# Cisco released patches for critical vulnerabilities across multiple enterprise products…

Published: 2026-04-02 · Severity: critical · Sectors: technology, infrastructure, telecommunications, financial-services, healthcare, government-national, education, manufacturing
Canonical: https://vorant.io/reports/7926dc56-66db-4281-a55e-c71f42e06bd2/cisco-released-patches-for-critical-vulnerabilities-across-multiple-enterprise

> Cisco released patches for critical vulnerabilities across multiple enterprise products enabling remote code execution on network infrastructure and management platforms.

Multiple vulnerabilities have been disclosed affecting Cisco's enterprise infrastructure management and network platforms, including Smart Software Manager On-Prem, Integrated Management Controller (IMC), Evolved Programmable Network Manager (EPNM), and Nexus Dashboard products. The most severe vulnerabilities could allow unauthenticated remote attackers to execute arbitrary code on affected devices, potentially leading to complete system compromise. The vulnerabilities primarily affect public-facing interfaces and management components across Cisco's data center, server management, and network operations product lines.

Affected products span a wide range of Cisco's enterprise portfolio, including various generations of UCS rack servers (M3, M5, M6), edge compute appliances, security analytics platforms, and centralized network management tools. Cisco has released patches for all affected versions, with updates available across multiple product lines. No active exploitation has been observed in the wild at the time of disclosure.

Organizations using affected Cisco products should prioritize patching, particularly for internet-facing management interfaces. The vulnerabilities allow exploitation through public-facing applications, representing a significant risk to enterprise network infrastructure. Affected sectors include any organization relying on Cisco enterprise infrastructure for data center operations, server management, or network provisioning.

## Mentioned in this report

- Vulnerabilities: CVE-2024-20432, CVE-2026-20041, CVE-2026-20042, CVE-2026-20085, CVE-2026-20087, CVE-2026-20093, CVE-2026-20094, CVE-2026-20095, CVE-2026-20151, CVE-2026-20155, CVE-2026-20160, CVE-2026-20174

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-cisco-products-could-allow-for-arbitrary-code-execution_2026-029

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/7926dc56-66db-4281-a55e-c71f42e06bd2/cisco-released-patches-for-critical-vulnerabilities-across-multiple-enterprise.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
