Description
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities.

The vulnerabilities tracked by CVE-2026-20325 are related to improper neutralization of special elements used in a command issue that are grouped under the Common Weakness Enumeration (CWE) CWE-77.
Published: 2026-09-16
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

CVE-2026-20325 represents a command injection vulnerability caused by improper neutralization of special elements in command processing. Attackers could supply crafted input that bypasses validation, allowing arbitrary command execution on the underlying system, leading to full system compromise. The weakness follows the Common Weakness Enumeration identifier CWE-77.

Affected Systems

The vulnerability affects Cisco Nexus Dashboard software. The specific affected release versions are not detailed in the advisory, but the issue was mitigated in the September 2026 hardening release. Organizations running any version of Cisco Nexus Dashboard should verify whether their product is part of the patched update.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.9, indicating a very high severity. However, the EPSS score is listed as < 1 %, meaning the likelihood of exploitation in the wild is very low. The vulnerability is not currently listed in CISA’s KEV catalog. Likely attack vectors involve remote exploitation through exposed management interfaces where command parameters are not properly sanitized.

Generated by OpenCVE AI on September 17, 2026 at 22:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Cisco Nexus Dashboard September 2026 hardening release that includes the CVE-2026-20325 fix.
  • If the patch cannot be applied immediately, restrict access to the Nexus Dashboard interface to trusted networks or IP ranges to limit exposure to command injection attempts.
  • Enable and monitor audit logs for suspicious command execution attempts to detect potential exploitation.

Generated by OpenCVE AI on September 17, 2026 at 22:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Cisco
Cisco nexus Dashboard
Vendors & Products Cisco
Cisco nexus Dashboard

Thu, 17 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard&nbsp;engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20325 are related to improper neutralization of special elements used in a command issue that are grouped under the Common Weakness Enumeration (CWE) CWE-77.
Title Cisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Neutralization of Special Elements used in a Command
Weaknesses CWE-77
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Cisco Nexus Dashboard
cve-icon MITRE

Status: PUBLISHED

Assigner: cisco

Published:

Updated: 2026-09-18T14:55:13.551Z

Reserved: 2025-10-08T11:59:15.411Z

Link: CVE-2026-20325

cve-icon Vulnrichment

Updated: 2026-09-17T13:36:22.440Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T20:17:23.347

Modified: 2026-09-18T15:17:07.450

Link: CVE-2026-20325

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:36:40Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')