CVE-2026-20198
CVE-2026-20198: 2 tracked advisory records across Cisco. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Cisco
2 advisories- Advisory severityHigh
High [CVE-2026-20028 +21] Cisco Advance Notification for Publication of August 5, 2026, Security Advisories
cisco-sa-notice-L4XfJg8SSource published Source updated
This bulletin covers 22 CVEs. The products, versions, score and guidance below describe the bulletin; check its source for applicability to this specific CVE.
On August 5, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026 CVE-2026-20303 CVE-2026-20304 CVE-2026-20310 CVE-2026-20312 CVE-2026-20313 Critical 9.9 Cisco IOS XE Software Security Hardening Release: August 2026 CVE-2026-20267 CVE-2026-20268 CVE-2026-20269 CVE-2026-20270 CVE-2026-20271 CVE-2026-20272 CVE-2026-20273 Critical 9.8 Cisco Integrated Management Controller Argument Injection Vulnerabilities CVE-2026-20200 CVE-2026-20288 High 8.8 Cisco IOS Software and IOS XE Software Extensible…
- Affected products in this advisory
- No product details extracted. Check the source bulletin.
- Source-reported affected versions
- Affected-version details not available in this record.
- Source-reported fixed versions
- No fixed-version detail extracted. This does not mean no fix exists.
- Mitigation guidance
- On August 5, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products: Catalyst SD-WAN Integrated Management Controller (IMC) IOS Software IOS XE Software RoomOS Terminal Services Agent To fully remediate vulnerabilities to be disclosed on August 5, 2026, Cisco strongly recommends that customers upgrade to the fixed software indicated in the advisories.
- Advisory severityMedium4.8
Medium [CVE-2026-20198] Cisco Integrated Management Controller Cross-Site Scripting Vulnerability
cisco-sa-cimc-xss-7EhBFxBpSource published Source updated
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the browser of the targeted user or access sensitive, browser-based information. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
- Affected products in this advisory
- Unified Computing System (Standalone)
- Unified Computing System E-Series Software (UCSE)
- Enterprise NFV Infrastructure Software
- Source-reported affected versions
- Scope: At the time of publication, this vulnerability affected the following Cisco products if they were running a vulnerable release of Cisco IMC, regardless of device configuration:
- Earlier than 4.12 — Migrate to a fixed release
- Release 4.12 (first fixed: 4.12.8)
- 4.13 — Migrate to a fixed release
13 more entries in the full advisory.
- Source-reported fixed versions
- 4.12.8
- 4.15.6
- 4.18.5 (Sep 2026)
- 26.1.2
6 more entries in the full advisory.
- Mitigation guidance
- Upgrade to the first fixed release for your train per the Fixed Releases table in this advisory.
- Earlier than 4.12: migrate to a fixed release.
- Release 4.12: upgrade to 4.12.8.
- Release 4.13: migrate to a fixed release.
5 more entries in the full advisory.
- Workarounds
- There are no workarounds that address this vulnerability.
Android app · Google Play
Monitor future Cisco CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.