CVE-2026-68791 Azure Machine Learning Information Disclosure Vulnerability
Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-68791 US
Incorrect authorization in Azure Machine Learning allows an unauthorized attacker to disclose information over a network.
EPSS 0.01 CVE-2026-68791 US
Information published.
EPSS 0.00 CVE-2026-69399 US
Authentication bypass by spoofing in Microsoft Dataverse allows an unauthorized attacker to elevate privileges over a network.
EPSS 0.00 CVE-2026-77903 Microsoft US
Authorization bypass through user-controlled key in Microsoft Container Registry allows an unauthorized attacker to elevate privileges over a network.
EPSS 0.00 CVE-2026-69865 Microsoft US
Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Arc allows an unauthorized attacker to elevate privileges over a network.
EPSS 0.00 CVE-2026-70009 US
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network.
EPSS 0.00 CVE-2026-55946 Microsoft US
Apache Software Foundation ha rilasciato aggiornamenti di sicurezza per Apache NiFi e Apache NiFi Registry, piattaforme open source per la gestione, l'elaborazione e il versionamento dei flussi di dati, che sanano alcune vulnerabilità, di cui 2 con gravità "alta". Tali vulnerabilità potrebbero consentire a un attaccante di effettuare operazioni sui file al di fuori della directory prevista, manipolare dati, eludere misure di sicurezza e, tramite richieste HTTP opportunamente predisposte, comprom
EPSS 0.00 CVE-2026-70469 CVE-2026-87976 Apache IT
HP ha rilasciato aggiornamenti di sicurezza per risolvere diverse vulnerabilità, di cui 4 con gravità "critica" e 5 con gravità "alta", che interessano HP AC Print & Scan, HP Output Central e HP Linux Imaging and Printing Software (HPLIP), soluzioni software destinate alla gestione delle funzionalità di stampa e scansione.
EPSS 0.01 CVE-2026-89082 CVE-2026-89083 CVE-2026-89084 CVE-2026-91097 CVE-2026-91098 CVE-2026-91102 CVE-2026-91104 CVE-2026-91105 CVE-2026-91106 HP IT
Weak password recovery mechanism for forgotten password in MobiAPParc Thu, 09/17/2026 - 14:21 Aviso Affected Resources IOS MobiAPParc v0 – v2.28;Android MobiAPParc v0 – v2.42. Description INCIBE has coordinated the disclosure of a high-severity vulnerability affecting SMAP’s MobiAPParc, an app that enables users to pay for parking in regulated parking zones and in municipal car parks managed by Palma City Council. The vulnerability was discovered by Llorenç Romá.This vulnerability has been…
EPSS 0.00 CVSS 8.1 CVE-2026-14850 SMAP doprava ES
View CSAF Summary ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE‑2026‑31431 (Copy Fail) is a Linux kernel vulnerability that may allow a locally authenticated user or compromised container workload to gain elevated (root) privileges on affected systems. Once root access is obtained, the attacker can effectively gain complete…
KEV ✓ EPSS 1.00 CVSS 7.8 CVE-2026-31431 ABB Linux výroba a průmysl energetika vodárenství US EU AT HU
View CSAF Summary Schneider Electric is aware of vulnerabilities in its PowerChute Serial Shutdown product. The PowerChute Serial Shutdown product is a UPS management software enabling graceful system shutdown and energy management capabilities for desktops, servers and workstations. Failure to apply the remediation provided below may risk improper authentication validation which could result in disruption of operations and access to system data. The following versions of Schneider Electric…
EPSS 0.00 CVSS 5.3 CVE-2026-13348 Schneider Electric energetika výroba a průmysl US
View CSAF Summary Schneider Electric is aware of a vulnerability in its Modicon M340 https://www.se.com/ww/en/product-range/1468-modicon-m340-pac/, BMXNOR0200H https://www.se.com/us/en/product/BMXNOR0200H/communication-module-modicon-m340-iec-608705101-104-dnp3-for-severe-environments/: Modicon M340 X80 Ethernet Communication Modules, BMXNGD0100 https://www.se.com/us/en/product/BMXNGD0100/communication-module-modicon-m580-global-data-service/: M580 Global Data module, BMXNOC0401 https://www.se…
