Skip to content
ThreatCluster

Multiple Cisco Vulnerabilities Expose Systems to Command Injection and Configuration Alteration

First seen 16 Sep 2026, 16:30 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 16, 2026 at 18:53 UTC
  • Cisco disclosed critical vulnerabilities in multiple products affecting command execution and configuration.
  • CVE-2026-20288 and CVE-2026-20200 allow privilege escalation and command injection.
  • Software updates are available, but no workarounds exist for these vulnerabilities.

Cisco has disclosed multiple vulnerabilities affecting its products, including the Integrated Management Controller, BroadWorks CommPilot Application Software, and ThousandEyes Virtual Appliance. The vulnerabilities allow authenticated attackers to execute arbitrary commands or alter configurations due to improper validation and missing authorization checks. CVE-2026-20288 and CVE-2026-20200, both published on 2026-08-05, are among the critical vulnerabilities that could lead to privilege escalation. Cisco has released software updates to address these issues, but no workarounds are available. The vulnerabilities affect a wide range of Cisco products, including various UCS servers and appliances. Security professionals are urged to apply the updates promptly to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-08-05
CVE-2026-20288 published
Cisco disclosed a vulnerability allowing command execution on affected systems, impacting multiple products.
Sec.Cloudapps.Cisco
2026-08-05
CVE-2026-20200 published
Cisco disclosed a vulnerability in BroadWorks CommPilot Application Software allowing configuration alteration.
Sec.Cloudapps.Cisco
2026-09-16
Cisco releases updates for vulnerabilities
Cisco has released software updates to address the vulnerabilities across affected products, urging users to apply them immediately.
Sec.Cloudapps.Cisco

More articles in this cluster (3)

Following this threat?

Track Cisco and CVE-2026-20200 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed