Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4353 articles · 196293 vulns · 36/41 feeds (7d)
← Back to list
8.8
CVE-2026-20200
Cisco · Cisco Unified Computing System (Standalone)

Cisco Integrated Management Controller Argument Injection and Remote Code Execution Vulnerability

Description

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root.  This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user. 

Affected Products

VendorProductVersions
CiscoCisco Unified Computing System (Standalone)4.3(1.230097), 4.3(1.230124), 4.3(1.230138), 4.3(2.230207), 4.3(2.230270), 4.3(2.240002), 4.3(3.240022), 4.3(3.240043), 4.3(4.240142), 4.3(4.240152), 4.3(4.242028), 4.3(4.241063), 4.3(4.242038), 4.3(5.240021), 4.3(4.242066), 4.3(5.250001), 4.3(5.250030), 4.3(6.250040), 4.3(5.250033), 4.3(6.250044), 4.3(6.250053), 4.3(4.252001), 4.3(4.252002), 6.0(1.250127), 6.0(1.250131), 4.3(6.250101), 6.0(1.250174), 4.3(6.250117), 4.3(5.250043), 4.3(6.250039), 4.3(5.250045), 4.3(6.250060), 6.0(1.250130), 4.3(4.241014), 6.0(1.250192), 4.3(6.260003), 6.0(1.250194), 4.3(6.260017)

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
cisintegrated managementcert_advisory90%
cissecurecert_advisory90%
cissecure firewall management centercert_advisory90%
cissecure networkcert_advisory90%

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU

Related News (9 articles)

Tier B
CERT-FR13d ago
Bulletin d'actualité CERTFR-2026-ACT-034 (10 août 2026)
→ No new info (linked only)
Tier D
Help Net Security14d ago
Week in review: Cisco fixes IMC bug, Patch Tuesday forecast, Black Hat USA 2026
→ No new info (linked only)
Tier D
Heise Security16d ago
Sicherheitsupdates Cisco: Angreifer können WAN-Umgebungen stören
→ No new info (linked only)
Tier D
The Hacker News17d ago
Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs
→ No new info (linked only)
Tier B
BSI Advisories17d ago
[NEU] [hoch] Cisco Integrated Management Controller: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
Help Net Security17d ago
Critical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200)
→ No new info (linked only)
Tier B
CERT-FR17d ago
Multiples vulnérabilités dans les produits Cisco (06 août 2026)
→ No new info (linked only)
Tier C
VulDB18d ago
CVE-2026-20200 | Cisco Unified Computing System up to 6.0(1.250194) Web-based Management Interface code injection
→ No new info (linked only)
Tier A
Cisco Security18d ago
Cisco Integrated Management Controller Argument Injection Vulnerabilities
→ No new info (linked only)
CVSS 3.18.8 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
CWECWE-141
PublishedAug 5, 2026
Last enriched18d ago
Trending Score14
Source articles9
Independent7
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-20337
ClamAV ZIP File Format Processing Memory Corruption Vulnerability
Trending: 33
HIGHCVE-2026-20338
ClamAV ZIP File Format Processing Memory Corruption Vulnerability
Trending: 33
HIGHCVE-2026-20320
CVE-2026-20320: A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote
Trending: 30
MEDIUMCVE-2026-20232
Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerability
Trending: 22
MEDIUMCVE-2026-20302
Cisco RoomOS Stack Overflow Vulnerability
Trending: 16

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 5, 2026
Discovered by ZDM
Aug 5, 2026