Cisco security advisory (AV26-921)
Canadian Cyber Centre warns actively exploited Cisco Secure Email Gateway SQL injection CVE-2026-76461 was added to CISA's KEV database.
The Canadian Centre for Cyber Security advisory AV26-921 (September 14, 2026) covers a SQL injection vulnerability in Cisco Secure Email Gateway (AsyncOS) and Secure Email and Web Manager. Affected versions include AsyncOS/Secure Email Gateway prior to 15.5.5-014, 16.0.4-302, and 16.5.0-780, and Secure Email and Web Manager prior to 15.5.5-006 and 16.5.0-429. Cisco stated CVE-2026-76461 is being actively exploited, and CISA added it to the Known Exploited Vulnerabilities database the same day. Users and administrators are urged to apply updates as they become available.
Cisco security advisory (AV26-876)
Canada's Cyber Centre relayed Cisco advisories covering a Nexus 9000 Silicon One RCE, IOS XR hardening, and denial-of-service flaws across IP phone lines.
The Canadian Centre for Cyber Security advisory AV26-876 lists Cisco vulnerabilities affecting IOS XR, Nexus 9000 Series switches, and several IP phone series. Included are a Nexus 9000 Silicon One remote code execution vulnerability, a September 2026 IOS XR security hardening release, and SIP software denial-of-service flaws in Desk Phone 9800, IP Phone 7800/8800, and Video Phone 8875. The Cyber Centre urges users and administrators to review the Cisco advisories and apply updates as they become available. No active exploitation is reported in the advisory.
Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Server-Side Request Forgery Vulnerability
Cisco patched an authenticated SSRF flaw in Packaged CCE and Unified CCE that lets credentialed users send arbitrary network requests from affected devices.
A server-side request forgery vulnerability caused by improper input validation of specific HTTP requests affects Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise. An authenticated, remote attacker with valid user credentials can send crafted HTTP requests to make the device issue arbitrary network requests. Cisco has released software updates; no exploitation is reported in the advisory.
Cisco Advance Notification for Publication of August 19, 2026, Security Advisories
Cisco PSIRT's advance notice previews August 19, 2026 advisories including Critical CVSS 10.0 hardening releases for Crosswork and Secure Workload.
Cisco PSIRT issued an advance notification for security advisories published August 19, 2026. The batch includes Critical-rated (CVSS 10.0) hardening releases for Cisco Crosswork and Cisco Secure Workload, a High-severity blind XML External Entity injection in BroadWorks (CVE-2026-20320, CVSS 7.5), a Medium SQL injection in Unified Intelligence Center (CVE-2026-20327, CVSS 6.5), and a RoomOS stack overflow. Full details and fixes follow in the individual advisories.
Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026
Cisco's September 2026 firewall hardening release fixes internally found ASA, FTD, and FMC flaws, two of which are actively exploited.
Cisco released September 2026 hardening updates for Secure Firewall ASA, FTD, and FMC software addressing multiple vulnerabilities discovered during a comprehensive internal security review. Two of the vulnerabilities are known to be actively exploited, including a Cisco Secure Firewall Management Center static credential vulnerability. Details are provided in separate linked advisories.
Cisco Advance Notification for Publication of September 2, 2026, Security Advisories
Cisco PSIRT published September 2, 2026 advisories including critical IOS XR hardening fixes and a Nexus 9000 remote code execution flaw.
Cisco's PSIRT released its September 2, 2026 batch of security advisories, including a Cisco IOS XR Software security hardening release bundling six CVEs (CVE-2026-20274 through CVE-2026-20280) rated critical with CVSS 9.8. A separate critical (CVSS 9.8) remote code execution vulnerability, CVE-2026-20212, affects Nexus 9000 Series switches with Silicon One, and a high-severity (CVSS 7.5) denial-of-service flaw, CVE-2026-20281, affects the Desk Phone 9800 Series and related SIP phones. Administrators should review the advisories and prioritize patching the critical-rated issues.
Cisco Identity Services Engine Hardening Release: September 2026
Cisco ISE hardening release fixes multiple internally discovered vulnerabilities, including an authentication bypass known to be actively exploited.
Cisco released September 2026 hardening updates for Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) following a comprehensive internal security review that uncovered multiple vulnerabilities. One of the flaws, an ISE authentication bypass, is known to be actively exploited. Cisco grouped the issues by underlying vulnerability to help customers prioritize patching and streamline disclosure.
Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026
Cisco's September 2026 hardening release for Secure Email Gateway and Secure Email and Web Manager patches internally found flaws, one actively exploited.
