Výsledky hledání

výrobce: Cisco v celém archivu

zrušit filtry CZ · EN/orig

53 karet z 61 položek

2

Cisco Advance Notification for Publication of August 19, 2026, Security Advisories

On August 19, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products: BroadWorks Crosswork Industrial Ethernet 1000 Series Switches Packaged Contact Center Enterprise and Unified Contact Center Enterprise RoomOS Secure Workload Unified Intelligence Center To fully remediate vulnerabilities to be disclosed on August 19, 2026, Cisco strongly…

Cisco US

Cisco PSIRT ·

Upozorňujeme na řetězec kritických zranitelností „wp2shell“ ve WordPress

Upozorňujeme na dvojici zranitelností ve WordPress Core označovaných jako wp2shell (CVE-2026-63030 a CVE-2026-60137), které mohou při kombinovaném zneužití vést ke vzdálenému spuštění kódu (RCE) bez nutnosti přihlášení.

KEV ✓ EPSS 0.96 CVSS 9.0 CVE-2026-60137 CVE-2026-63030 WordPress Cisco Microsoft Progress WORDPRESS CZ US AT FR 5 zdrojů

NÚKIB · Cisco Talos · Elastic Security · CERT.at · CERT-FR – alerty

7

ClamAV Vulnerabilities Affecting Cisco Products: August 2026

Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations. For more information about these vulnerabilities, see the Details section of this advisory. For additional information on these vulnerabilities in ClamAV, see the ClamAV blog. Cisco has released software updates that address these vulnerabilities in affected Cisco platforms. There are no workarounds that address these vulnerabilities. Notes: The…

EPSS 0.00 CVE-2026-20337 CVE-2026-20338 CVE-2026-20339 CVE-2026-20345 CVE-2026-20346 CVE-2026-20347 CVE-2026-20348 Cisco US

Cisco PSIRT ·

Curiouser and Curiouser

Welcome to this week’s edition of the Threat Source newsletter. “Experiment is the mother of knowledge.” ― Madeleine L'Engle, A Wrinkle in Time“Don't slide down the rabbit hole. The way down is a breeze, but climbing back's a battle.” ― Kate Morton, The Clockmaker's Daughter Hacker Summer Camp has come and gone, which means it’s time for you to start planning next year’s trip. I’m surely going to recap Camp Season, right? Nope.One of the things that I’ve really enjoyed lately is a segment on…

Microsoft Cisco Signal Shopify finance obchod US

Cisco Talos ·

Dissecting the JWR phishing framework

Cisco Talos recently identified an undocumented phishing framework, internally branded "JWR" by its developer, built to convincingly impersonate checkout and login pages across major payment and shopping platforms. The client engine of the JWR phishing framework is a real-time, operator-driven system that, rather than merely logging form submissions like a static credential-stealing page, keeps an AES-CTR encrypted WebSocket open to the threat actor so they can steer each victim's session live.…

Cisco PayPal Apple Klarna US

Cisco Talos ·

ZDI-26-580: Cisco Identity Services Engine Missing Authentication for Critical Function Information Disclosure Vulnerability

The vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-20190.

EPSS 0.01 CVSS 7.5 CVE-2026-20190 Cisco telekomunikace US

Zero Day Initiative ·

1

2

Cisco Secure Firewall Management Center Software Static Credential Vulnerability

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the…

KEV ✓ EPSS 0.01 CVSS 9.8 CVE-2026-20316 Cisco US 3 zdrojů

Cisco PSIRT · Zero Day Initiative · CISA KEV

CISA Adds Three Known Exploited Vulnerabilities to Catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) Heap Inspection Vulnerability CVE-2026-68820 Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability CVE-2026-72898 Metabase SQL Injection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious…

KEV ✓ EPSS 0.10 CVE-2026-20349 CVE-2026-68820 CVE-2026-72898 Cisco Microsoft Metabase veřejná správa US

CISA Advisories ·

1

10th August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 10th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES North Carolina Ports, the US authority operating the ports of Wilmington, Morehead City and others, has suffered a cyberattack that forced some operations onto manual processes. The authority claims it has contained the intrusion, but degraded systems caused delays while affected services were restored. Ryde, an electric scooter operator in…

EPSS 0.01 CVSS 10.0 CVE-2026-12537 CVE-2026-54316 CVE-2026-64638 Cloudflare Google Anthropic Cisco finance obchod obrana IL

Check Point Research ·

1

Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficient access control enforcement for specific template types that are not included in the encryption allowlist. A low-privileged attacker could exploit this vulnerability by viewing logs on the local system or on a remote logging server. A successful exploit…

EPSS 0.00 CVE-2026-20294 Cisco US

Cisco PSIRT ·

1

Why metaphor may dictate your security strategy

Welcome to this week’s edition of the Threat Source newsletter. Metaphor is a powerful tool for understanding emerging issues in cybersecurity. Framing the unfamiliar in terms of the well understood helps us remove the burden of extraneous detail to draw focus to the real issues. Recent reports of offensive AI agents "escaping" their sandbox environments to attack external systems have forced the industry into a moment of rapid sense-making. How we interpret this event doesn’t just reflect our…

Cisco US

Cisco Talos ·

13

Cisco Advance Notification for Publication of August 5, 2026, Security Advisories

On August 5, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026 CVE-2026-20303CVE-2026-20304CVE-2026-20310CVE-2026-20312CVE-2026-20313 Critical 9.9 Cisco IOS XE Software Security Hardening Release: August 2026 CVE-2026-20267CVE-2026-20268CVE-2026-20269CVE-2026-20270CVE-2026-20271CVE-2026-20272CVE-2026-20273…

EPSS 0.00 CVE-2026-20028 CVE-2026-20124 CVE-2026-20198 CVE-2026-20263 CVE-2026-20289 CVE-2026-20294 CVE-2026-20301 CVE-2026-20311 Cisco US

Cisco PSIRT ·

Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerability

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the web-based management interface…

EPSS 0.00 CVE-2026-20308 Cisco US

Cisco PSIRT ·

Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these…

EPSS 0.00 CVE-2026-20303 CVE-2026-20304 CVE-2026-20310 CVE-2026-20312 CVE-2026-20313 Cisco US

Cisco PSIRT ·

Cisco Terminal Services Agent Firewall Rules Bypass Vulnerability

A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker to bypass firewall rules that are associated with the account of the attacker. This vulnerability is due to an incorrect mapping of network connections to user accounts. An attacker with at least user-level credentials could exploit this vulnerability by sending crafted network traffic to an affected device. A successful exploit could allow the attacker to inherit the…

EPSS 0.00 CVE-2026-20028 Cisco US

Cisco PSIRT ·

Cisco Integrated Management Controller Argument Injection Vulnerabilities

Multiple vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities…

EPSS 0.01 CVE-2026-20200 CVE-2026-20288 Cisco US

Cisco PSIRT ·

Cisco IOS XE Software Security Hardening Release: August 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues…

EPSS 0.00 CVE-2026-20267 CVE-2026-20268 CVE-2026-20269 CVE-2026-20270 CVE-2026-20271 CVE-2026-20272 CVE-2026-20273 Cisco US

Cisco PSIRT ·

Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerability

A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of malformed XMCP packets. An attacker could exploit this vulnerability by sending a malformed XMCP packet to an affected device. A successful exploit could allow the…

EPSS 0.00 CVE-2026-20301 Cisco US

Cisco PSIRT ·

Cisco IOS XE Software SNMP Denial of Service Vulnerability

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to improper error handling when parsing SNMP requests. This vulnerability affects all versions of SNMP — Versions 1, 2c, and 3. An attacker could exploit this vulnerability by sending a malformed SNMP request to an affected device. A…

EPSS 0.00 CVE-2026-20124 Cisco US

Cisco PSIRT ·

Cisco IOS XE Software Blocks Extensible Exchange Protocol Denial of Service Vulnerability

A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling when parsing a specific BEEP SOAP request. An attacker could exploit this vulnerability by sending a specific BEEP SOAP request to an affected device. A successful exploit could allow the attacker to cause the device to reload…

EPSS 0.00 CVE-2026-20263 Cisco US

Cisco PSIRT ·

Cisco RoomOS Logging Subsystem Information Disclosure Vulnerability

A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive information. This vulnerability is due to the logging of sensitive information. An attacker could exploit this vulnerability by enabling a specific logging level and then collecting the system logs. A successful exploit could allow the attacker to view sensitive information like user login credentials. Cisco has released software updates that address this…

EPSS 0.00 CVE-2026-20289 Cisco US

Cisco PSIRT ·

Cisco Integrated Management Controller Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the…

EPSS 0.00 CVE-2026-20198 Cisco US

Cisco PSIRT ·

Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerability

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient error handling in the web-based management interface. An attacker could exploit this vulnerability by authenticating with a malformed certificate. A successful exploit could allow the attacker to cause the affected device to reload, resulting…

EPSS 0.00 CVE-2026-20311 Cisco US

Cisco PSIRT ·

Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the…

EPSS 0.38 CVE-2026-20079 Cisco veřejná správa US

Cisco PSIRT ·

2

[Webinar] Tales from the Frontlines: An exclusive briefing on Q2 incidents

Have you ever read the Talos IR Quarterly Trends report and wondered, “How did that phishing or ransomware campaign actually play out? When was Talos IR contacted, how did they contain it, and how did they remediate the environment?" You’re in luck. Next Tuesday, August 11, Cisco Talos Incident Responders will be hosting an exclusive, unrecorded 30-minute webinar to review the most high-impact incidents our customers faced in Q2 2026. This isn’t a rehashing of the report itself, but a candid…

Cisco US

Cisco Talos ·

3rd August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 27th July, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Minnesota IT Services has confirmed coordinated cyberattacks affecting more than 30 community water utilities across the state. The incidents briefly disrupted a treatment plant in Braham and affected industrial control systems. Officials reported that drinking water safety was not affected. While the attack was not officially attributed, federal…

KEV ✓ EPSS 0.70 CVSS 9.8 CVE-2026-20316 CVE-2026-42897 CVE-2026-59309 CVE-2026-59310 CVE-2026-59726 CVE-2026-63077 CVE-2026-66066 Check Point Cisco Broadcom Microsoft vodárenství finance zdravotnictví telekomunikace IL

Check Point Research ·

2

You were onto something with “It’s the Climb,” Miley

Welcome to this week’s edition of the Threat Source newsletter. For my fianceé’s 30th birthday, I took her on a weekend trip to Shenandoah National Park – a favorite of ours since we went to a wedding there several years back. We’ve done several incredible hikes over the years, but one in particular had always loomed over my head: Old Rag, a 9.3 mile circuit hike that’s largely considered the most difficult in Virginia. I've always been warned that at the beginning and end, you hate Old Rag.…

Cisco Microsoft Check Point Zoho zdravotnictví veřejná správa vodárenství US

Cisco Talos ·

Black Hat special: Rewind and revisit

Cybersecurity is rarely a straight line. In this special Black Hat edition of Humans of Talos, Amy looks back at the incredible journeys that brought past guests to the world of threat intelligence. From forensic labs and newsrooms to the kitchen line, we’re revisiting the stories and lessons that define the people behind the threat intelligence.Heading to Black Hat? We have a presence within the Cisco and Splunk booth (2633) during Black Hat where you can chat to us about our latest threat…

Cisco US

Cisco Talos ·

2

Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel

Cisco Talos has discovered a new Rust-based remote access trojan (RAT) we call “msaRAT” attributed to the Chaos ransomware group. The name is derived from the binding names found in the binary: “msaOpen,” “msaClose,” “msaError,” and “msaMessage”.msaRAT is implemented using the Tokio asynchronous runtime, with primary capabilities of browser-leveraged remote code execution and covert tunneling to establish command-and-control (C2) communications.This RAT never touches the network directly — it…

Cisco Cloudflare Twilio US

Cisco Talos ·

Preview: Cisco Talos at Black Hat USA 2026

We’re looking forward to having some great conversations with those of you heading to the desert for Hacker Summer Camp 2026. We have a presence within the Cisco and Splunk booth (2633) during Black Hat where you can chat to us about our latest threat research, incident response, and how Talos powers the Cisco portfolio with our intelligence.Or, feel free to pretend to want to talk to us about those things while grabbing a new multicolored Snorty. That’s fine, too.Here’s some of the ways we’ll…

Cisco Splunk US

Cisco Talos ·

1

Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerability

A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by uploading a crafted file to the…

KEV ✓ EPSS 0.92 CVE-2026-20127 CVE-2026-20182 CVE-2026-20245 Cisco telekomunikace energetika doprava finance obchod zdravotnictví US 2 zdrojů

Cisco PSIRT · Mandiant / Google TI

1

Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) guest portals could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit these vulnerabilities by injecting malicious code into specific pages of the interface. A…

EPSS 0.00 CVE-2025-20204 CVE-2025-20205 Cisco US

Cisco PSIRT ·

2

Begun, the Patch Wars have

Welcome to this week’s edition of the Threat Source newsletter. We all knew, to some degree or another, that this summer was going to a hot mess. I don’t mean FIFA drama or record setting heat waves. I mean the slow but steady momentum that AI frontier models were accruing for vulnerability research. If you were like me, and guesstimating exactly when that shoe would drop, my money was on the middle of summer. And... well, friends, I hate to say it, but I was right. This July’s Patch Tuesday is…

Microsoft Cisco US

Cisco Talos ·

UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign

Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025. Talos has discovered that the actor in this campaign delivers a Python-based remote access tool (RAT) that we track as “Starland RAT” and a command-and-control (C2) memory implant known as the “WLDR agent.” The WLDR agent is a sophisticated PowerShell-based C2 memory implant that…

Cisco finance US

Cisco Talos ·

2

Cisco Advance Notification for Publication of July 15, 2026, Security Advisories

On July 15, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco RoomOS Security Hardening Release: July 2026 CVE-2026-20150CVE-2026-20153CVE-2026-20156CVE-2026-20157CVE-2026-20158CVE-2026-20187 High 8.8 Cisco Identity Services Engine Path Traversal Vulnerability CVE-2026-20146 Medium 5.5 To fully remediate the vulnerabilities that were disclosed on July 15, 2026, Cisco…

EPSS 0.00 CVSS 5.5 CVE-2026-20146 Cisco US 2 zdrojů

Cisco PSIRT · Zero Day Initiative

Cisco RoomOS Security Hardening Release: July 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues by…

EPSS 0.00 CVE-2026-20150 CVE-2026-20153 CVE-2026-20156 CVE-2026-20157 CVE-2026-20158 CVE-2026-20187 Cisco US

Cisco PSIRT ·

2

Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to achieve remote code execution or conduct information disclosure attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at…

EPSS 0.01 CVE-2026-20181 CVE-2026-20190 Cisco US

Cisco PSIRT ·

Cisco Catalyst Center Arbitrary File Read Vulnerability

A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to read arbitrary files from a restricted container of the affected device. Cisco has released software updates that address this…

EPSS 0.01 CVE-2026-20191 Cisco US

Cisco PSIRT ·

1

ClamAV Vulnerabilities Affecting Cisco Products: July 2026

Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations. For more information about these vulnerabilities, see the Details section of this advisory. For additional information on these vulnerabilities in ClamAV, see the ClamAV blog. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. Notes: The Security Impact Rating (SIR) for…

