DIRAS TAKE
Act urgently: public exploit code exists for this flaw, so immediately restrict network access to the web management interface and follow vendor guidance to mitigate exposure.
What is CVE-2026-20200?
An authenticated, remote attacker with low privileges can run arbitrary commands and escalate to root on Cisco Unified Computing System (Standalone) web management interfaces; this is tracked as CVE-2026-20200. The flaw affects multiple 4.x branch builds (examples include 4.3(1.230097), 4.3(2.240002) and several 4.3.x builds listed by the vendor). Exploitation requires network access to the product's web-based management interface and a low-privilege account that can submit crafted inputs to the interface.
Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Which versions of Cisco Cisco Unified Computing System (Standalone) are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 4.x | 4.3(1.230097) | |
| 4.x | 4.3(1.230124) | |
| 4.x | 4.3(1.230138) | |
| 4.x | 4.3(2.230207) | |
| 4.x | 4.3(2.230270) | |
| 4.x | 4.3(2.240002) | |
| 4.x | 4.3(3.240022) | |
| 4.x | 4.3(3.240043) | |
| 4.x | 4.3(4.240142) | |
| 4.x | 4.3(4.240152) |
Is CVE-2026-20200 being exploited?
Public exploit code is available.
How to fix CVE-2026-20200
- Restrict access to the web-based management interface to trusted management networks and use IP allowlists.
- Increase authentication controls for the management interface and rotate administrative credentials.
- Monitor management interface logs and host integrity for suspicious commands or privilege escalation indicators.
- Follow Cisco's official advisory and apply vendor guidance as it becomes available.
Frequently asked questions
Is CVE-2026-20200 being actively exploited?
Public exploit code is available for CVE-2026-20200; the vulnerability is not listed in CISA's KEV catalog as of 2026-09-29.
Which Cisco Unified Computing System (Standalone) versions are affected by CVE-2026-20200?
Multiple 4.x branch builds of Cisco Unified Computing System (Standalone) are affected, including several 4.3(...) builds such as 4.3(1.230097), 4.3(2.240002), and others listed by the vendor.
Is there a patch for CVE-2026-20200?
There are no fixed versions listed for CVE-2026-20200 in the vendor-affected data as of 2026-09-29; follow Cisco guidance for mitigations.
Does CVE-2026-20200 require authentication?
Yes; the issue requires a low-privilege authenticated account interacting with the Cisco Unified Computing System (Standalone) web-based management interface.
References
- nvd.nist.gov/vuln/detail/CVE-2026-20200
- cve.org/CVERecord?id=CVE-2026-20200
- sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU
- All Cisco CVEs on CVE Radar
- CVEs published in September 2026