Answer in brief
CVE-2026-20288 records a Medium severity (CVSS 6.5) vulnerability in Cisco IMC Remote Code Execution Vulnerability Remote Code Execution Vulnerability. The current sources do not mark it as known exploited. The current feed maps Cisco/Cisco Unified Computing System E-Series Software (UCSE) (generic), Cisco/Cisco Unified Computing System (Standalone) (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 6.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Cisco/Cisco Unified Computing System E-Series Software (UCSE) (generic), Cisco/Cisco Unified Computing System (Standalone) (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Cisco/Cisco Unified Computing System E-Series Software (UCSE)generic | 3.2.7 || 3.2.6 || 3.2.4 || 3.2.10 || 3.2.2 || 3.2.3 || 3.2.1 || 3.2.11.1 || 3.2.8 || 3.1.1 || 3.1.2 || 3.1.4 || 3.1.3 || 3.1.5 || 3.1.0 || 3.2.11.3 || 3.2.11.5 || 3.2.12.2 || 3.2.13.6 || 3.2.14 || 4.11.1 || 3.2.15 || 4.12.1 || 3.2.15.3 || 4.12.2 || 3.2.16.1 || 4.15.2 || 3.2.17.1 || 4.15.3 | Not reported |
| Cisco/Cisco Unified Computing System (Standalone)generic | 4.0(2g) || 3.1(2i) || 3.1(1d) || 4.0(4i) || 4.1(1c) || 4.0(2c) || 4.0(1e) || 4.0(2h) || 4.0(4h) || 4.0(1h) || 4.0(2l) || 3.1(3g) || 4.0(1.240) || 4.0(2f) || 4.0(1g) || 4.0(2i) || 3.1(3i) || 4.0(4d) || 4.1(1d) || 3.1(3c) || 4.0(4k) || 3.1(2d) || 3.1(3a) || 3.1(3j) || 4.0(2d) || 4.1(1f) || 4.0(4j) || 4.0(2m) || 4.0(2k) || 4.0(1c) || 4.0(4f) || 4.0(4c) || 3.1(3d) || 3.1(2g) || 3.1(2c) || 4.0(1d) || 3.1(2e) || 4.0(1a) || 4.0(1b) || 3.1(3b) || 4.0(4b) || 3.1(2b) || 4.0(4e) || 3.1(3h) || 4.0(4l) || 4.1(1g) || 4.1(2a) || 4.0(2n) || 4.1(1h) || 3.1(3k) || 4.1(2b) || 4.0(2o) || 4.0(4m) || 4.1(2d) || 4.1(3b) || 4.0(2p) || 4.1(2e) || 4.1(2f) || 4.0(4n) || 4.0(2q) || 4.1(3c) || 4.0(2r) || 4.1(3d) || 4.1(2g) || 4.1(2h) || 4.1(3g) || 4.1(3f) || 4.1(2j) || 4.1(2k) || 4.1(3h) || 4.2(2a) || 4.1(3i) || 4.2(2f) || 4.2(2g) || 4.2(3b) || 4.1(3l) || 4.2(3d) || 4.3(1.230097) || 4.2(1e) || 4.2(1b) || 4.2(1j) || 4.2(1i) || 4.2(1f) || 4.2(1a) || 4.2(1c) || 4.2(1g) || 4.3(1.230124) || 4.1(2l) || 4.2(3e) || 4.3(1.230138) || 4.2(3g) || 4.3(2.230207) || 4.2(3h) || 4.2(3i) || 4.3(2.230270) || 4.1(3m) || 4.1(2m) || 4.3(2.240002) || 4.3(3.240022) || 4.2(3j) || 4.1(3n) || 4.3(2.240009) || 4.3(3.240041) || 4.2(3k) || 4.3(3.240043) || 4.3(4.240142) || 4.3(2.240037) || 4.3(2.240053) || 4.3(4.240152) || 4.2(3l) || 4.3(2.240077) || 4.3(4.242028) || 4.3(4.241063) || 4.3(4.242038) || 4.2(3m) || 4.3(2.240090) || 4.3(5.240021) || 4.3(2.240107) || 4.3(4.242066) || 4.2(3n) || 4.3(5.250001) || 4.2(3o) || 4.3(2.250016) || 4.3(2.250021) || 4.3(5.250030) || 4.3(2.250022) || 4.3(6.250039) || 4.3(6.250040) || 4.3(5.250033) || 4.3(6.250044) || 4.3(6.250053) || 4.3(2.250037) || 4.3(2.250045) || 4.3(4.252001) || 4.3(4.252002) || 6.0(1.250127) || 4.2(3p) || 6.0(1.250131) || 4.3(6.250101) || 6.0(1.250174) || 4.3(6.250117) || 4.3(5.250043) || 4.3(5.250045) || 4.3(6.250060) || 6.0(1.250130) || 4.3(4.241014) || 4.3(2.250063) || 6.0(1.250192) || 4.3(6.260003) || 6.0(1.250194) || 4.3(6.260017) || 4.3(2.260007) || 6.0(2.260044) || 6.0(2.260069) || 4.3(6.260033) || 4.2(3q) | Not reported |
Published upstream
