VORANT. Threat Intelligence Sign in Get the full feed

Cisco patches RCE flaws across management platforms

high vulnerability

Cisco released patches for multiple critical vulnerabilities across Smart Software Manager On-Prem, IMC, EPNM, and Nexus Dashboard products that could allow arbitrary code execution.

Cisco has disclosed multiple vulnerabilities affecting its enterprise management and network infrastructure products, including Smart Software Manager On-Prem, Integrated Management Controller (IMC), Evolved Programmable Network Manager (EPNM), and Nexus Dashboard platforms. The most severe vulnerabilities could allow unauthenticated attackers to achieve arbitrary code execution on affected devices, potentially leading to complete system compromise.

The vulnerabilities span multiple product lines used for license management, server administration, network provisioning, and data center operations. Affected products include various versions of Cisco UCS C-Series and E-Series servers, edge compute appliances, telemetry brokers, and security analytics platforms. All identified flaws involve exploitation of public-facing applications, categorized under MITRE ATT&CK technique T1190.

At the time of disclosure, there are no reports of active exploitation in the wild. Cisco has released patches for all affected products, with version-specific fixes ranging from IMC 4.3(2.260007) for M5 servers to Nexus Dashboard Fabric Controller 12.2.2. Organizations are advised to apply updates immediately after testing, implement vulnerability scanning, and enforce least-privilege access controls.

Mentioned in this report

Vulnerabilities CVE-2024-20432CVE-2026-20041CVE-2026-20042CVE-2026-20085CVE-2026-20087CVE-2026-20093CVE-2026-20094CVE-2026-20095CVE-2026-20151CVE-2026-20155CVE-2026-20160CVE-2026-20174

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-cisco-products-could-allow-for-arbitrary-code-execution_2026-029

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free