Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2982 articles · 185103 vulns · 37/41 feeds (7d)
← Back to list
8.8
CVE-2026-20200
Cisco · Cisco Unified Computing System (Standalone)

Cisco Integrated Management Controller Argument Injection and Remote Code Execution Vulnerability

Description

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root.  This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user. 

Affected Products

VendorProductVersions
CiscoCisco Unified Computing System (Standalone)4.3(1.230097), 4.3(1.230124), 4.3(1.230138), 4.3(2.230207), 4.3(2.230270), 4.3(2.240002), 4.3(3.240022), 4.3(3.240043), 4.3(4.240142), 4.3(4.240152), 4.3(4.242028), 4.3(4.241063), 4.3(4.242038), 4.3(5.240021), 4.3(4.242066), 4.3(5.250001), 4.3(5.250030), 4.3(6.250040), 4.3(5.250033), 4.3(6.250044), 4.3(6.250053), 4.3(4.252001), 4.3(4.252002), 6.0(1.250127), 6.0(1.250131), 4.3(6.250101), 6.0(1.250174), 4.3(6.250117), 4.3(5.250043), 4.3(6.250039), 4.3(5.250045), 4.3(6.250060), 6.0(1.250130), 4.3(4.241014), 6.0(1.250192), 4.3(6.260003), 6.0(1.250194), 4.3(6.260017)

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
cisintegrated managementcert_advisory90%
cissecurecert_advisory90%
cissecure firewall management centercert_advisory90%
cissecure networkcert_advisory90%

References

  • https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU

Related News (7 articles)

Tier D
Heise Security1d ago
Sicherheitsupdates Cisco: Angreifer können WAN-Umgebungen stören
→ No new info (linked only)
Tier D
The Hacker News2d ago
Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs
→ No new info (linked only)
Tier B
BSI Advisories2d ago
[NEU] [hoch] Cisco Integrated Management Controller: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
Help Net Security2d ago
Critical Cisco IMC bug gives attackers root, PoC is out (CVE-2026-20200)
→ No new info (linked only)
Tier B
CERT-FR3d ago
Multiples vulnérabilités dans les produits Cisco (06 août 2026)
→ No new info (linked only)
Tier C
VulDB3d ago
CVE-2026-20200 | Cisco Unified Computing System up to 6.0(1.250194) Web-based Management Interface code injection
→ No new info (linked only)
Tier A
Cisco Security3d ago
Cisco Integrated Management Controller Argument Injection Vulnerabilities
→ No new info (linked only)
CVSS 3.18.8 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
CWECWE-141
PublishedAug 5, 2026
Last enriched3d ago
Trending Score52
Source articles7
Independent7
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-20303
Cisco Catalyst SD-WAN Security Hardening Release - Input Validation Vulnerabilities
Trending: 51
CRITICALCVE-2026-20304
Cisco Catalyst SD-WAN Security Hardening Release - Access Control Vulnerabilities
Trending: 48
CRITICALCVE-2026-20310
Cisco SD-WAN Software Security Hardening Release - Improper Link Resolution Before File Access
Trending: 48
HIGHCVE-2026-20338
ClamAV ZIP File Format Processing Memory Corruption Vulnerability
Trending: 42
HIGHCVE-2026-20337
ClamAV ZIP File Format Processing Memory Corruption Vulnerability
Trending: 42

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 5, 2026
Discovered by ZDM
Aug 5, 2026