CVE-2026-20199

HIGH

A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to execute commands on the underlying operating system as the r...

Affects 0 products across 3 vendors.

BCS3.14
CVSS 3.17.2
EPSS0.4%
Percentile36th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, high privileges required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-74: Injection

Parent class for all injection vulnerabilities where attacker-supplied data is interpreted as code or commands.

Related Attack Patterns (CAPEC)
CAPEC-3 Using Leading 'Ghost' Character Sequences to Bypass Input Filters
via CWE-74
CAPEC-7 Blind SQL Injection
via CWE-74
CAPEC-8 Buffer Overflow in an API Call
via CWE-74
CAPEC-9 Buffer Overflow in Local Command-Line Utilities
via CWE-74
CAPEC-10 Buffer Overflow via Environment Variables
via CWE-74
Show all 37
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74
via CWE-74

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance allows an authenticated, remote attacker to execute commands on the underlying operating system as the root user due to insufficient validation of user-supplied input.

BSID: BS-2026-GLOBAL-268619-M • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2026-20199?
A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance allows an authenticated, remote attacker to execute commands on the underlying operating system as the root user due to insufficient validation of user-supplied input.
What is the CVSS score for CVE-2026-20199?
CVE-2026-20199 has CVSS 7.2 (High). Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H. EPSS: 0.4%.
Is CVE-2026-20199 actively exploited?
No confirmed active exploitation of CVE-2026-20199 as of 2026-07-01.
How do I remediate CVE-2026-20199?
Priority: HIGH. Advisory: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-tevacert-rce-RMJVEym5 PSIRT: [email protected]
What systems are affected by CVE-2026-20199?
CVE-2026-20199 affects: Cisco, Francisco Burzi, Valid.
Vulnerability Details
CVE IDCVE-2026-20199
BSIDBS-2026-GLOBAL-268619-M BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Published2026-05-20
Last Modified2026-06-30
ICS Relevance55%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to execute commands on the underlying operating system as the root user. This vulnerability is due to insufficient validation of user-supplied input. An authenticated attacker could exploit this vulnerability by uploading a crafted certificate to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system. To exploit this vulnerability, the attacker must have valid administrative credentials.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An authenticated attacker can exploit this vulnerability by uploading a crafted certificate to an affected device.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Cisco —
Francisco Burzi —
Valid —
Remediation
View Vendor Advisory →

Remediation Priority: HIGH

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 66 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash2b2cf65d2991c93e491b3235b3fa89732a1f6b04a760f4f3a1f767e9e428b555365fa435a856ec9ba2f86a616e3beb71fa74a00e576e6891e3bb9225c5d6d2da
Related CVEs affecting Cisco
CVE-2025-20393 10.0 A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for ... CVE-2007-2036 10.0 The SNMP implementation in the Cisco Wireless LAN Controller (WLC) before 200... CVE-2003-0732 10.0 CiscoWorks Common Management Foundation (CMF) 2.1 and earlier allows the gues... CVE-2004-0308 10.0 Unknown vulnerability in Cisco ONS 15327 before 4.1(3), ONS 15454 before 4.6(... CVE-2007-5382 10.0 The conversion utility for converting CiscoWorks Wireless LAN Solution Engine...
View all Cisco CVEs →

ICS/OT Vulnerability Intelligence for Your Environment

BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.

Join free →