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with Admin privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user. Cisco has assigned this vulnerability a SIR of High rather than Medium as the score indicates because additional security implications could occur when the attacker becomes root.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-20288 records a Medium severity (CVSS 6.5) vulnerability in Cisco IMC Remote Code Execution Vulnerability Remote Code Execution Vulnerability. The current sources do not mark it as known exploited. The current feed maps Cisco/Cisco Unified Computing System E-Series Software (UCSE) (generic), Cisco/Cisco Unified Computing System (Standalone) (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 6.5. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Cisco/Cisco Unified Computing System E-Series Software (UCSE) (generic), Cisco/Cisco Unified Computing System (Standalone) (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Cisco/Cisco Unified Computing System E-Series Software (UCSE)generic | 3.2.7 || 3.2.6 || 3.2.4 || 3.2.10 || 3.2.2 || 3.2.3 || 3.2.1 || 3.2.11.1 || 3.2.8 || 3.1.1 || 3.1.2 || 3.1.4 || 3.1.3 || 3.1.5 || 3.1.0 || 3.2.11.3 || 3.2.11.5 || 3.2.12.2 || 3.2.13.6 || 3.2.14 || 4.11.1 || 3.2.15 || 4.12.1 || 3.2.15.3 || 4.12.2 || 3.2.16.1 || 4.15.2 || 3.2.17.1 || 4.15.3 | Not reported |
| Cisco/Cisco Unified Computing System (Standalone)generic | 4.0(2g) || 3.1(2i) || 3.1(1d) || 4.0(4i) || 4.1(1c) || 4.0(2c) || 4.0(1e) || 4.0(2h) || 4.0(4h) || 4.0(1h) || 4.0(2l) || 3.1(3g) || 4.0(1.240) || 4.0(2f) || 4.0(1g) || 4.0(2i) || 3.1(3i) || 4.0(4d) || 4.1(1d) || 3.1(3c) || 4.0(4k) || 3.1(2d) || 3.1(3a) || 3.1(3j) || 4.0(2d) || 4.1(1f) || 4.0(4j) || 4.0(2m) || 4.0(2k) || 4.0(1c) || 4.0(4f) || 4.0(4c) || 3.1(3d) || 3.1(2g) || 3.1(2c) || 4.0(1d) || 3.1(2e) || 4.0(1a) || 4.0(1b) || 3.1(3b) || 4.0(4b) || 3.1(2b) || 4.0(4e) || 3.1(3h) || 4.0(4l) || 4.1(1g) || 4.1(2a) || 4.0(2n) || 4.1(1h) || 3.1(3k) || 4.1(2b) || 4.0(2o) || 4.0(4m) || 4.1(2d) || 4.1(3b) || 4.0(2p) || 4.1(2e) || 4.1(2f) || 4.0(4n) || 4.0(2q) || 4.1(3c) || 4.0(2r) || 4.1(3d) || 4.1(2g) || 4.1(2h) || 4.1(3g) || 4.1(3f) || 4.1(2j) || 4.1(2k) || 4.1(3h) || 4.2(2a) || 4.1(3i) || 4.2(2f) || 4.2(2g) || 4.2(3b) || 4.1(3l) || 4.2(3d) || 4.3(1.230097) || 4.2(1e) || 4.2(1b) || 4.2(1j) || 4.2(1i) || 4.2(1f) || 4.2(1a) || 4.2(1c) || 4.2(1g) || 4.3(1.230124) || 4.1(2l) || 4.2(3e) || 4.3(1.230138) || 4.2(3g) || 4.3(2.230207) || 4.2(3h) || 4.2(3i) || 4.3(2.230270) || 4.1(3m) || 4.1(2m) || 4.3(2.240002) || 4.3(3.240022) || 4.2(3j) || 4.1(3n) || 4.3(2.240009) || 4.3(3.240041) || 4.2(3k) || 4.3(3.240043) || 4.3(4.240142) || 4.3(2.240037) || 4.3(2.240053) || 4.3(4.240152) || 4.2(3l) || 4.3(2.240077) || 4.3(4.242028) || 4.3(4.241063) || 4.3(4.242038) || 4.2(3m) || 4.3(2.240090) || 4.3(5.240021) || 4.3(2.240107) || 4.3(4.242066) || 4.2(3n) || 4.3(5.250001) || 4.2(3o) || 4.3(2.250016) || 4.3(2.250021) || 4.3(5.250030) || 4.3(2.250022) || 4.3(6.250039) || 4.3(6.250040) || 4.3(5.250033) || 4.3(6.250044) || 4.3(6.250053) || 4.3(2.250037) || 4.3(2.250045) || 4.3(4.252001) || 4.3(4.252002) || 6.0(1.250127) || 4.2(3p) || 6.0(1.250131) || 4.3(6.250101) || 6.0(1.250174) || 4.3(6.250117) || 4.3(5.250043) || 4.3(5.250045) || 4.3(6.250060) || 6.0(1.250130) || 4.3(4.241014) || 4.3(2.250063) || 6.0(1.250192) || 4.3(6.260003) || 6.0(1.250194) || 4.3(6.260017) || 4.3(2.260007) || 6.0(2.260044) || 6.0(2.260069) || 4.3(6.260033) || 4.2(3q) | Not reported |
Published upstream
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with Admin privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user. Cisco has assigned this vulnerability a SIR of High rather than Medium as the score indicates because additional security implications could occur when the attacker becomes root.
Quoted source text, attributed separately from HOL analysis.