CVE-2026-20360
Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Information Exposure & Insecure Handling
Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20360 are related to information exposure and insecure handling issues that are grouped under the Common Weakness Enumeration (CWE) CWE-200.
In plain language
AI Act nowCisco Nexus Dashboard has a serious security weakness with a public attack tool available, so businesses using it should act now.
CVE-2026-20360 is a CVSS 8.8 network-accessible flaw in Cisco Nexus Dashboard involving information exposure and insecure handling; an attacker needs a low-privileged account and can affect confidentiality, integrity, and availability.
What to do now
- Confirm whether your organization runs Cisco Nexus Dashboard and identify its installed version.
- Ask your Cisco support contact whether your version is affected; Cisco has not published a fixed version or patch information for CVE-2026-20360.
- Limit Cisco Nexus Dashboard access to necessary, trusted administrator accounts and remove unused accounts.
- Review dashboard administrator activity for unexpected configuration changes or data access.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-20360 and every CVE in our database. Create a free account — no credit card required.
Create Free Account