Cisco issued a security hardening release for Cisco Secure Email Gateway and Secure Email and Web Manager covering multiple internally discovered vulnerabilities, grouped by CWE class to streamline patching. Cisco states one of the vulnerabilities is known to be actively exploited. The exploited issue is the Cisco Secure Email Gateway SQL Injection Vulnerability detailed in a companion advisory. Software updates are available.
Cisco Nexus Dashboard Software Security Hardening Release: September 2026
Cisco released Nexus Dashboard hardening updates for multiple internally discovered vulnerabilities, grouped by CWE and not known to be exploited.
Cisco's Nexus Dashboard engineering team conducted an internal security review that found multiple vulnerabilities, addressed via software hardening releases. The issues were discovered during internal testing and are not known to be actively exploited. Cisco grouped the issues by CWE class and assigned a single CVE ID per issue before releasing fixes.
Cisco Integrated Management Controller Argument Injection Vulnerabilities
Cisco patched multiple argument-injection vulnerabilities in Cisco IMC's web management interface allowing authenticated attackers root command execution.
Cisco published an advisory covering multiple argument injection vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC). An authenticated, remote attacker could exploit them to execute arbitrary commands on the underlying operating system and elevate privileges to root. Cisco released software updates and states there are no workarounds; the advisory carries a High Security Impact Rating.
Cisco IOS XR Software Security Hardening Release: September 2026
Cisco released IOS XR security hardening fixes for multiple internally discovered vulnerabilities, grouped by CWE class, with no known active exploitation.
Cisco's IOS XR engineering team conducted a comprehensive internal security review and released hardening updates addressing multiple internally discovered vulnerabilities. The issues were found during internal testing and are not known to be actively exploited. Cisco grouped the vulnerabilities by CWE class and assigned a single CVE ID to each grouping to streamline patching and disclosure.
Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability
Cisco warns of a DoS flaw in SIP software on Desk Phone 9800 and IP Phone 7800/8800 series from improper HTTP packet memory handling.
Cisco disclosed a denial of service vulnerability affecting Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 devices running Cisco SIP Software. An unauthenticated remote attacker can send a continuous stream of crafted HTTP packets, causing sustained memory consumption until the device becomes unresponsive. A manual reboot is required to recover an affected device. No CVE identifier was listed in the advisory text.
Cisco Crosswork Security Hardening Release: August 2026
Cisco released an August 2026 Crosswork security hardening update addressing multiple internally discovered vulnerabilities, grouped by CWE class with one CVE per grouping.
Cisco's Crosswork engineering team completed a comprehensive internal security review and shipped a hardening release fixing multiple internally discovered vulnerabilities. The issues were found during internal testing, are grouped by CWE class, and each grouping received a single CVE ID. Cisco states these vulnerabilities are not known to be actively exploited.
Cisco Secure Workload Software Security Hardening Release: August 2026
Cisco shipped August 2026 hardening releases for Secure Workload fixing multiple internally discovered vulnerabilities that are not actively exploited.
Cisco's Secure Workload engineering team completed an internal security review that found multiple vulnerabilities during internal testing. The issues are grouped by CWE class with a single CVE assigned per grouping, and none are known to be actively exploited. Cisco has released hardening updates for customers to patch.
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Object Group Access Control List Bypass Vulnerabilities
Cisco patched ACL Object Group Search bypass flaws in ASA and FTD firewall software that let unauthenticated attackers reach protected networks.
Cisco disclosed multiple vulnerabilities in the ACL Object Group Search implementation of Secure Firewall ASA and FTD Software, caused by a logic error in populating group access control policies. An unauthenticated remote attacker could send traffic that should be blocked through the device, bypassing configured access controls. Cisco has released software updates; no exploitation is mentioned.
Cisco Advance Notification for Publication of September 16, 2026, Security Advisories
Cisco will publish security advisories with fixed software on September 16, 2026, covering BroadWorks, ISE, Nexus Dashboard, ASA, FMC, FTD and ThousandEyes.
Cisco PSIRT announced advance notification for security advisories to be published on September 16, 2026, along with fixed software releases. Affected products include BroadWorks CommPilot Application Software, Identity Services Engine (ISE), Nexus Dashboard, Secure Firewall ASA, Secure Firewall Management Center (FMC), Secure Firewall Threat Defense (FTD), and ThousandEyes Virtual Appliance. ISE, Nexus Dashboard and the Secure Firewall products receive security hardening releases, and the ASA, FMC and FTD advisories will be included in the same combined release.
Cisco BroadWorks Out-of-Band Blind XML External Entity Injection Vulnerability
Cisco patched an XXE flaw in BroadWorks' OCI XML parser letting unauthenticated remote attackers read sensitive files from the filesystem.
