Cisco Found a Missing Login Check in Its Data-Centre Control Panel
The software coordinating a data centre deserves scrutiny before an attacker proves why. Cisco Nexus Dashboard hardening now addresses six vulnerability classes, including a missing authentication check for a critical function. Cisco reports no known malicious use, but the significance of a management-plane weakness does not depend on waiting for a public incident.
The 16 September bulletin groups defects by class, scoring each group’s worst member. These identifiers are not a count of individual bugs.
Six identifiers do not mean six identical attack paths
| Identifier | Maximum CVSS | Class | Privileges in published maximum-severity vector |
|---|---|---|---|
| CVE-2026-20322 | 9.9 | Improper access control | Low |
| CVE-2026-20325 | 9.9 | Command or code injection | Low |
| CVE-2026-20326 | 9.8 | Missing authentication | None |
| CVE-2026-20360 | 8.8 | Information exposure | Low |
| CVE-2026-20361 | 8.8 | SQL injection | Low |
| CVE-2026-76409 | 8.8 | Path traversal | Low |
The original CNA records expose a useful distinction: the published missing-authentication vector requires no privileges; the other five require low privileges. These are worst-member vectors, not complete prerequisites for every grouped defect. Treating all six classes as unauthenticated root execution would overstate the evidence.
One remediation table applies to all six identifiers
| Nexus Dashboard branch | Remediation |
|---|---|
| 4.2 and earlier | Migrate to a fixed release |
| 4.3 | First fixed release 4.3.1.175 |
All six classes share no-workaround and no-known-exploitation guidance. Cisco says configuration does not remove affected software from scope. No credible public exploit was verified. Access restrictions are not the product fix.
Make the change measurable before calling it complete
BlackTree recommends treating the dashboard as a control-plane dependency in the change process. Agree who owns availability, who verifies the resulting build and who reviews anything suspicious found during the work. A patch ticket should distinguish a technical upgrade result from an incident-response conclusion.
- Identify every deployment. Record the branch, running build, administrative reachability and owner. Include test or recovery deployments with real infrastructure access.
- Check the migration path. Assess compatibility, dependencies, backups and the vendor’s upgrade procedure before replacing an older branch.
- Verify the running version afterwards. Confirm the actual software on the deployment rather than relying only on the success of an installation task.
- Review privileged connections. Document which administrators, automation accounts and networks should reach the management surface. Remove unnecessary access through the normal change process.
- Test useful operation and monitoring. Confirm expected management functions, recovery access and central logging after the upgrade.
- Escalate evidence, not assumptions. Unexpected accounts, files or changes deserve investigation. The bulletin alone does not prove that a particular deployment was compromised.
Related BlackTree coverage of Nexus 9000 switch code execution concerns a different product and attack path. A completed switch remediation is not evidence that Nexus Dashboard has received this hardening release.
The practical question is not whether the bulletin has six red scores. It is whether the system trusted to coordinate infrastructure is running the fixed software, with an accountable owner and a verified result.
Sources
- Cisco, Nexus Dashboard Software Security Hardening Release: September 2026, first published 16 September 2026 at 16:00 GMT, 18:00 Europe/Madrid. Reviewed version 1.0, Final; no later revision time was shown.
Original CNA records, published and last updated on 16 September 2026: access control at 20:02:56 UTC; injection at 20:06:50 UTC; missing authentication at 20:02:33 UTC; information exposure at 20:13:40 UTC; SQL injection at 20:08:08 UTC; and path traversal at 20:10:07 UTC. Madrid times are two hours later. Clocks are shown to the second, omitting record milliseconds.


