ZeroHour

Source: Cisco Security Advisories

33 items in the last 24h

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL VPN Denial of Service Vulnerability

Cisco expanded an SSL VPN denial-of-service advisory to cover all ASA and FTD software platforms; unauthenticated attackers can exhaust device memory.

A vulnerability in the VPN and management web servers of Cisco ASA Software and Cisco Secure FTD Software allows an unauthenticated remote attacker to exhaust system memory or buffer blocks, causing a denial of service. Originally scoped to the ASAv and FTDv virtual appliances, Cisco updated the advisory on September 16, 2026 to cover all ASA and FTD platforms.

Cisco Security Advisories · 18h agoAdvisory 9 sources

Cisco Secure Firewall Management Center Software Vulnerabilities

Cisco Secure Firewall Management Center vulnerabilities could let remote attackers gain root access and perform session forgery or impersonation.

Cisco disclosed multiple vulnerabilities in Secure Firewall Management Center (FMC) Software that could allow a remote attacker to gain root access and perform session forgery or session impersonation. Software updates have been released and no workarounds address the issues. The advisory is part of Cisco's September 2026 grouped release of firewall product advisories.

Cisco Security Advisories · 18h agoAdvisory 6 sources

Cisco Secure Firewall Management Center Software sftunnel Root Arbitrary Code Execution Vulnerability

Cisco patched an sftunnel flaw in Secure Firewall Management Center letting an authenticated remote attacker execute arbitrary commands as root.

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center allows an authenticated remote attacker to execute commands as root. The flaw stems from incorrect permissions allowing a registered sftunnel peer to write an arbitrary file anywhere on the device, exploitable via connection hijacking or crafted sftunnel commands. Cisco has released software updates.

Cisco Security Advisories · 18h agoAdvisory 6 sources

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Certificate Authentication Denial of Service Vulnerability

Cisco patched an ASA/FTD IKEv2 certificate authentication flaw letting unauthenticated remote attackers crash the IKEv2 process and reload devices with crafted certificates.

A logic error during the certificate authentication phase of IKEv2 connection setup in Cisco Secure Firewall ASA and FTD Software allows an unauthenticated, remote attacker to crash the IKEv2 process. Exploitation involves attempting to establish an IKEv2 VPN connection with a crafted certificate, causing a denial of service through an unexpected device reload. Cisco has released software updates.

Cisco Security Advisories · 18h agoAdvisory 9 sources

Cisco Identity Services Engine SQL Injection Vulnerabilities

Cisco released fixes for multiple SQL injection vulnerabilities in Identity Services Engine as part of its September 2026 advisory batch.

Multiple SQL injection vulnerabilities in Cisco Identity Services Engine (ISE) could allow a remote attacker to conduct SQL injection attacks against affected devices. Cisco has released software updates, and no workarounds address the flaws. The advisory is part of a group of advisories published in Cisco's September 2026 batch.

Cisco Security Advisoriesupdated · 15m agofirst · 18h agoAdvisory 19 sources

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Secure Firewall 3100 and 4200 Series DTLS Denial of Service Vulnerability

Cisco patched a DTLS flaw in ASA and FTD software for Secure Firewall 3100/4200 series letting unauthenticated attackers trigger device reloads.

Improper resource management when processing DTLS messages in Cisco ASA and Secure Firewall Threat Defense software for Secure Firewall 3100 and 4200 series devices allows an unauthenticated remote attacker to cause a denial of service. Exploitation via a crafted stream of DTLS traffic causes the device to reload. Cisco has released software updates.

Cisco Security Advisories · 18h agoAdvisory 9 sources

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Logging Denial of Service Vulnerability

Cisco patched an ASA/FTD rate-limiting flaw where TCP SYN floods trigger excessive syslog 419002 messages, causing high CPU and degraded performance.

A vulnerability in the system rate-limiting process for syslog message 419002 in Cisco Secure Firewall ASA and FTD Software allows an unauthenticated, remote attacker to cause high CPU utilization. The flaw results from improper rate limiting; an attacker can exploit it by sending a flood of TCP SYN packets, degrading device performance. Cisco has released software updates.

Cisco Security Advisories · 18h agoAdvisory 9 sources

Cisco Identity Services Engine Vulnerabilities

Cisco patched ISE and ISE-PIC flaws enabling REST API authentication bypass, remote code execution, SQL injection, and XXE attacks.

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to bypass authentication to the REST API, achieve remote code execution, perform SQL injection, and conduct XML External Entity injection attacks. Cisco has released software updates; no workarounds address these vulnerabilities.

Cisco Security Advisoriesupdated · 15m agofirst · 18h agoAdvisory 19 sources

Cisco Nexus Dashboard Software Security Hardening Release: September 2026

Cisco released Nexus Dashboard hardening updates for multiple internally discovered vulnerabilities, grouped by CWE and not known to be exploited.

Cisco's Nexus Dashboard engineering team conducted an internal security review that found multiple vulnerabilities, addressed via software hardening releases. The issues were discovered during internal testing and are not known to be actively exploited. Cisco grouped the issues by CWE class and assigned a single CVE ID per issue before releasing fixes.

Cisco Security Advisories · 18h agoAdvisory

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Object Group Access Control List Bypass Vulnerabilities

Cisco patched ACL Object Group Search bypass flaws in ASA and FTD firewall software that let unauthenticated attackers reach protected networks.

Cisco disclosed multiple vulnerabilities in the ACL Object Group Search implementation of Secure Firewall ASA and FTD Software, caused by a logic error in populating group access control policies. An unauthenticated remote attacker could send traffic that should be blocked through the device, bypassing configured access controls. Cisco has released software updates; no exploitation is mentioned.

Cisco Security Advisories · 18h agoAdvisory 9 sources

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software EIGRP Denial of Service Vulnerability

Cisco fixed an EIGRP flaw in Secure Firewall ASA/FTD software letting unauthenticated adjacent attackers trigger memory leaks and unexpected device reloads.

A vulnerability in the EIGRP implementation of Cisco Secure Firewall ASA and FTD Software stems from improper resource management when handling EIGRP update messages. An unauthenticated, adjacent attacker can send crafted EIGRP updates at a high rate to cause a memory leak that eventually reloads the device, creating a denial of service. Cisco has released software updates addressing the issue.

Cisco Security Advisories · 18h agoAdvisory 9 sources

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software TCP DNS Denial of Service Vulnerability

Cisco disclosed a TCP DNS flaw in ASA and FTD firewall software letting unauthenticated remote attackers trigger device reloads and denial of service.

A logic error in the DNS over TCP implementation of Cisco Secure Firewall ASA and FTD software mishandles buffer-size tracking when parsing DNS queries. An unauthenticated, remote attacker can send a crafted reply to a DNS query sent from the targeted device, causing the TCP DNS response handler to restart and the device to reload. The result is a denial of service condition on affected firewalls.

Cisco Security Advisories · 18h agoAdvisory 9 sources

Cisco Secure Firewall Threat Defense Software Snort 2 SSL/TLS Denial of Service Vulnerability

Cisco fixed an SSL certificate parsing flaw in FTD's Snort 2 engine letting unauthenticated remote attackers force detection engine restarts.

Incomplete validation of SSL certificates in the Snort 2 Detection Engine of Cisco Secure Firewall Threat Defense software allows an unauthenticated, remote attacker to send a crafted SSL connection setup request for parsing. A successful exploit restarts the Snort 2 Detection Engine unexpectedly, causing a denial of service. Cisco has released software updates, and no workarounds address the vulnerability.

Cisco Security Advisories · 18h agoAdvisory 9 sources

Cisco Identity Services Engine Authenticated Remote Code Execution and API Vulnerabilities

Cisco fixed ISE vulnerabilities enabling authenticated SQL injection and OS command execution; CVE-2026-20282 and CVE-2026-20283 rated High.

Multiple Cisco Identity Services Engine vulnerabilities allow an authenticated remote attacker to conduct SQL injection, modify data, or execute arbitrary commands on the underlying OS. Cisco assigned a Security Impact Rating of High to CVE-2026-20282 and CVE-2026-20283 because attackers can easily reach root from the achieved privilege level. Software updates are available and a workaround addresses one of the vulnerabilities.

Cisco Security Advisoriesupdated · 15m agofirst · 18h agoAdvisory 19 sourcesCVE-2026-20282CVE-2026-20283

Cisco Identity Services Engine Remote Code Execution Vulnerabilities

Cisco patched multiple authenticated remote code execution vulnerabilities in Identity Services Engine that require valid administrative credentials.

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) allow an authenticated remote attacker with valid administrative credentials to execute arbitrary commands on the underlying operating system. Cisco has released software updates; no workarounds address these vulnerabilities. The advisory is part of a batch of ISE releases.

Cisco Security Advisoriesupdated · 15m agofirst · 18h agoAdvisory 19 sources

Cisco Identity Services Engine Cross-Site Scripting Vulnerability

Cisco patched a reflected XSS in the ISE management interface allowing unauthenticated attackers to execute script via crafted links.

A reflected cross-site scripting vulnerability in the web-based management interface of Cisco Identity Services Engine lets an unauthenticated remote attacker execute arbitrary script in the context of the interface. Exploitation requires persuading a user to click a crafted link due to improper input validation. Cisco has released software updates.

Cisco Security Advisoriesupdated · 15m agofirst · 18h agoAdvisory 19 sources

Cisco Identity Services Engine Authorization Bypass Vulnerabilities

Cisco fixed authorization bypass flaws in ISE and ISE-PIC web management letting authenticated admins modify file descriptions via crafted HTTP requests.

