrary account, including high-privileged administrative user accounts, possibly allowing the attacker to gain unauthorized access to the application as any user.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-10-07: 310-07
Referenced assets3 URLs
Full discourse3 posts
  • Daily CyberSecurity@Daily_CyberSec

    Cisco License On-Prem vulnerabilities include CVSS 10 flaw CVE-2026-76482 and password reset bug CVE-2026-20328. APIC and Meraki also patched. #Cisco #SmartLicensing #APIC #Meraki #CVE202676482 #CVE202620328 #PatchNow #Vulnerability https://securityonline.info/cisco-license-on-prem-vulnerabilities/

    00000382
    13.0K followersView on X
  • Kaitan ID Security@KaitanSecurity

    🚨 CRITICAL — CVE-2026-20328 Cisco License (Smart Software Manager) On-Prem Vulnerabilities CVSS 9.1 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-20328 #Cisco #CyberSecurity #InfoSec

    0000029
    89 followersView on X
  • VulniPulse@vulnipulse

    CVE advisory (CRITICAL): CVE-2026-20328 - cisco: Cisco License (Smart Software Manager) On-Prem Vulnerabilities. https://vulnipulse.com/advisories/cisco-cisco-sa-ssm-access-nttb2dhe #CVE #CyberSecurity #Cisco #CiscoSSM

    0000026
    7 followersView on X

Explore more