EPSS 0.00 CVSS 7.5 CVE-2025-6625 Schneider Electric energetika vodárenství výroba a průmysl US
View CSAF Summary Schneider Electric is aware of multiple vulnerabilities in its NetBotz 5 – 750/755 products.The NetBotz 5 – 750/755 products are security and environmental monitors providing temperature, humidity, leak, smoke, vibration, door contact, and video monitoring capabilities. Failure to apply the remediation provided below may risk arbitrary or remote code execution over the local network, which could result in device manipulation and unauthorized data access. The following versions…
EPSS 0.01 CVSS 6.4 CVE-2026-13336 CVE-2026-13337 Schneider Electric výroba a průmysl US
View CSAF Summary Successful exploitation of these vulnerabilities could allow unauthorized access to telemetry data and firmware. The following versions of Bransys ELD are affected: Android <11.00.00 (CVE-2026-86520, CVE-2026-86689, CVE-2026-77960) iOS <1.1.54 (CVE-2026-86520, CVE-2026-86689, CVE-2026-77960) CVSS Vendor Equipment Vulnerabilities v3 7.5 Bransys Bransys ELD Use of Hard-coded Credentials, Cleartext Transmission of Sensitive Information Background Critical Infrastructure Sectors:…
CVSS 7.5 CVE-2026-77960 CVE-2026-86520 CVE-2026-86689 Bransys doprava US
View CSAF Summary Hitachi Energy is aware of vulnerabilities that affect the FACTS Control systems with GWS component listed in this document. An attacker exploiting these vulnerabilities can cause impact on confidentiality, integrity and availability of the product. Following FACTS Control systems with GWS component deployed from year 2020 onwards are likely affected by the above vulnerabilities. Product deployments without GWS component are not affected. • SVC Light (STATCOM) • Fixed Series…
EPSS 0.01 CVSS 9.9 CVE-2024-3980 CVE-2024-3982 CVE-2024-4872 CVE-2024-7940 CVE-2024-7941 Hitachi Energy energetika US
View CSAF Summary Successful exploitation of this vulnerability could allow a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modify part of the executable module in memory, and thereby allows the attacker to view, tamper with, destroy, or delete control programs. The following versions of Mitsubishi Electric GX Works3 and Motion Control Settings are affected: Mitsubishi Electric GX Works3 vers:all/* (CVE-2026-15688)…
EPSS 0.00 CVSS 8.8 CVE-2026-15688 Mitsubishi Electric výroba a průmysl US
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly. The following versions of Mitsubishi Electric CC-Link IE TSN…
EPSS 0.00 CVE-2026-13584 Mitsubishi Electric výroba a průmysl US
Aggiornamenti di sicurezza Docker sanano due vulnerabilità, di cui una con gravità "critica" e una con gravità "alta", in Docker Sandboxes.
EPSS 0.00 CVE-2026-77179 CVE-2026-79994 Docker IT FR
Oracle heeft 19 kwetsbaarheden verholpen in Oracle VM VirtualBox. De kwetsbaarheden betreffen verschillende beveiligingsproblemen in Oracle VM VirtualBox, waaronder mogelijkheden voor lokale en geauthenticeerde kwaadwillenden om ongeautoriseerde acties uit te voeren. De kwetsbaarheden hebben CVSS-scores variërend van laag tot hoog. Van de in totaal 19 kwetsbaarheden kan volgens Oracle één kwetsbaarheid zonder authenticatie op afstand worden misbruikt. Succesvol misbruik kan onder meer leiden…
EPSS 0.00 CVE-2026-87273 CVE-2026-87277 Oracle NL
Rilasciati aggiornamenti di sicurezza per Craft CMS, sistema di gestione dei contenuti per la realizzazione e gestione di siti e applicazioni web, che sanano alcune vulnerabilità, di cui 4 con gravità "alta". Tali vulnerabilità potrebbero consentire a un attaccante di accedere a informazioni sensibili, eludere restrizioni di sicurezza, elevare i privilegi utente ed eseguire codice arbitrario sui sistemi interessati.
