Cisco confirmed active exploitation of CVE-2026-20079, a CVSS 10.0 authentication bypass enabling unauthenticated root command execution in Secure FMC; CISA added it to KEV.
Cisco confirmed in August 2026 that CVE-2026-20079 (CVSS 10.0), an unauthenticated authentication bypass in Secure Firewall Management Center, is being actively exploited, allowing remote attackers to execute scripts and commands as root via crafted HTTP requests to the web interface. CISA added the flaw to its Known Exploited Vulnerabilities catalog, ordering federal civilian agencies to patch by September 12, 2026. Shared IOCs, identical hot fixes, and a July 23 log entry suggest CVE-2026-20079 was used alongside the separately exploited static-credential flaw CVE-2026-20316 in the same attacks. Cisco released patches and cloud fixes, warns hot fixes do not remediate already-compromised devices, and says there are no workarounds.
Cisco will publish security advisories with fixed software on September 16, 2026, covering BroadWorks, ISE, Nexus Dashboard, ASA, FMC, FTD and ThousandEyes.
Cisco PSIRT announced advance notification for security advisories to be published on September 16, 2026, along with fixed software releases. Affected products include BroadWorks CommPilot Application Software, Identity Services Engine (ISE), Nexus Dashboard, Secure Firewall ASA, Secure Firewall Management Center (FMC), Secure Firewall Threat Defense (FTD), and ThousandEyes Virtual Appliance. ISE, Nexus Dashboard and the Secure Firewall products receive security hardening releases, and the ASA, FMC and FTD advisories will be included in the same combined release.
Cisco PSIRT published September 2, 2026 advisories including critical IOS XR hardening fixes and a Nexus 9000 remote code execution flaw.
Cisco's PSIRT released its September 2, 2026 batch of security advisories, including a Cisco IOS XR Software security hardening release bundling six CVEs (CVE-2026-20274 through CVE-2026-20280) rated critical with CVSS 9.8. A separate critical (CVSS 9.8) remote code execution vulnerability, CVE-2026-20212, affects Nexus 9000 Series switches with Silicon One, and a high-severity (CVSS 7.5) denial-of-service flaw, CVE-2026-20281, affects the Desk Phone 9800 Series and related SIP phones. Administrators should review the advisories and prioritize patching the critical-rated issues.
Cisco warns of seven ClamAV denial-of-service flaws in Secure Endpoint Connector, two with public PoCs; patches due in August.
Cisco warned that seven ClamAV denial-of-service vulnerabilities, tracked as CVE-2026-20337 through CVE-2026-20339 and CVE-2026-20345 through CVE-2026-20348, affect the Secure Endpoint Connector on Windows, macOS and Linux. Two flaws, CVE-2026-20337 (CVSS 7.5, out-of-bounds write) and CVE-2026-20338 (memory double-free), have public proof-of-concept code, but Cisco PSIRT reports no evidence of malicious exploitation. Fixes shipped in ClamAV 1.5.4, with Cisco patches due in August and no workaround available. Windows is rated high risk because ClamAV runs with elevated privileges there.
Hard-Coded Password Vulnerability in Cisco Secure Firewall Management Center
Cisco Secure Firewall Management Center (FMC), formerly Firepower Management Center, contains a use of hard-coded password vulnerability (CWE-259) that allows an unauthenticated, remote attacker to log in to an affected system. By authenticating with the built-in hard-coded credentials for a low-privileged account, the attacker can gain access to sensitive data within the impacted systems. Any organization running an affected Cisco FMC deployment is exposed, particularly where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-29, indicating active exploitation in the wild, and related reporting describes active exploitation of FMC vulnerabilities. No CVSS score or public proof-of-concept is yet available, but EPSS assigns a 9.8% probability of exploitation within 30 days (95th percentile).
· Cisco Secure Firewall Management Center (FMC) KEV ransomwarelarge
Unauthenticated RCE in Cisco Nexus 9000 Switches with Silicon One Integration
CVE-2026-20212 (CVSS 9.8, CWE-1327) is a critical flaw in the Silicon One integration for Cisco Nexus 9000 Series Switches: TCP ports 43210 and 43211 are exposed in the default Layer 3 VRF, allowing an unauthenticated remote attacker with network reachability to those ports to send crafted input that is executed as code with root privileges. Exploitation can also crash the S1HAL process, forcing the device to reload. Affected devices are Nexus 9000 switches that use the Silicon One integration; other Nexus deployments are not implicated in this data. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known at this time, and EPSS estimates only about a 0.5% probability of exploitation within 30 days.
