ZeroHour

Search: “network-firewall”

17 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Object Group Access Control List Bypass Vulnerabilitiesnew

Cisco patched ACL Object Group Search bypass flaws in ASA and FTD firewall software that let unauthenticated attackers reach protected networks.

Cisco disclosed multiple vulnerabilities in the ACL Object Group Search implementation of Secure Firewall ASA and FTD Software, caused by a logic error in populating group access control policies. An unauthenticated remote attacker could send traffic that should be blocked through the device, bypassing configured access controls. Cisco has released software updates; no exploitation is mentioned.

Cisco Secure Firewall Management Center Software Vulnerabilitiesnew

Cisco fixed multiple Secure Firewall Management Center flaws enabling remote attackers to gain root access, download files, inject SQL, or cause DoS.

Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) software could allow a remote attacker to gain root access, download sensitive files, perform SQL injection attacks, or cause a denial of service condition. Cisco released software updates addressing the issues. No workarounds are available, and the advisory is part of a grouped release of Cisco advisories.

Cisco FMC CVE-2026-20079 Actively Exploited

Cisco confirms active exploitation of CVE-2026-20079, a maximum-severity authentication bypass in Secure Firewall Management Center.

Cisco has confirmed that CVE-2026-20079, a critical authentication bypass in Cisco Secure Firewall Management Center (FMC), is being actively exploited in the wild. The vulnerability carries a maximum CVSS severity, and defenders are urged to treat it as an urgent patch priority. FMC centrally manages Cisco Secure Firewall deployments, so exposure across enterprise environments is likely.

SOCRadarupdated · 2d agofirst · 6d agoExploit / PoC in the wild 11 sourcesCVE-2026-20079

Next

Palo Alto Networks product-category page describing Next-Generation Firewall threat detection, including encrypted traffic; no standalone article.

The page is a product category listing for Palo Alto Networks Next-Generation Firewalls, stating the products detect known and unknown threats, including in encrypted traffic, using intelligence from many thousands of customer deployments. It contains no research findings, vulnerabilities, or incident details relevant to defenders.

Palo Alto Unit 42 · 28d agoIndustry

AWS makes it easier to spot firewall rules that have gone quiet

AWS Network Firewall added rule hit counts for stateful rules, letting teams identify unused rules and validate control effectiveness at no added cost.

AWS Network Firewall's rule hit count capability gives security teams visibility into which stateful firewall rules are matching traffic, helping identify unused or redundant rules and validate controls for compliance frameworks like PCI DSS 4.0 and DORA. The feature covers stateful rules in custom and managed rule groups, is enabled by default at no additional Network Firewall cost, and is available in all supported Regions except UAE and Bahrain. Data is surfaced in the Network Firewall dashboard's Top Rule Hits view and can be queried via CloudWatch Logs Insights or Amazon Athena.

Help Net Security · 23d agoTools

Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability

Cisco warns of a critical authentication bypass in Secure Firewall Management Center that lets unauthenticated attackers execute scripts and obtain root access.

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software allows an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. The flaw stems from an improper system process created at boot time and is triggered via crafted HTTP requests. If the FMC management interface does not have public internet access, the attack surface is limited.

Cisco Secure Firewall Management Center Software Static Credential Vulnerability

Cisco warns of static low-privileged credentials in Secure Firewall Management Center's web interface, letting unauthenticated remote attackers log in and access sensitive data.

Cisco disclosed a vulnerability in the web interface of Secure Firewall Management Center (FMC) Software caused by the presence of static credentials for a low-privileged account. An unauthenticated remote attacker could log in to an affected device using the static account and access sensitive data within impacted systems. The attack surface is reduced when the FMC management interface does not have public internet access.

Cisco Security Advisories · Aug 11, 2026Advisory

Risky Bulletin: Academics find source code overlaps between Geedge and China's Great Firewall

Academics linked Chinese vendor Geedge Networks' Tiangou Secure Gateway source code to one of the Great Firewall's three traffic filtering capabilities.

US researchers presenting at USENIX Security reconstructed Geedge Networks' Tiangou Secure Gateway firmware from over 100,000 leaked files, including Git repositories with commit history, and matched its filtering behavior to sections of China's Great Firewall. They found only 1 of 3 characterized DNS injectors matched Geedge code, noted the system relies on memory-unsafe C components and copied third-party code, and said its bugs could aid future circumvention tools. Geedge also exports censorship tools to Kazakhstan, Ethiopia, Pakistan, and Myanmar. The newsletter additionally rounds up multiple breaches.