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine and ISE Passive Identity Connector result from missing server-side validation of Administrator permissions. An authenticated remote attacker with valid Administrator credentials can submit crafted HTTP requests to modify descriptions of files on specific pages. Cisco has released software updates addressing the issues.

Cisco Security Advisoriesupdated · 15m agofirst · 18h agoAdvisory 19 sources

Cisco Identity Services Engine Authentication Bypass Vulnerability

Cisco patched an unauthenticated API authentication bypass in Identity Services Engine allowing attackers to access the web-based management interface.

A vulnerability in an API of Cisco Identity Services Engine (ISE) stems from insufficient authentication control on an API endpoint. An unauthenticated remote attacker can send a crafted request to bypass authentication and gain unauthorized access to the device via the web-based management interface. Cisco has released software updates and no workarounds are available.

Cisco Security Advisoriesupdated · 15m agofirst · 18h agoAdvisory 19 sources

Cisco Identity Services Engine Multiple Path Traversal Vulnerabilities

Cisco ISE and ISE-PIC contain multiple path traversal vulnerabilities allowing remote attacks; fixes released with no workarounds available.

Multiple path traversal vulnerabilities in Cisco Identity Services Engine (ISE) and the ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to conduct path traversal attacks on affected devices. Cisco has released software updates that address these vulnerabilities, and no workarounds are available. The advisory is part of a grouped set of September 2026 ISE advisories.

Cisco Security Advisoriesupdated · 15m agofirst · 18h agoAdvisory 19 sources

Cisco Identity Services Engine RADIUS Denial of Service Vulnerability

Cisco patched a RADIUS flaw in Identity Services Engine letting unauthenticated remote attackers trigger denial of service on ISE nodes.

A vulnerability in the RADIUS feature of Cisco Identity Services Engine allows an unauthenticated remote attacker to cause a denial of service by sending crafted RADIUS requests directly to an affected device. The flaw stems from improper handling of certain RADIUS requests and can render ISE nodes unavailable. In single-node deployments, endpoints that have not yet authenticated would be unable to access the network until the node recovers. Cisco has released software updates addressing the issue.

Cisco Security Advisoriesupdated · 15m agofirst · 18h agoAdvisory 19 sources

Cisco Identity Services Engine Authentication Bypass Vulnerabilities

Cisco fixed multiple authentication bypass flaws in Identity Services Engine and ISE-PIC enabling remote data access, manipulation, and certificate material disruption.

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and the ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to access or manipulate data, obtain sensitive information, or cause a reload of certificate and key material on affected devices. Cisco has released software updates, and no workarounds are available. The advisory is part of Cisco's September 2026 publication batch.

Cisco Security Advisoriesupdated · 15m agofirst · 18h agoAdvisory 19 sources

Cisco Identity Services Engine Information Disclosure Vulnerability

Cisco patched an ISE API flaw letting an authenticated administrator view sensitive data including hashed credentials via crafted API requests.

A vulnerability in the Cisco Identity Services Engine API allows an authenticated remote attacker with valid administrative credentials to view sensitive information, including hashed credentials usable in future attacks. The flaw is caused by insufficient validation of user-supplied API request parameters. Cisco has released software updates.

Cisco Security Advisoriesupdated · 15m agofirst · 18h agoAdvisory 19 sources

Cisco Identity Services Engine 802.1X Session Hijack and Information Disclosure Vulnerabilities

Cisco patched Identity Services Engine flaws letting unauthenticated local attackers bypass 802.1X authentication or disclose sensitive information.

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an unauthenticated local attacker to conduct an authentication bypass involving 802.1X session hijack or disclose sensitive information. Cisco has released software updates addressing these vulnerabilities. No workarounds are available. The advisory is part of a batch of Cisco releases.

Cisco Security Advisoriesupdated · 15m agofirst · 18h agoAdvisory 19 sources

Cisco Identity Services Engine SQL and HQL Injection Vulnerabilities

Cisco fixed multiple authenticated SQL and HQL injection flaws in Identity Services Engine and ISE-PIC APIs allowing arbitrary database queries and unauthorized data access.

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and ISE-PIC stem from insufficient validation of user-supplied input to affected APIs before it is used to build database queries. An authenticated, remote attacker can send crafted requests to execute arbitrary SQL or HQL queries against the underlying database, viewing or modifying data they are not authorized to access. Cisco has released software updates.

Cisco Security Advisoriesupdated · 15m agofirst · 18h agoAdvisory 19 sources

Cisco Identity Services Engine Hardening Release: September 2026

Cisco ISE hardening release fixes multiple internally discovered vulnerabilities, including an authentication bypass known to be actively exploited.

