Skip to content
CiscoCVE-2026-20198

Cisco Enterprise NFV Infrastructure Software: cross-site scripting

Medium4.8CVE-2026-20198 · Published Aug 5, 2026 · updated Aug 6, 2026

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the browser of the targeted user or access sensitive, browser-based information.

Cisco advisory

Affected versions

PackageAffectedFixed in
Cisco Enterprise NFV Infrastructure Software
Product
<= 4.1.1No fix yet
<= 3.9.1No fix yet
<= 3.5.2No fix yet
<= 3.12.2No fix yet
Cisco Unified Computing System (Standalone)
Product
<= 4.0(2g)No fix yet
<= 3.1(2i)No fix yet
<= 3.1(1d)No fix yet
<= 4.0(4i)No fix yet
Cisco Unified Computing System E-Series Software (UCSE)
Product
<= 3.2.7No fix yet
<= 3.2.6No fix yet
<= 3.2.4No fix yet
<= 3.2.10No fix yet
Details and references

More Cisco advisories

All Cisco
Advisory
Cisco Catalyst SD-WAN: cleartext secrets
High8.8Aug 5
Cisco Catalyst SD-WAN: improper quantity validation
High7.7Aug 5
Cisco IOS XE Software: denial of service
Medium4.3Aug 5
Cisco Catalyst SD-WAN: link following
Critical9.1Aug 5
Cisco IOS XE Software: denial of service
Medium6.3Aug 5
Cisco IOS XE Software: denial of service
High8.6Aug 5

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.