SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-20358

CRITICAL · CVSS 10 EPSS 0.46%

Source: NVD + CISA KEV + EPSS · Published 2026-08-19 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Cisco products are vulnerable due to external control of the file system, which could allow an attacker to manipulate files and potentially execute arbitrary code. The impact is critical, with a CVSS score of 10.0, indicating severe risk to system integrity and confidentiality. Organizations using affected Cisco products should prioritize immediate remediation to mitigate potential exploitation.

CVE
CVE-2026-20358
Severity
CRITICAL
CVSS
10
EPSS
0.46%
Cisco

Original NVD Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20358 are related to external control of the file system issues that are grouped Common Weakness Enumeration (CWE) CWE-73.