EPSS 0.01 CVE-2026-92591 CVE-2026-92592 CVE-2026-92593 CVE-2026-92594 Craft CMS IT
Cisco heeft 21 kwetsbaarheden verholpen in Cisco Identity Services Engine (ISE) en Cisco ISE Passive Identity Connector (ISE-PIC). De kwetsbaarheden betreffen verschillende beveiligingsproblemen in Cisco ISE en ISE-PIC, waaronder mogelijkheden voor niet-geauthenticeerde en laaggeprivilegieerde kwaadwillenden om via netwerktoegang ongeautoriseerde acties uit te voeren. De kwetsbaarheden hebben CVSS-scores variërend van middel tot kritiek. Van de in totaal 21 kwetsbaarheden zijn 13 als kritiek…
KEV ✓ EPSS 0.01 CVE-2026-20130 CVE-2026-20192 CVE-2026-76423 CVE-2026-76460 Cisco NL
Siemens ha rilasciato aggiornamenti di sicurezza per sanare una vulnerabilità presente in alcuni dispositivi di telelettura e contabilizzazione energetica della serie WTV.
EPSS 0.00 CVE-2026-89207 Siemens energetika IT
ISC ha rilasciato aggiornamenti di sicurezza per BIND 9 e BIND Supported Preview Edition, software per la gestione e la risoluzione delle richieste DNS, che sanano alcune vulnerabilità, di cui 7 con gravità "alta". Tali vulnerabilità possono causare la terminazione anomala di alcuni processi o un consumo eccessivo delle risorse, fino a compromettere la disponibilità del servizio sui sistemi interessati.
EPSS 0.00 CVE-2026-19666 CVE-2026-19667 CVE-2026-76163 CVE-2026-77692 CVE-2026-80274 CVE-2026-81563 CVE-2026-81736 ISC IT
Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. [...]
KEV ✓ EPSS 0.68 CVE-2025-20337 CVE-2026-20176 CVE-2026-20211 CVE-2026-20284 CVE-2026-20307 CVE-2026-76423 CVE-2026-76460 Cisco US
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung rlottie. Interaction with the rlottie library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91826.
EPSS 0.00 CVSS 7.8 CVE-2026-91826 Samsung US
Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: CVE-2026-92238, CVE-2026-92239, CVE-2026-92240, CVE-2026-92005, CVE-2026-92006, CVE-2026-92007, CVE-2026-92008, CVE-2026-92009, CVE-2026-92010, CVE-2026-92011, CVE-2026-92012, CVE-2026-92013, CVE-2026-92015, CVE-2026-92035, CVE-2026-92016, CVE-2026-92017, CVE-2026-92018, CVE-2026-92019, CVE-2026-92020, CVE-2026-92022 (+46 other associated CVEs), Summary: Security Vulnerabilities fixed in…
Mozilla FI
Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 8.8, CVEs: CVE-2026-92122, CVE-2026-92123, CVE-2026-92124, CVE-2026-92125, CVE-2026-92126, CVE-2026-92127, CVE-2026-92128, CVE-2026-92129, CVE-2026-92130, CVE-2026-92131, CVE-2026-92132, CVE-2026-92133, CVE-2026-92134, CVE-2026-92135, CVE-2026-92136, CVE-2026-92137, CVE-2026-92138, CVE-2026-92139, CVE-2026-92140, CVE-2026-92141, Summary: This advisory announces vulnerabilities in the following Jenkins…
CVSS 8.8 Jenkins FI
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.9, CVEs: CVE-2026-76669, CVE-2026-76670, CVE-2026-76672, CVE-2026-76673, CVE-2026-76674, CVE-2026-76675, CVE-2026-76676, CVE-2026-76677, CVE-2026-76678, CVE-2026-76679, CVE-2026-76680, CVE-2026-76681, CVE-2026-76682, CVE-2026-76683, CVE-2026-76684, CVE-2026-76685, CVE-2026-76686, CVE-2026-76687, CVE-2026-76688, CVE-2026-76689 (+19 other associated CVEs), Summary: HPE Networking has released updates for…
CVSS 9.9 HPE FI
Classification: Severe, Solution: Temporary Fix, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: , Summary: A vulnerability in MLflow’s dspy and statsmodels model flavors allows unauthorized pickle deserialization executions despite a safety control. Specifically, the dspy flavor conditionally applies the control based on the model path’s file extension, and the statsmodels flavor does not apply the control. Exploitation of this vulnerability allows for arbitrary remote code execution…
MLflow FI
