Cyber Security News

Cisco Smart Software Manager Vulnerability Let Attackers Execute Arbitrary Commands

Cisco has issued an urgent security warning regarding a critical vulnerability in its Smart Software Manager On-Prem (SSM On-Prem) platform.

Enterprise organizations widely use this tool to manage their Cisco software licenses locally. Tracked as CVE-2026-20160, the flaw carries a near-perfect CVSS severity score of 9.8 out of 10. If exploited, it allows an unauthenticated, remote attacker to take complete control of the affected system.

Cisco Smart Software Manager Vulnerability

The core of the problem stems from an internal system service that was accidentally left exposed. Because of this oversight, attackers do not need a username, password, or any prior authorized access to the network to exploit the machine.

To trigger the vulnerability, a hacker needs to send a specially crafted request to the application programming interface (API) of this exposed service.

 If the attack is successful, the threat actor can execute arbitrary commands on the underlying operating system. Worse yet, these commands run with root-level privileges.

This means the attacker gains absolute administrative control over the host, allowing them to steal sensitive data, install ransomware, or pivot to other protected areas of the corporate network.

This bug specifically impacts Cisco SSM On-Prem environments. However, not all versions are at risk.

Organizations only need to worry if they are running specific software releases published during the previous year.

Here is the breakdown of the software versions:

  • Vulnerable: Releases from 9-202502 up to 9-202510.
  • Safe: Any older release (before 9-202502) is naturally immune to the flaw.
  • Fixed: The newly released version 9-202601 contains the official patch.

Cisco also confirmed that this issue does not affect the Smart Licensing Utility or the Smart Software Manager satellite products. If your organization is running a vulnerable version, immediate action is required.

Current Exploitation Status

Cisco has stated clearly that there are no workarounds or temporary mitigations available to block this attack.

The only way to secure your network is to upgrade your SSM On-Prem software to the fixed release (9-202601) as soon as possible.

 Before upgrading, IT teams should verify that their devices meet the memory and hardware requirements for the new release.

Cisco’s Product Security Incident Response Team (PSIRT) noted that there are currently no known public exploits or malicious campaigns exploiting this bug.

The vulnerability was actually discovered internally while a Cisco Technical Assistance Center (TAC) team was helping a customer resolve an unrelated support case.

However, because the details of CVE-2026-20160 are now public, cybercriminals will likely begin reverse-engineering the patch and scanning the internet for vulnerable systems.

Security teams should treat this upgrade as a top priority to prevent a potential network compromise.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago