Topic: cisco vulnerability
-
Cisco warns of ASA, FTD VPN flaw used to crash devices
Cisco disclosed CVE-2026-20349, a high-severity (8.6) denial-of-service vulnerability in Secure Firewall ASA and FTD software, which is already being actively exploited remotely to crash devices via crafted HTTP requests to Remote Access SSL VPN services, requiring no authentication. The flaw ste...
Read More » -
Cisco confirms attackers exploiting Unified CM flaw
Cisco confirmed active exploitation of CVE-2024-20253, a Unified Communications Manager flaw with publicly available proof-of-concept exploit code, for which a patch was released in early June. The vulnerability allows unauthenticated attackers to trigger a remote denial-of-service condition, pot...
Read More » -
Cisco Unified CM vulnerability exploited to deploy webshells
Threat actors are actively exploiting an SSRF vulnerability (CVE-2026-20230) in Cisco Unified Communications Manager to deploy webshells and establish remote code execution capabilities. The flaw allows unauthenticated attackers to execute arbitrary commands and maintain persistent access for lat...
Read More » -
Cisco Patches Actively Exploited SD-WAN vManage Zero-Day Flaw
Cisco released emergency patches for a critical zero-day vulnerability (CVE-2026-20262) in Catalyst SD-WAN Manager, which is actively exploited in the wild to allow attackers with low-level privileges to escalate to root access. The flaw stems from insufficient input validation during file upload...
Read More » -
Critical Cisco Secure Workload flaw elevates users to Site Admin
Cisco patched CVE-2026-20223, a maximum-severity vulnerability in its Secure Workload platform that allows unauthenticated attackers to gain Site Admin privileges via crafted API requests. No workarounds exist; Cisco released software updates for on-premises customers and has already fixed the is...
Read More » -
Cisco FMC Flaw Exploited Before Patch (CVE-2026-20131)
The Interlock ransomware gang exploited a critical zero-day vulnerability (CVE-2026-20131) in Cisco's Secure Firewall Management Center for over a month before a patch was released, using it for arbitrary code execution and privilege escalation. Amazon's threat intelligence, using a honeypot, unc...
Read More » -
Cisco Patches Critical Zero-Day Flaw in AsyncOS (CVE-2025-20393)
Cisco has patched a critical zero-day vulnerability (CVE-2025-20393) in its Email Security and Web Manager appliances, which was actively exploited by suspected state-sponsored actors. The flaw allowed unauthenticated attackers to execute root-level commands via a flaw in the Spam Quarantine feat...
Read More » -
Cisco Customers Vulnerable to New Chinese Hacking Campaign
A Chinese state-sponsored hacking campaign is exploiting a critical zero-day vulnerability (CVE-2025-20393) in Cisco's Secure Email Gateway and Web Manager software, primarily targeting systems in India, Thailand, and the United States. The attack surface is limited to hundreds of systems, as exp...
Read More » -
Cisco Warns of Chinese Hackers Using New Zero-Day
Cisco warns of an active, state-sponsored hacking campaign exploiting a critical zero-day vulnerability in its security appliances, allowing complete device takeover with no patch currently available. The flaw targets specific Cisco AsyncOS products, but exploitation requires a non-default config...
Read More » -
Cisco Hackers Use SNMP Flaw to Install Rootkit on Switches
Cybersecurity experts warn of a serious threat exploiting a recently patched remote code execution vulnerability (CVE-2025-20352) in Cisco networking hardware, allowing attackers with root access to install persistent rootkits. The campaign, named 'Operation Zero Disco', targets Cisco switches li...
Read More » -
Cisco Zero-Day Exploited to Plant Rootkits on Network Switches
A critical vulnerability (CVE-2025-20352) in Cisco's network operating systems allowed attackers with administrative credentials to execute remote code and install persistent Linux rootkits on switches. Attackers implanted a rootkit that sets a universal password, uses memory hooks to hide filele...
Read More » -
Cisco Warns: Patch This Critical RCE & DoS Bug Now
A critical vulnerability (CVE-2025-20352) in Cisco's IOS and IOS XE Software allows remote attackers to execute arbitrary code or cause a denial-of-service if they have compromised credentials. The flaw exists in the SNMP subsystem and can be triggered by sending a crafted packet, with exploitati...
Read More » -
Millions of Cisco Devices Hit by Active 0-Day Attack
A critical vulnerability (CVE-2025-20352) affects approximately two million Cisco devices, allowing attackers to crash systems or execute malicious code with the highest privileges. The flaw is a stack overflow bug in the SNMP processing component and is being actively exploited, prompting Cisco ...
Read More » -
US Offers $10M Reward for Russian FSB Hackers Info
The U.S. State Department is offering up to $10 million for information on three Russian FSB officers accused of orchestrating cyberattacks against American critical infrastructure, including government bodies and energy firms. These officers, part of the FSB's Center 16, targeted over 500 energy...
Read More »