CVE-2026-20326 CVE-2026-20322 CVE-2026-20325 CVE-2026-76409 CVE-2026-20360 CVE-2026-20361
Cisco Nexus Dashboard September 2026 hardening fixes missing authentication and injection flaws (CVE-2026-20326 and others)
Cisco Nexus Dashboard releases are affected by multiple critical missing authentication and injection flaws. Cisco's September 2026 security hardening release fixes them; no workaround is listed.
What happened
Cisco's September 2026 security hardening release for Cisco Nexus Dashboard addresses several vulnerabilities found during an internal security review. CVE-2026-20326 is missing authentication for a critical function. Its CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, meaning a remote attacker needs no privileges and no user interaction, and can cause high impact across confidentiality, integrity and availability.
The same release also addresses CVE-2026-20322 (improper access control), CVE-2026-20325 (improper neutralisation of special elements used in a command), CVE-2026-76409 (improper limitation of a pathname), CVE-2026-20360 (information exposure and insecure handling) and CVE-2026-20361 (SQL injection). These carry CVSS 3.1 scores of 9.9 and 8.8 and assume a low-privileged attacker over the network with no user interaction; the command injection and access control issues have scope changed.
Cisco PSIRT states it is not aware of any public announcements or malicious use of the vulnerabilities described in this advisory. There is no CISA KEV entry and no public disclosure is recorded.
Who is affected
Cisco Nexus Dashboard is the affected product. Cisco lists the following affected versions: 2.1(1d), 2.1(1e), 2.1(2d), 2.2(1h), 2.2(1e), 2.2(2d), 2.1(2f) and 2.3(1c). If you run Cisco Nexus Dashboard, compare the running version against this list.
What to do now
- Apply the Cisco Nexus Dashboard software security hardening release described in Cisco's September 2026 advisory.
- Plan for no workaround: Cisco states there are no workarounds that address these vulnerabilities. Until the update is applied, restrict network access to the Nexus Dashboard management interface, particularly from untrusted networks.
- Confirm every affected version in your estate is updated, and review administrative accounts and configuration changes for unexpected activity.
How to detect it
Cisco has not published indicators of compromise for these vulnerabilities. Until the hardening release is applied, monitor administrative access and configuration changes on Cisco Nexus Dashboard for unexpected activity.
Beyond the patch
These are the kind of flaws that exposure management and offensive testing are designed to catch before an advisory lands. A network-reachable management interface with missing authentication is an exposure problem, and injection or access-control weaknesses are what a penetration test finds first. Use Virtual CISO Services (vCISO) to reduce exposed management surfaces, or Implementation & Assessment Services to assess and harden your Cisco Nexus Dashboard deployment.
Affected and fixed versions
| Product | Affected | Fixed in |
|---|---|---|
| CVE-2026-20326 Cisco Nexus Dashboard | 2.1(1d) 2.1(1e) 2.1(2d) 2.2(1h) 2.2(1e) 2.2(2d) 2.1(2f) 2.3(1c) | No fixed version listed yet |
| CVE-2026-20322 Cisco Nexus Dashboard | 2.1(1d) 2.1(1e) 2.1(2d) 2.2(1h) 2.2(1e) 2.2(2d) 2.1(2f) 2.3(1c) | No fixed version listed yet |
| CVE-2026-20325 Cisco Nexus Dashboard | 2.1(1d) 2.1(1e) 2.1(2d) 2.2(1h) 2.2(1e) 2.2(2d) 2.1(2f) 2.3(1c) | No fixed version listed yet |
| CVE-2026-76409 Cisco Nexus Dashboard | 2.1(1d) 2.1(1e) 2.1(2d) 2.2(1h) 2.2(1e) 2.2(2d) 2.1(2f) 2.3(1c) | No fixed version listed yet |
| CVE-2026-20360 Cisco Nexus Dashboard | 2.1(1d) 2.1(1e) 2.1(2d) 2.2(1h) 2.2(1e) 2.2(2d) 2.1(2f) 2.3(1c) | No fixed version listed yet |
| CVE-2026-20361 Cisco Nexus Dashboard | 2.1(1d) 2.1(1e) 2.1(2d) 2.2(1h) 2.2(1e) 2.2(2d) 2.1(2f) 2.3(1c) | No fixed version listed yet |