ZeroHour

CVE-2026-20360

large

Information Exposure and Insecure Handling Flaws in Cisco Nexus Dashboard

CVSS 3.1
8.8 high
EPSS
Published
()
Modified
AI analysis

Cisco Nexus Dashboard contains multiple internally discovered information-exposure and insecure-handling flaws (CWE-200), which Cisco is addressing together in a software hardening release. Based on the CVSS vector, the issues can be triggered remotely by an authenticated low-privileged user, with no user interaction or special conditions required. An attacker who successfully exploits these flaws can obtain sensitive information, and the 8.8 (high) rating indicates potential high impact to confidentiality, integrity, and availability. Any organization running Cisco Nexus Dashboard as the management/control platform for its Cisco data-center environment is potentially affected. No public proof-of-concept or in-the-wild exploitation is known, and the issue is not listed in CISA's Known Exploited Vulnerabilities catalog.

What to do: Review the Cisco PSIRT advisory for the exact fixed Nexus Dashboard release and upgrade promptly, since this hardening release bundles multiple internally found flaws. Restrict Nexus Dashboard management access to trusted administrative networks, review low-privileged user accounts and exposed services for signs of information gathering, and monitor Cisco for updated guidance as more detail on the individual issues may emerge.

Affected
Cisco Nexus Dashboard
Estimated exposure
largeon the order of tens of thousands of Nexus Dashboard deployments worldwide, with only a minority directly internet-exposed — Nexus Dashboard is Cisco's consolidated management/control platform for its very large ACI and NX-OS data-center switching install base, so deployments likely number in the tens of thousands, though most sit on internal management networks…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20360 are related to information exposure and insecure handling issues that are grouped under the Common Weakness Enumeration (CWE) CWE-200.

Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.