ZeroHour

Source: Cisco Security Advisories

6 stories in the last 24h

Cisco Identity Services Engine Hardening Release: September 2026

Cisco ISE hardening release fixes multiple internally discovered vulnerabilities, including an authentication bypass known to be actively exploited.

Cisco released September 2026 hardening updates for Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) following a comprehensive internal security review that uncovered multiple vulnerabilities. One of the flaws, an ISE authentication bypass, is known to be actively exploited. Cisco grouped the issues by underlying vulnerability to help customers prioritize patching and streamline disclosure.

Cisco Security Advisoriesupdated · 44m agofirst · 19h agoAdvisory in the wild 21 sources

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Object Group Access Control List Bypass Vulnerabilities

Cisco patched ACL Object Group Search bypass flaws in ASA and FTD firewall software that let unauthenticated attackers reach protected networks.

Cisco disclosed multiple vulnerabilities in the ACL Object Group Search implementation of Secure Firewall ASA and FTD Software, caused by a logic error in populating group access control policies. An unauthenticated remote attacker could send traffic that should be blocked through the device, bypassing configured access controls. Cisco has released software updates; no exploitation is mentioned.

Cisco Security Advisories · 19h agoAdvisory 9 sources

Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026

Cisco's September 2026 firewall hardening release fixes internally found ASA, FTD, and FMC flaws, two of which are actively exploited.

Cisco released September 2026 hardening updates for Secure Firewall ASA, FTD, and FMC software addressing multiple vulnerabilities discovered during a comprehensive internal security review. Two of the vulnerabilities are known to be actively exploited, including a Cisco Secure Firewall Management Center static credential vulnerability. Details are provided in separate linked advisories.

Cisco Security Advisories · 19h agoAdvisory in the wild 6 sources

Cisco ThousandEyes Virtual Appliance Authenticated Web Interface Command Injection Vulnerability

Cisco patched an authenticated command injection in ThousandEyes Virtual Appliance allowing arbitrary OS command execution with root privileges.

Improper validation of user-supplied input in the web-based management interface of Cisco ThousandEyes Virtual Appliance enables command injection. An authenticated remote attacker with valid administrative credentials can save configuration details containing malicious values to execute arbitrary operating system commands with root privileges. Cisco has released software updates that address the vulnerability.

Cisco Security Advisories · 19h agoAdvisory

Cisco BroadWorks CommPilot Application Software Authorization Bypass Vulnerability

Cisco patched a BroadWorks CommPilot authorization bypass letting low-privileged authenticated users alter device configurations via crafted HTTP requests.

A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software is caused by missing authorization checks. An authenticated remote attacker with low privileges can send crafted HTTP requests to alter configurations on select pages. Cisco has released software updates and no workarounds are available.

Cisco Security Advisories · 19h agoAdvisory

Cisco Nexus Dashboard Software Security Hardening Release: September 2026

Cisco released Nexus Dashboard hardening updates for multiple internally discovered vulnerabilities, grouped by CWE and not known to be exploited.

Cisco's Nexus Dashboard engineering team conducted an internal security review that found multiple vulnerabilities, addressed via software hardening releases. The issues were discovered during internal testing and are not known to be actively exploited. Cisco grouped the issues by CWE class and assigned a single CVE ID per issue before releasing fixes.

Cisco Security Advisories · 19h agoAdvisory