· Cisco Nexus 9000 Series Switches with Silicon One integrationlarge
Critical Improper Resource Control Flaws in Cisco IOS XR Software
CVE-2026-20274 covers a set of internally discovered improper resource control weaknesses (CWE-664) in Cisco IOS XR Software, found during a comprehensive internal security review by Cisco's IOS XR engineering team and addressed in a bundled software hardening release. The CVSS 3.1 vector (9.8, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) indicates the issues are triggerable over the network by an unauthenticated attacker with no user interaction, though the disclosure does not describe the exact trigger path. Successful exploitation carries high confidentiality, integrity, and availability impact, which is consistent with serious compromise of the affected device; separately reported coverage of the same coordinated patch batch describes an unauthenticated root RCE in Cisco Nexus 9000 (NX-OS), suggesting a related but distinct advisory. Any deployment of Cisco IOS XR Software is potentially affected — IOS XR powers Cisco's carrier-grade service provider routing platforms — and the source data does not list specific affected or fixed version ranges. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS estimates roughly a 0.7% probability of exploitation within 30 days.
Critical Improper Access Control in Cisco IOS XR Software
CVE-2026-20279 covers one or more improper access control flaws (CWE-284) in Cisco IOS XR Software, discovered by Cisco's own engineering team during an internal security review and addressed in a bundled software hardening release. According to the CVSS vector (AV:N/AC:L/PR:N/UI:N), the flaws are remotely exploitable over the network with no authentication and no user interaction, and the 9.8 critical score reflects high impact to confidentiality, integrity, and availability, though the specific attack path is not detailed in the available data. A successful unauthenticated remote attacker would gain high-impact access to the affected device per the CVSS scoring, on networks running IOS XR, which is deployed primarily on Cisco's service-provider routing platforms. The fix was rolled into Cisco's coordinated September 2, 2026 advisory bundle, in which the IOS XR team consolidated patches for multiple internally discovered issues into a single update release, published alongside other Cisco fixes (including a separate critical Nexus 9000 issue). No public proof-of-concept, CISA KEV listing, or in-the-wild exploitation is currently known; EPSS estimates the 30-day exploitation probability at roughly 0.3%.
Incorrect Calculation Vulnerabilities in Cisco IOS XR Software
CVE-2026-20275 tracks multiple internally discovered incorrect-calculation issues (CWE-682) in Cisco IOS XR Software, found during Cisco's internal security review and addressed through dedicated software hardening releases. According to the CVSS 3.1 vector (AV:A/AC:L/PR:N/UI:N), an unauthenticated attacker positioned on an adjacent network segment could trigger the flaw with no user interaction or privileges required. Successful exploitation carries high-impact consequences for confidentiality, integrity, and availability (CVSS 8.8, High), though the advisory summary does not detail the precise mechanism or the exact attacker gain. Any deployment running Cisco IOS XR Software is potentially affected; defenders should consult Cisco's September 2, 2026 advisory publication for exact affected releases and fixed versions, which are not specified in the available data. No public proof-of-concept, KEV listing, or known in-the-wild exploitation exists, and EPSS assigns only a 0.2% probability of exploitation within 30 days.
Unauthenticated Remote DoS Flaws in Cisco IOS XR Software
CVE-2026-20276 covers a set of internally discovered vulnerabilities in Cisco IOS XR Software caused by insufficient control flow management (CWE-691), which Cisco addressed through software hardening releases following a comprehensive internal security review. The flaws are exploitable over the network by unauthenticated attackers with no user interaction or privileges required, per the CVSS vector (AV:N/AC:L/PR:N/UI:N). With no confidentiality or integrity impact but a high availability impact and changed scope, successful exploitation most likely causes a denial-of-service condition such as a device crash or process restart. Any organization running Cisco IOS XR — typically service providers and large enterprises operating carrier-grade routing infrastructure — is potentially affected, although the available data does not specify affected or fixed versions. There is no known exploitation in the wild, no public proof-of-concept, and EPSS assigns only a 0.3% 30-day exploitation probability, making this a schedule-patch rather than an emergency.
Unauthenticated Memory-Leak DoS in Cisco SIP Software for IP and Desk Phones
CVE-2026-20281 is a memory-management flaw (CWE-401) in the Cisco Session Initiation Protocol (SIP) Software running on the Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875, where HTTP packets are not properly released from memory. An unauthenticated, remote attacker can trigger it by sending a continuous stream of crafted HTTP packets to an affected phone, causing the device to consume memory without freeing it. A successful attack results in a denial-of-service condition on the handset that persists until an administrator manually reboots the device, with no confidentiality or integrity impact. Only phones registered to Cisco Unified Communications Manager (Unified CM) with Web Access enabled are exploitable, and Web Access is disabled by default, so a large share of deployments is likely unaffected. There is currently no evidence of exploitation, no public proof-of-concept, the flaw is not in the CISA KEV catalog, and EPSS estimates roughly a 0.3% chance of exploitation within 30 days.
· Cisco Desk Phone 9800 Series running Cisco SIP Software · Cisco IP Phone 7800 Series running Cisco SIP Softwaremass
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device.
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate as a result of a memory double-free, resulting in a DoS condition on the affected software.
A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impa
A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in XAR files during scanning. An attacker could exploit this vulnerability by submitting a crafted file that contains XAR content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the…
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device.
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an out-of-bounds write condition. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.