Skip to content
CVE-2026-20362: Cisco Finesse SSRF Vulnerability Disclosed

CVE-2026-20362: Cisco Finesse SSRF Vulnerability Disclosed

First seen 7 Oct 2026, 22:31 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 7, 2026 at 22:32 UTC
  • •CVE-2026-20362 allows SSRF attacks via Cisco Finesse management interface.
  • •No active exploitation reported, but organizations should prioritize remediation.
  • •Cisco plans to release patches; no workarounds are currently available.

A vulnerability identified as CVE-2026-20362 in the web-based management interface of Cisco Finesse allows unauthenticated remote attackers to conduct server-side request forgery (SSRF) attacks. This flaw stems from improper input validation for specific HTTP requests, enabling attackers to send crafted requests to affected devices. Successful exploitation could yield limited sensitive information associated with the device. Cisco plans to release software updates to address this issue, but currently, there are no workarounds available. Organizations with internet-accessible management interfaces are particularly at risk. The CVSS score for this vulnerability is 7.2, indicating a high severity level. As of now, there are no reports of active exploitation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-07
CVE-2026-20362 published
Cisco disclosed a vulnerability in the Finesse management interface allowing SSRF attacks.
Redpacketsecurity
2026-10-07
Cisco plans software updates
Cisco announced plans to release software updates to address the identified vulnerability.
sec.cloudapps.cisco.com

More articles in this cluster (2)

Following this threat?

Track Cisco and CVE-2026-20362 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What systems are affected?
The vulnerability affects Cisco Finesse management interfaces.
Is there active exploitation of this vulnerability?
No, there are currently no reports of active exploitation.
What should organizations do now?
Organizations should prepare to apply the upcoming patches and monitor for unusual requests.