Critical Alert 1 Active Exploit Detected Today

CVE-2026-63077 JetBrains TeamCity Deserialization of Untrusted Data Vulnerability →
Powered by CVE Watchtower
×
August 7, 2026

CVE Watchtower


← Back to CVE List

CVE-2026-20288NVD

Vulnerability Summary

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with Admin privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root. 

This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user. 
Cisco has assigned this vulnerability a SIR of High rather than Medium as the score indicates because additional security implications could occur when the attacker becomes root.
Severity Level
MEDIUM(6.5)
Published Date
Aug 5, 2026
Last Modified
Aug 6, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.35%Probability
Root Weakness (CWE)
Refer to the official MITRE database for detailed architectural specifications regarding this weakness.
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredHigh
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityNone