A stored input-validation flaw in Cisco ICM Enterprise’s web management interface lets an attacker run script in an administrator’s browser session if tricked into clicking a crafted link.
Every CISA KEV addition, plus critical-severity flaws in the kit that sits at the edge of a network: firewalls, VPN gateways, load balancers, routers, switches and management consoles.
Colour on the left of each entry is the CVSS severity. A pink CISA KEV badge means the flaw is being exploited right now — treat those first, whatever the score says. How each post is sourced and checked is set out in the methodology.
Cisco Webex Meetings Services HTTP Cache Poisoning Vulnerability
An unauthenticated attacker could poison cached HTTP responses in Cisco Webex Meetings’ cloud-based join service, causing some clients to receive incorrect responses when connecting to a meeting.
Cisco Webex Services Cross-Site Scripting Vulnerabilities
Three flaws in Cisco’s cloud-based Webex service let a crafted link inject scripting into a user’s session, with the fix applied server-side and no local patching needed.
Cisco ThousandEyes Endpoint Agent for Windows Arbitrary File Delete Vulnerabilities
A symbolic-link trick during agent upgrades lets a logged-in local user on Windows redirect the update process’s delete operation onto any protected file on the machine.
Cisco Unified Contact Center Express Editor Remote Code Execution Vulnerability
Opening a booby-trapped .aef script file in Cisco’s Unified CCX Editor can let an attacker run their own code on the machine, using whatever access the person who opened the file already has.
Cisco Unified Contact Center Express Vulnerabilities
Three separate flaws in the Cisco Unified CCX admin web interface let an already-authenticated administrator plant a stored XSS payload, deserialise a malicious Java object for code execution, or use path traversal plus SSH to run commands as root.
Cisco Integrated Management Controller Privilege Escalation Vulnerability
An authenticated attacker with SSH access to Cisco IMC on UCS B, C, S and X-Series servers can use crafted SSH syntax to reach internal services with elevated rights, up to creating new admin accounts.
Cisco Customer Collaboration Platform Information Disclosure Vulnerability
Cisco’s Customer Collaboration Platform chat interface fails to sanitise HTTP requests, letting an unauthenticated remote attacker craft requests that could redirect a user’s chat session to an attacker-controlled server.
Cisco Identity Services Engine on Cloud Platforms Static Credential Vulnerability
Cloud deployments of Cisco ISE on AWS, Azure and OCI ship with the same static credentials across every instance of a given release and platform, letting anyone who knows them reach the admin node without authenticating.
Cisco IOS XE Wireless Controller Software Arbitrary File Upload Vulnerability
Cisco Catalyst 9800 wireless controllers ship with a hard-coded authentication token in the AP file upload service, letting anyone reach the interface remotely without credentials and push files onto the controller.