CVE-2026-20016

MEDIUM

CVSS v3.1: 6.0 · EPSS: 0.0001 (0.7 percentile)

No user interactionVendor advisory ref

Source data as of:

At a glance

Severity
MEDIUM
CVSS
6.0 v3.1 · NVD
EPSS
0.0001 (0.7 percentile) · FIRST.org
CISA KEV
No
Attack conditions (CVSS vector)
No user interaction · Source: NVD Vector
Affected vendors
cisco
Published
2026-03-04 · Modified: 2026-06-05

CVSS / EPSS / KEV

CVSS v3.1 6.0 / 10 MEDIUM Source: NVD
EPSS 0.0001 0.7 percentile Source: FIRST.org
CISA KEV No Source: CISA

Source — CVSS: NVD · EPSS: FIRST.org · KEV: CISA. Data & Sources

Description

A vulnerability in the Cisco FXOS Software CLI feature for Cisco Secure Firewall ASA Software and Secure FTD Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system with root-level privileges. To exploit this vulnerability, the attacker must have valid administrative credentials on an affected device. This vulnerability is due to insufficient input validation of user-supplied command arguments. An attacker could exploit this vulnerability by submitting crafted input for specific CLI commands. A successful exploit could allow the attacker to execute commands on the underlying operating system with root-level privileges.

Record details

CVE ID
CVE-2026-20016
CVSS (v3.1)
6.0 (MEDIUM)
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Exploitability subscore
0.8
Impact subscore
5.2
EPSS
0.0001 (0.7 percentile) — 2026-06-06
CISA KEV
No
Weakness (CWE)
CWE-88
Affected vendors
cisco
Affected configurations (CPE)
10
Published
2026-03-04
Modified
2026-06-05
Status
Analyzed

References

Reference URLs as listed by NVD, grouped by a mechanical match on the link's host/pattern. Labels describe the link type only.