cisco-sa-cnc-inj-QNMeEmxk
Cisco Crosswork Network Controller Server-Side Template Injection Vulnerability
CVEs:CVE-2026-20220
Affected products
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-273559 | affected | Cisco | — | — |
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 3 are already weaponised in the wild — see the Exploited section.
Cisco Crosswork Network Controller Server-Side Template Injection Vulnerability
CVEs:CVE-2026-20220
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-273559 | affected | Cisco | — | — |
Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities
CVEs:CVE-2026-20181CVE-2026-20190
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-111903 | affected | Cisco | — | — |
| CVRFPID-292424 | affected | Cisco | — | — |
Cisco Umbrella Virtual Appliance Privilege Escalation Vulnerability
CVEs:CVE-2026-20246
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-231188 | affected | Cisco | — | — |
Cisco Webex App Open Redirect Vulnerability
CVEs:CVE-2026-20178
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-210403 | affected | Cisco | — | — |
Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability
CVEs:CVE-2026-20262
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-271450 | affected | Cisco | — | — |
Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerability
CVEs:CVE-2026-20245
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-271450 | affected | Cisco | — | — |
| CVRFPID-292518 | affected | Cisco | — | — |
Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability
CVEs:CVE-2026-20230
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-88444 | affected | Cisco | — | — |
Cisco Finesse Remote File Inclusion Vulnerability
CVEs:CVE-2026-20175
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-193469 | affected | Cisco | — | — |
Cisco Webex Meetings Cross-Site Scripting Vulnerability
CVEs:CVE-2026-20233
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| CVRFPID-228295 | affected | Cisco | — | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.