Skip to content
CiscoCVE-2026-20200

Cisco Unified Computing System (Standalone): remote code execution

High8.8CVE-2026-20200 · Published Aug 5, 2026 · updated Aug 31, 2026

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root.  This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user. 

Cisco advisory

Affected versions

PackageAffectedFixed in
Cisco Unified Computing System (Standalone)
Product
<= 4.3(1.230097)No fix yet
<= 4.3(1.230124)No fix yet
<= 4.3(1.230138)No fix yet
<= 4.3(2.230207)No fix yet
Details and references

More Cisco advisories

All Cisco
Advisory
Cisco Catalyst SD-WAN: cleartext secrets
High8.8Aug 5
Cisco Catalyst SD-WAN: improper quantity validation
High7.7Aug 5
Cisco IOS XE Software: denial of service
Medium4.3Aug 5
Cisco Catalyst SD-WAN: link following
Critical9.1Aug 5
Cisco IOS XE Software: denial of service
Medium6.3Aug 5
Cisco IOS XE Software: denial of service
High8.6Aug 5

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.