VORANT. Threat Intelligence Sign in Get the full feed

Cisco patches RCE flaws across multiple platforms

medium vulnerability

Cisco disclosed a dozen vulnerabilities across Smart Software Manager, IMC, EPNM, NFVIS, and Nexus Dashboard products that could allow arbitrary code execution; no exploitation observed yet.

Cisco has released patches for multiple vulnerabilities spanning several product lines including Smart Software Manager On-Prem, Integrated Management Controller (IMC), Evolved Programmable Network Manager, NFVIS, Nexus Dashboard, Nexus Dashboard Insights, and Nexus Dashboard Fabric Controller. The most severe flaws could allow an attacker to achieve arbitrary code execution, potentially leading to complete compromise of affected devices. All identified vulnerabilities map to exploitation of public-facing applications as the initial access vector.

Affected systems include widely deployed enterprise infrastructure components such as UCS C-Series and E-Series rack servers, Cisco Telemetry Broker appliances, Secure Endpoint Private Cloud appliances, Secure Network Analytics appliances, and Catalyst 8300 Series edge uCPE devices. As of publication, there are no reports of in-the-wild exploitation, but given the breadth of affected management and orchestration platforms, timely patching is recommended.

MS-ISAC recommends organizations apply Cisco's updates after testing, enforce least-privilege access, restrict administrative accounts, conduct regular vulnerability scanning and penetration testing, and maintain network segmentation to limit exposure of these management interfaces.

Mentioned in this report

Vulnerabilities CVE-2024-20432CVE-2026-20041CVE-2026-20042CVE-2026-20085CVE-2026-20087CVE-2026-20093CVE-2026-20094CVE-2026-20095CVE-2026-20151CVE-2026-20155CVE-2026-20160CVE-2026-20174

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-cisco-products-could-allow-for-arbitrary-code-execution_2026-029

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free