Risky Business News · 26d agoResearch2

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability

Cisco patched an unauthenticated remote DoS in ASA and FTD Remote Access SSL VPN that reloads devices via crafted HTTP requests.

Cisco disclosed a denial-of-service vulnerability in the Remote Access SSL VPN service of Secure Firewall ASA and FTD software. Insufficient error checking when processing HTTP requests allows an unauthenticated, remote attacker to send a crafted HTTP request that causes the affected device to reload. Cisco has released software updates addressing the flaw.

Cisco Security Advisories · Aug 11, 2026Advisory

Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)

Cisco patches CVE-2026-20349, a high-severity unauthenticated DoS in ASA and FTD VPN services now added to CISA's KEV.

CVE-2026-20349 affects the Remote Access SSL VPN service in Cisco Secure Firewall ASA and FTD software, where specially crafted unauthenticated HTTP requests can cause appliances to reload, creating a denial of service. Cisco confirmed active exploitation observed in August 2026 and released hot fixes for ASA versions 9.16 through 9.24 and FTD versions 7.0 through 10.0. The flaw was added to CISA's Known Exploited Vulnerabilities catalog with a remediation deadline of August 14, 2026 for US civilian federal agencies. No workarounds or indicators of compromise are available.

Help Net Security · Aug 13, 2026Exploit / PoC in the wildCVE-2026-20349

MacOS 27 - First Boot, (Tue, Sep 15th)

SANS ISC documents the expected network traffic macOS 27 'Golden Gate' generates on first boot to help defenders baseline their networks.

Johannes Ullrich of SANS Internet Storm Center captured roughly 300 packets from a macOS 27 'Golden Gate' system before user login, covering DHCP, IPv6 duplicate address discovery, DNS, and TCP behavior. macOS 27 resolves hostnames like albert.apple.com (device activation, certificate-pinned), push messaging hosts, and ipv4only.arpa for NAT64 networks. The OS still uses a TCP window scale of 6, ECN, and random timestamps, with only four TCP connections observed during boot. The analysis provides a reference baseline for security teams monitoring Apple endpoints.

SANS Internet Storm Center · 1d agoResearch

Best Practice Assessment Archives

Palo Alto Networks' Best Practice Assessment measures Next-Generation Firewall and Panorama configuration usage, enabling customers to strengthen security and maximize return on investment.

The Palo Alto Networks Best Practice Assessment measures usage of Next-Generation Firewall and Panorama security management capabilities across a customer deployment. The results are intended to guide configuration adjustments that strengthen security posture and maximize return on investment. The page is an archive listing for this product category rather than a new disclosure or release.

Palo Alto Unit 42 · Aug 17, 2026Industry

Advanced Dns Security

Palo Alto Networks Unit 42 hosts a product archive page for its Advanced DNS Security DNS-layer threat prevention service.

The page is a product category archive on the Unit 42 blog with no article text available. Advanced DNS Security is Palo Alto Networks' DNS-layer threat prevention offering. No research findings, incidents, or vulnerabilities are described.

Palo Alto Unit 42 · 8d agoIndustry 6 sources

SonicWall security advisory (AV26-853)

Canada's Cyber Centre relays a SonicWall advisory flagging vulnerabilities in NetExtender Linux Client 3.5 and earlier, urging administrators to apply updates as available.

The Canadian Centre for Cyber Security issued advisory AV26-853, noting SonicWall vulnerabilities affecting NetExtender Linux Client version 3.5 and earlier as of August 25, 2026. The relay provides no CVE identifiers or exploitation details and directs users and administrators to review SonicWall's security advisories and apply updates as they become available.

Canadian Centre for Cyber Security · 20d agoAdvisory

Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490)

Citrix patched a critical authentication bypass, CVE-2026-19490, in NetScaler Gateway and NetScaler ADC, urging customers to upgrade immediately.

Citrix has patched two flaws in NetScaler ADC and NetScaler Gateway. CVE-2026-19490 is a critical authentication bypass (CVSS v4.0 9.3) that works when the appliance is configured as an SSL VPN, ICA Proxy, CVPN, RDP Proxy Gateway or AAA virtual server, with additional conditions depending on firmware and SAML configuration. A second flaw, CVE-2026-19489 (CVSS 8.8), is a memory overflow that can cause denial of service when SIP ALG is enabled on LSN setups. Rapid7 had not observed exploitation as of August 19, 2026, but urged emergency patching; a signature-based mitigation is available via NetScaler Console.