CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2024-20399: Cisco NX-OS Flaw Exploited by Velvet Ant

June 25, 2026

CVE-2024-20399 is a vulnerability in Cisco NX-OS that requires admin access and was exploited by the China-linked group Velvet Ant to plant backdoors on switches. Cisco patched it in July 2024, and CISA flagged it as exploited the next day.