An unauthenticated attacker can bypass login on Cisco ISE and ISE-PIC’s web management interface and gain access to the device outright, with no patch yet available.
Posts tagged: Cisco
Cisco Secure Email Gateway SQL Injection Vulnerability
An unauthenticated attacker can send a single crafted email to a Cisco Secure Email Gateway and gain root control of the appliance through a SQL injection flaw in its message-parsing logic.
Cisco IOS XR Software Security Hardening Release: September 2026
A single Cisco advisory bundles seven internally-found IOS XR flaws by weakness class, two of them unauthenticated and remotely exploitable for full device compromise, with fixes spread across dozens of per-train SMUs.
Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
An unauthenticated attacker can send crafted HTTP requests to Cisco Firewall Management Center’s web interface and gain root on the underlying host, no login needed.
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
An unauthenticated attacker can trigger a heap memory fault over the network on Cisco ASA and FTD firewalls, forcing an unplanned reload and knocking down the firewall’s availability.
Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026
Cisco’s internal security review of Catalyst SD-WAN Manager and Controller software uncovered five separate flaws, one rated 9.9, that a low-privileged network attacker could exploit without any user interaction.
Cisco IOS XE Software Security Hardening Release: August 2026
Cisco’s own engineers found seven flaws in IOS XE running in autonomous or controller mode, including a critical injection bug reachable over the network with no login needed, and there is no workaround short of upgrading.
Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability
An unauthenticated attacker who can reach the FMC web interface can exploit a flawed boot-time process to run scripts and gain root on the underlying operating system, no credentials needed.
Cisco Catalyst Center Virtual Appliance Privilege Escalation Vulnerability
An authenticated user with only Observer-level access to Cisco Catalyst Center’s virtual appliance can send a crafted HTTP request to gain full Administrator control.
Cisco Catalyst Center REST API Command Injection Vulnerability
An Observer-level account with API access to Cisco Catalyst Center can inject commands that run as root inside a restricted container, no admin privileges needed.