EPSS 0.01 CVE-2026-20213 CVE-2026-20214 CVE-2026-20215 CVE-2026-20216 CVE-2026-20217 CVE-2026-20243 CVE-2026-20244 Cisco US

Cisco PSIRT ·

1

Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could…

KEV ✓ EPSS 0.83 CVE-2026-20230 Cisco US

Cisco PSIRT ·

1

Cisco Finesse Remote File Inclusion Vulnerability

A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote locations into an active user session on an affected device, possibly leading to browser-based attacks. This vulnerability is due to insufficient validation of user-supplied input for HTTP requests that are sent to an affected device. An attacker who has knowledge of the address of the affected device could exploit this vulnerability by persuading a user to click a crafted link…

EPSS 0.00 CVE-2026-20175 Cisco US

Cisco PSIRT ·

1

Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Cross-Site Scripting Vulnerabilities

Multiple vulnerabilities in the web-based management interface of Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. These vulnerabilities exist because the web-based management interface does not properly validate user-supplied input. An attacker could exploit these…

EPSS 0.00 CVE-2026-20055 CVE-2026-20109 Cisco US

Cisco PSIRT ·

3

Cisco Webex App Open Redirect Vulnerability

A vulnerability in the browser-based version of Cisco Webex App could have allowed an unauthenticated, remote attacker to redirect users to a malicious webpage. Cisco has addressed this vulnerability in the Cisco Webex App, and no customer action is needed. This vulnerability existed due to improper input validation of URL parameters in an HTTP request. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by persuading a user to click a crafted URL. A…

EPSS 0.00 CVE-2026-20178 Cisco US

Cisco PSIRT ·

Cisco Crosswork Network Controller Server-Side Template Injection Vulnerability

A vulnerability in the web-based management interface of Cisco Crosswork Network Controller could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vulnerability is due to insufficient input validation in the configuration template engine of the web-based management interface. An attacker could exploit this vulnerability by sending a crafted request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands…

EPSS 0.00 CVE-2026-20220 Cisco US

Cisco PSIRT ·

Cisco Umbrella Virtual Appliance Privilege Escalation Vulnerability

A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of user-supplied commands. An attacker with vmadmin privileges could exploit this vulnerability by using certain commands at the CLI. A successful exploit could allow the attacker to elevate privileges to root. Cisco has released software updates that address this vulnerability. There…

EPSS 0.00 CVE-2026-20246 Cisco US

Cisco PSIRT ·

3

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit…

KEV ✓ EPSS 0.88 CVE-2026-20127 Cisco US EU FR 3 zdrojů

Cisco PSIRT · CERT-EU · CERT-FR – alerty

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The Indicators of Compromise section of this advisory includes Show Control Connections guidance to help with system checks. A vulnerability in the peering authentication in Cisco…

KEV ✓ EPSS 0.92 CVE-2026-20182 Cisco US

Cisco PSIRT ·

Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists because the affected software does not properly validate user-supplied input during a file upload process. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected API endpoint of the affected system. A successful exploit…

KEV ✓ EPSS 0.28 CVE-2026-20262 Cisco US

Cisco PSIRT ·

1

VAROVANIE – Aktívne zneužívaná kritická zero-day zraniteľnosť v CISCO CATALYST SD-WAN.

Národné centrum kybernetickej bezpečnosti SK-CERT varuje pred bezprostrednou hrozbou kybernetických bezpečnostných útokov na produkty CISCO CATALYST SD-WAN. V týchto produktoch boli identifikované kritické zero-day zraniteľnosti. Keďže disponujeme informáciami, že zraniteľnosti v týchto produktoch sú aktuálne zneužívané na kompromitáciu systémov vo svete, vydávame varovanie podľa §27 ods. 1 písm. a) zákona č. 69/2018 Z.z. o kybernetickej bezpečnosti.... The post VAROVANIE – Aktívne zneužívaná…

Cisco SK

SK-CERT (NBÚ SR) ·