ZDI-26-719: Cisco ThousandEyes Virtual Appliance DHCP Client Command Injection Remote Code Execution Vulnerability
Executive Summary
A remote code execution vulnerability (CVE-2026-20350) in Cisco ThousandEyes Virtual Appliance allows authenticated attackers to inject commands via the DHCP client, enabling arbitrary code execution. The flaw carries a CVSS score of 7.2 and was identified by Zero Day Initiative.
Intelligence Metadata - Source Publisher: Zero Day Initiative - Published Date: 2026-09-22T05:00:00+00:00 - Category: cves
Original Description: This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco ThousandEyes Virtual Appliance. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-20350.
"The world makes way for the man who knows where he is going."
— Ralph Emerson