Cisco released September 2026 hardening updates for Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) following a comprehensive internal security review that uncovered multiple vulnerabilities. One of the flaws, an ISE authentication bypass, is known to be actively exploited. Cisco grouped the issues by underlying vulnerability to help customers prioritize patching and streamline disclosure.

Cisco Security Advisoriesupdated · 15m agofirst · 18h agoAdvisory in the wild 19 sources

Cisco Identity Services Engine Command Injection Vulnerabilities

Authenticated attackers with admin credentials could exploit Cisco ISE command injection flaws to execute arbitrary commands as root; fixes released.

Multiple command injection vulnerabilities in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) allow an authenticated, remote attacker with valid administrative credentials to execute arbitrary commands as the root user. Cisco has released software updates, and no workarounds are available. The advisory is part of a grouped set of September 2026 ISE advisories.

Cisco Security Advisoriesupdated · 15m agofirst · 18h agoAdvisory 19 sources

Cisco ThousandEyes Virtual Appliance Authenticated Web Interface Command Injection Vulnerability

Cisco patched an authenticated command injection in ThousandEyes Virtual Appliance allowing arbitrary OS command execution with root privileges.

Improper validation of user-supplied input in the web-based management interface of Cisco ThousandEyes Virtual Appliance enables command injection. An authenticated remote attacker with valid administrative credentials can save configuration details containing malicious values to execute arbitrary operating system commands with root privileges. Cisco has released software updates that address the vulnerability.

Cisco Security Advisories · 18h agoAdvisory

Cisco BroadWorks CommPilot Application Software Authorization Bypass Vulnerability

Cisco patched a BroadWorks CommPilot authorization bypass letting low-privileged authenticated users alter device configurations via crafted HTTP requests.

A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software is caused by missing authorization checks. An authenticated remote attacker with low privileges can send crafted HTTP requests to alter configurations on select pages. Cisco has released software updates and no workarounds are available.

Cisco Security Advisories · 18h agoAdvisory

Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Execution Vulnerability

Cisco fixed an unauthenticated Java deserialization RCE in FMC's External Database Access feature allowing root command execution via a TCP port.

Insecure deserialization of a user-supplied Java byte stream in Cisco Secure Firewall Management Center's External Database Access feature lets an unauthenticated remote attacker execute arbitrary commands and elevate to root. Exploitation requires sending a crafted serialized stream to a specific TCP port from a host configured in the external database access list. Cisco has released software updates.

Cisco Security Advisories · 18h agoAdvisory 6 sources

Cisco Secure Firewall Management Center and Secure Firewall Threat Defense Software sftunnel Vulnerabilities

Cisco fixed sftunnel flaws in Secure Firewall Management Center and Threat Defense allowing unauthenticated authentication bypass or denial of service.

Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) and Secure Firewall Threat Defense (FTD) software could allow an unauthenticated attacker to bypass sftunnel authentication or mount a sftunnel denial-of-service attack. Cisco has released software updates addressing these vulnerabilities. No workarounds are available. The advisory is part of a grouped Cisco release.

Cisco Security Advisories · 18h agoAdvisory 6 sources

Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026

Cisco's September 2026 firewall hardening release fixes internally found ASA, FTD, and FMC flaws, two of which are actively exploited.

Cisco released September 2026 hardening updates for Secure Firewall ASA, FTD, and FMC software addressing multiple vulnerabilities discovered during a comprehensive internal security review. Two of the vulnerabilities are known to be actively exploited, including a Cisco Secure Firewall Management Center static credential vulnerability. Details are provided in separate linked advisories.

Cisco Security Advisories · 18h agoAdvisory in the wild 6 sources

Cisco Secure Firewall Threat Defense Software TLS 1.3 Denial of Service Vulnerability

A TLS 1.3 buffer management flaw in Cisco Secure Firewall Threat Defense lets remote attackers crash the LINA process and reload devices.

A vulnerability in the TLS 1.3 implementation of Cisco Secure Firewall Threat Defense (FTD) software allows an unauthenticated remote attacker to cause a denial of service via crafted TLS 1.3 packets sent to a TLS 1.3-enabled listening socket. Improper buffer management causes the LINA process to crash, forcing a device reload that can occur before or after connection authentication. Cisco has released software updates to address the flaw.

Cisco Security Advisories · 18h agoAdvisory 9 sources

Cisco Secure Firewall Management Center Software Vulnerabilities

Cisco fixed multiple Secure Firewall Management Center flaws enabling remote attackers to gain root access, download files, inject SQL, or cause DoS.

Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) software could allow a remote attacker to gain root access, download sensitive files, perform SQL injection attacks, or cause a denial of service condition. Cisco released software updates addressing the issues. No workarounds are available, and the advisory is part of a grouped release of Cisco advisories.

Cisco Security Advisories · 18h agoAdvisory 6 sources