A flaw in how Erlang/OTP’s SSH server handles authentication messages lets an unauthenticated remote attacker run code on affected Cisco products, with fixes staggered across trains through late 2025.
Every CISA KEV addition, plus critical-severity flaws in the kit that sits at the edge of a network: firewalls, VPN gateways, load balancers, routers, switches and management consoles.
Colour on the left of each entry is the CVSS severity. A pink CISA KEV badge means the flaw is being exploited right now — treat those first, whatever the score says. How each post is sourced and checked is set out in the methodology.
Cisco Meraki MX and Z Series AnyConnect VPN with Client Certificate Authentication Denial of Service Vulnerability
Unauthenticated attackers can crash the AnyConnect SSL VPN service on Meraki MX and Z Series gateways that use client certificate authentication, dropping every active remote-access session and blocking new ones.
ClamAV UDF File Parsing Out-of-Bounds Read Information Disclosure Vulnerability
A crafted UDF file sent to Cisco Secure Endpoint Connector’s bundled ClamAV can crash the scanning process, halting file scans on Linux, Mac and Windows endpoints until it restarts.
Cisco Identity Services Engine Authorization Bypass Vulnerability
An authenticated attacker who reaches Cisco ISE’s admin web interface via SAML SSO can bypass authorisation checks on some administrative functions, including settings that trigger a device restart.
Cisco Identity Services Stored Cross-Site Scripting Vulnerability
A stored XSS bug in Cisco ISE’s admin web interface lets an authenticated admin plant script that runs in another admin’s session, exposing session data with no workaround available.
Cisco Unified Communications Manager Static SSH Credentials Vulnerability
Certain Cisco Unified Communications Manager engineering-special builds ship with a hardcoded root SSH account that cannot be changed or removed, letting anyone reach it log straight in as root.
Cisco Enterprise Chat and Email Stored Cross-Site Scripting Vulnerability
A stored XSS bug in Cisco ECE’s web UI lets an agent-credentialed attacker plant script that runs in a colleague’s session when they click a crafted link, but only if a specific rich text security setting is left disabled.
Cisco Spaces Connector Privilege Escalation Vulnerability
A local flaw in Cisco Spaces Connector lets someone already logged in as spacesadmin run crafted CLI commands to gain full root control of the underlying operating system.
Cisco BroadWorks Application Delivery Platform Cross-Site Scripting Vulnerability
An admin with valid CommPilot credentials can plant script in the BroadWorks management interface that runs in another admin’s browser session when they view the affected page.
Cisco Unified Intelligence Center Server-Side Request Forgery Vulnerability
Cisco Unified Intelligence Center’s web management interface fails to validate certain HTTP requests properly, letting an unauthenticated remote attacker force the device to send arbitrary network requests on its behalf.