Classification: Severe, Solution: Workaround, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: CVE-2026-90999, Summary: A vulnerability exists in Sentry Seer when the system is configured to automatically hand issues to a coding agent for remediation. Successful exploitation results in arbitrary code execution within the coding‑agent environment and access to connected source repositories. This vulnerability is tracked as CVE-2026-90999. Successful exploitation may allow arbitrary code…
EPSS 0.00 CVE-2026-90999 Sentry FI
Classification: Important, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: , Summary: The Drupal project uses the CKEditor library for WYSIWYG editing. CKEditor has released a security update that impacts Drupal. Vulnerabilities are possible if Drupal is configured to use CKEditor for WYSIWYG editing. An attacker that can create or edit content (even without access to CKEditor themselves) may be able to exploit this Cross-Site Scripting (XSS) vulnerability to target…
Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv4.0: 9.3, CVEs: CVE-2026-89026, Summary: The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. Attackers can use the forged token to call the manager originate endpoint with the System…
EPSS 0.01 CVSS 9.3 CVE-2026-89026 Issabel FI
Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: 10.0, CVEs: CVE-2026-20350, CVE-2026-20309, CVE-2026-20247, CVE-2026-20300, CVE-2026-20176, CVE-2026-20211, CVE-2026-20307, CVE-2026-76448, CVE-2026-76449, CVE-2026-76450, CVE-2026-76451, CVE-2026-76439, CVE-2026-76444, CVE-2026-76446, CVE-2026-76447, CVE-2026-20071, CVE-2026-20072, CVE-2026-76431, CVE-2026-76432, CVE-2026-76433 (+59 other associated CVEs), Summary: Advisories: Cisco ThousandEyes Virtual…
CVSS 10.0 Cisco FI
Classification: Severe, Solution: Official Fix, Exploit Maturity: High, CVSSv3.0: 7.8, CVEs: CVE-2026-87886, Summary: Exploitation of this vulnerability has been detected in the wild in limited, targeted attacks against Acronis Backup plugin for cPanel & WHM deployments. Affected products Acronis Backup plugin for cPanel & WHM (Linux) before build 1.9.3.1021 Acronis Backup extension for Plesk (Linux) before build 1.8.11.638
KEV ✓ EPSS 0.00 CVSS 7.8 CVE-2026-87886 Acronis cPanel Plesk WebHost Manager FI IT US
Classification: Critical, Solution: Official Fix, Exploit Maturity: High, CVSSv3.1: None, CVEs: CVE-2026-56914, CVE-2026-58773, CVE-2026-55318, CVE-2026-55343, CVE-2026-56920, CVE-2026-56967, CVE-2026-58683, CVE-2026-58710, CVE-2026-0179, CVE-2026-0187, CVE-2026-0192, CVE-2026-0194, CVE-2026-0199, CVE-2026-0200, CVE-2026-55302, CVE-2026-55317, CVE-2026-55323, CVE-2026-55329, CVE-2026-55337, CVE-2026-55357 (+90 other associated CVEs), Summary: The Pixel Update Bulletin contains details of…
Google FI
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 10.0, CVEs: CVE-2026-87273, CVE-2026-87268, CVE-2026-87269, CVE-2026-87270, CVE-2026-87271, CVE-2026-87272, CVE-2026-87275, CVE-2026-87279, CVE-2026-87267, CVE-2026-87274, CVE-2026-87280, CVE-2026-87281, CVE-2026-87282, CVE-2026-87283, CVE-2026-87284, CVE-2026-87285, CVE-2026-87289, CVE-2026-70755, CVE-2026-83354, CVE-2026-87276 (+785 other associated CVEs), Summary: This Critical Security Patch Update…
CVSS 10.0 Oracle FI
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: CVE-2026-91726, CVE-2026-91721, CVE-2026-91749, CVE-2026-91724, CVE-2026-91728, CVE-2026-91734, CVE-2026-91727, CVE-2026-91743, CVE-2026-91744, CVE-2026-91712, CVE-2026-91748, CVE-2026-91720, CVE-2026-91731, CVE-2026-91747, CVE-2026-91733, CVE-2026-91741, CVE-2026-91709, CVE-2026-91717, CVE-2026-91735, CVE-2026-91708 (+22 other associated CVEs), Summary: The Stable channel has been updated to…
FI
Une vulnérabilité a été découverte dans Nextcloud Server. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance.
Nextcloud FR
De multiples vulnérabilités ont été découvertes dans Drupal. Elles permettent à un attaquant de provoquer une injection de code indirecte à distance (XSS).