Cisco BroadWorks permits external entity resolution by default in its Open Client Interface XML parser, enabling out-of-band blind XXE injection. An unauthenticated remote attacker can send crafted XML to the OCI-P provisioning service and read sensitive configuration files with BroadWorks user privileges. Cisco has released software updates and no workarounds are available.
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability
Cisco patched an unauthenticated remote DoS in ASA and FTD Remote Access SSL VPN that reloads devices via crafted HTTP requests.
Cisco disclosed a denial-of-service vulnerability in the Remote Access SSL VPN service of Secure Firewall ASA and FTD software. Insufficient error checking when processing HTTP requests allows an unauthenticated, remote attacker to send a crafted HTTP request that causes the affected device to reload. Cisco has released software updates addressing the flaw.
Cisco ThousandEyes Virtual Appliance Authenticated Web Interface Command Injection Vulnerability
Cisco patched an authenticated command injection in ThousandEyes Virtual Appliance allowing arbitrary OS command execution with root privileges.
Improper validation of user-supplied input in the web-based management interface of Cisco ThousandEyes Virtual Appliance enables command injection. An authenticated remote attacker with valid administrative credentials can save configuration details containing malicious values to execute arbitrary operating system commands with root privileges. Cisco has released software updates that address the vulnerability.
Cisco BroadWorks CommPilot Application Software Authorization Bypass Vulnerability
Cisco patched a BroadWorks CommPilot authorization bypass letting low-privileged authenticated users alter device configurations via crafted HTTP requests.
A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software is caused by missing authorization checks. An authenticated remote attacker with low privileges can send crafted HTTP requests to alter configurations on select pages. Cisco has released software updates and no workarounds are available.
Cisco RoomOS Stack Overflow Vulnerability
Cisco fixed a stack overflow in the RoomOS USB driver allowing physical-access attackers to execute code with root privileges.
Insufficient boundary checks in the USB driver of Cisco RoomOS allow a buffer overflow when specific data is supplied through the USB port. An unauthenticated local attacker with physical access can connect a malicious USB device and execute arbitrary code with root privileges. Cisco has released software updates and no workarounds address the issue.
Cisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability
Cisco released a fix for a management-plane flooding DoS in IE-1000 switches that can make the device manager, SSH, or API inaccessible.
Insufficient protection against management plane flooding in Cisco Industrial Ethernet 1000 Series Switches allows an unauthenticated remote attacker to send high-rate ICMP, SSH, or HTTP traffic, raising CPU usage and causing a denial-of-service condition on the device manager web GUI, SSH, or API. Data traffic through the device is not affected. Cisco has released software updates to address the issue.
Cisco Unified Intelligence Center SQL Injection Vulnerability
Cisco patched a blind SQL injection in Unified Intelligence Center's web interface allowing authenticated local attackers to read the internal database.
Cisco disclosed a blind SQL injection vulnerability in the web-based management interface of Unified Intelligence Center, caused by insufficient validation of user-supplied input. An authenticated local attacker can send crafted requests and read the contents of the device's internal database. Exploitation requires valid user credentials, and Cisco has released software updates.
ClamAV Vulnerabilities Affecting Cisco Products: August 2026
Cisco patched ClamAV vulnerabilities that allow remote attackers to cause denial-of-service conditions, rated High only for Windows-based platforms.
Cisco released an advisory covering multiple ClamAV vulnerabilities that could let a remote attacker interrupt scanning operations with a denial of service. Software updates are available for affected Cisco platforms, and no workarounds exist. The Security Impact Rating is High for Windows-based platforms because ClamAV runs there in a privileged security context.
Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability
Cisco warns of a critical authentication bypass in Secure Firewall Management Center that lets unauthenticated attackers execute scripts and obtain root access.
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software allows an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. The flaw stems from an improper system process created at boot time and is triggered via crafted HTTP requests. If the FMC management interface does not have public internet access, the attack surface is limited.
Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability
Cisco disclosed a UEFI Secure Boot bypass in UCS servers and UCS-based appliances letting authenticated or physically present attackers execute unauthorized software.
Cisco published an advisory for a vulnerability in the UEFI Shell implementation of UCS servers and UCS-based appliances. Memory write commands remain available in the UEFI Shell while Secure Boot is enabled, allowing an attacker to modify UEFI memory and bypass validation checks to run unauthorized software. Exploitation requires either valid credentials for a user or admin account, or unauthenticated physical access to select the UEFI Shell boot option at boot time. The issue affects firmware boot integrity rather than the running operating system.