CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-20200

criticalpublic exploitCVSS 8.8covered by 5 sourcesfirst seen 2026-08-05
Public exploit code is available. Proof-of-concept or working exploit code for CVE-2026-20200 is indexed in GitHub PoC. Expect opportunistic scanning and exploitation attempts — prioritize remediation even though it is not (yet) in the CISA KEV catalog.
A remote, authenticated attacker can exploit multiple vulnerabilities in Cisco Integrated Management Controller to conduct a cross site scripting attack or execute arbitrary code with root privileges.

CSIRTS triage

What
Multiple vulnerabilities allow authenticated attackers to conduct cross-site scripting attacks or execute arbitrary code with root privileges.
Who is affected
Cisco Integrated Management Controller deployments accessible to authenticated users.
Urgency
High severity with authenticated remote code execution as root demands immediate remediation.
Action
Apply Cisco security patches for Integrated Management Controller.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-20200

Get an email if CVE-2026-20200 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Exploit availability

Public exploit or proof-of-concept code for CVE-2026-20200 is indexed in these free datasets. Available exploit code raises real-world risk independent of the CVSS score.

Advisory coverage (5)

External references

NVD record for CVE-2026-20200

CVE.org record

Embed the live status

CVE-2026-20200 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-20200 status](https://www.csirts.com/badge/CVE-2026-20200)](https://www.csirts.com/cve/CVE-2026-20200)