Summary
| Parameter | Value |
|---|---|
| CVE ID | CVE-2026-20160 |
| Alert Source | GitHub Advisory - Critical Vulnerability |
| CVE Publication Year | 2026 |
| Date Published | 2026-04-01 |
| Vendor | Cisco |
| Product | Smart Software Manager On-Prem |
| CVSS Score | 9.8 (critical) |
| EPSS Score | No data |
| CISA KEV | No |
| Ransomware | Not confirmed |
Vulnerability Description
A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host.
This vulnerability is due to the unintentional exposure of an internal service. An attacker could exploit this vulnerability by sending a crafted request to the API of the exposed service. A successful exploit could allow the attacker to execute commands on the underlying opera…
Required Actions
Apply vendor patches or mitigations as soon as available.
Who Is Affected?
This vulnerability affects Smart Software Manager On-Prem by Cisco. Check if your organization uses this software and requires updates.
Sources
Need help securing your systems? nFlo team offers vulnerability management and 24/7 SOC services. Contact us.
How can nFlo help?
If your organization uses products affected by this vulnerability, contact us. We can help with:
- Verifying whether your systems are at risk
- Implementing patches and risk mitigation
- Monitoring for exploitation attempts in your environment
Useful resources:
