Cisco disclosed two vulnerabilities affecting Cisco Smart Software Manager On-Prem: one that allows arbitrary command execution and another that enables privilege escalation. The issues were published as separate Cisco security advisories and affect the on-premises software management platform used to manage Cisco licenses and entitlements within enterprise environments.
Together, the flaws raise the risk that an attacker could execute commands on a vulnerable appliance and gain elevated privileges, increasing the potential impact on systems running the product. Organizations using Cisco Smart Software Manager On-Prem should review the relevant Cisco advisories, determine exposure in their deployments, and prioritize vendor-recommended remediation to reduce the risk of compromise.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
Cisco released fixes for CVE-2026-20093, a critical Integrated Management Controller vulnerability that could allow an unauthenticated remote attacker to bypass authentication, change user passwords, and gain elevated access. Cisco said there was no evidence of in-the-wild exploitation and that no workaround was available.
Cisco published a separate security advisory for a privilege escalation vulnerability affecting Cisco Smart Software Manager On-Prem. The advisory was released on 2026-01-04.
Cisco published a security advisory for an arbitrary command execution vulnerability affecting Cisco Smart Software Manager On-Prem. The advisory was released on 2026-01-04.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
runzero.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcesec.cloudapps.cisco.com
Open sourcesec.cloudapps.cisco.com
Open sourcesec.cloudapps.cisco.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.