← Vulnerability feed

Vulnerability record · CVE-2026-20996 · published 16 March 2026

CVE-2026-20996: Samsung smart switch broken cryptographic algorithm vulnerability

Samsung · Smart Switch

Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.69.15 allows remote attackers to configure a downgraded scheme for authentication.

7.1 CVSS 4.0 High EPSS 0.17% · top 94.6% CWE-327 · Broken cryptographic algorithm
7.1CVSS 4.0 base score
0.17%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Use of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.69.15 allows remote attackers to configure a downgraded scheme for authentication.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-20996 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2025-21062Samsung smart switch broken cryptographic algorithm vulnerabilityUse of a broken or risky cryptographic algorithm in Smart Switch prior to version 3.7.67.2 allows local attackers to replace the restoring applicatio…EPSS 0.10%7.1CVE-2026-21005Samsung smart switch path traversal vulnerabilityPath traversal in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to overwrite arbitrary files with Smart Switch privilege.EPSS 0.24%7.1CVE-2026-20998Samsung smart switch vulnerabilityImproper authentication in Smart Switch prior to version 3.7.69.15 allows remote attackers to bypass authentication.EPSS 0.55%7.1CVE-2026-20999Samsung smart switch authentication bypass by capture-replay vulnerabilityAuthentication bypass by replay in Smart Switch prior to version 3.7.69.15 allows remote attackers to trigger privileged functions.EPSS 0.31%7.0CVE-2026-21079Samsung smart switch missing encryption vulnerabilityMissing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept transmitted data.EPSS 0.10%6.9CVE-2026-21080Samsung smart switch cleartext storage of sensitive data vulnerabilityCleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.EPSS 0.17%6.9CVE-2026-21004Samsung smart switch improper authentication vulnerabilityImproper authentication in Smart Switch prior to version 3.7.69.15 allows adjacent attackers to trigger a denial of service.EPSS 0.19%6.8CVE-2026-21083Samsung smart switch improper input validation vulnerabilityImproper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.EPSS 0.26%

Source: NIST National Vulnerability Database (record CVE-2026-20996), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.