Drupal FR
Une vulnérabilité a été découverte dans KeyCloak. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.
EPSS 0.00 CVE-2026-90997 KeyCloak FR
Une vulnérabilité a été découverte dans NetApp ONTAP 9. Elle permet à un attaquant de provoquer un déni de service à distance, une atteinte à la confidentialité des données et une atteinte à l'intégrité des données.
EPSS 0.01 CVE-2026-42512 NetApp FR
De multiples vulnérabilités ont été découvertes dans ISC BIND. Elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à l'intégrité des données et un contournement de la politique de sécurité.
EPSS 0.00 CVE-2026-75029 CVE-2026-76163 CVE-2026-77119 CVE-2026-77692 CVE-2026-78301 CVE-2026-80274 CVE-2026-81563 CVE-2026-81736 ISC FR
Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. [...]
média US
Welcome back to our monthly look at Apple security patches. This release shows Apple is not immune to the new normal of AI-assisted vulnerability discovery as they release patches for 273 total CVEs.For the September 2026 release, Apple released 273 unique CVEs across macOS 27 (Golden Gate), macOS Sequoia 15.8, macOS Tahoe 26.7, iOS / iPadOS 27, visionOS 27, watchOS 27, tvOS 27, iOS / iPadOS 26.7, Safari 27, and Xcode 27. This patch release actually happened a couple of days ago, but since…
Apple US
Serial Number: AV26-931Date: September 16, 2026 As of September 16, 2026, ISC is affected by vulnerabilities in the following product: ISC BIND 9 Prior to or equal to 9.18.50 Prior to or equal to 9.18.50-S1 Prior to or equal to 9.20.27 Prior to or equal to 9.20.27-S1 Prior to or equal to 9.21.25 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. BIND 9 Software Vulnerability Matrix
ISC CA
Serial Number: AV26-930Date: September 16, 2026 As of September 14, 2026, Apple is affected by vulnerabilities in the following products: iOS and iPadOS Prior to 27 Prior to 26.7 macOS Golden Gate Prior to 27 macOS Tahoe Prior to 26.7 macOS Sequoia Prior to 15.8 tvOS Prior to 27 watchOS Prior to 27 visionOS 27 Prior to 27 Safari Prior to 27 Xcode Prior to 27 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become…
Apple CA
Serial number: AV26-929Date: September 16, 2026 As of September 15, 2026, Oracle Corporation is affected by vulnerabilities in the following products: Helidon Oracle Access Manager Oracle Agile Engineering Data Management Oracle Agile PLM Oracle Agile PLM MCAD Connector Oracle Application Testing Suite Oracle Autonomous Health Framework Oracle Banking Branch Oracle Banking Corporate Lending Oracle Banking Corporate Lending Process Management Oracle Banking Origination Oracle Banking Treasury…
Oracle CA
Serial number: AV26-928Date: September 16, 2026 As of September 15, 2026, Hewlett Packard Enterprise (HPE) is affected by vulnerabilities in the following products: HPE Networking EdgeConnect SD-WAN Gateways Multiple versions HPE Networking EdgeConnect SD-WAN Orchestrator Multiple versions The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. HPESBNW05135 rev.1 - Multiple Vulnerabilities in HPE Networking…
HPE CA
Serial number: AV26-927Date: September 16, 2026 As of September 16, 2026, Phoenix Contact is affected by vulnerabilities in the following products: ICE2-8IOL-G65L-V1D Prior to 1.7.4 ICE2-8IOL-K45P-RJ45 Prior to 1.7.4 ICE2-8IOL-K45S-RJ45 Prior to 1.7.4 ICE2-8IOL1-G65L-V1D Prior to 1.7.4 ICE3-8IOL-G65L-V1D Prior to 1.7.4 ICE3-8IOL-G65L-V1D-Y Prior to 1.7.4 ICE3-8IOL-K45P-RJ45 Prior to 1.7.4 ICE3-8IOL-K45S-RJ45 Prior to 1.7.4 ICE3-8IOL1-G65L-V1D Prior to 1.7.4 IOL MA8 EIP DI8 Prior to 1.7.4 IOL…
Serial number: AV26-926 Date: September 16, 2026 As of September 15, 2026, Google is affected by vulnerabilities in the following product: Chrome Prior to 153.0.8010.48 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. Stable Channel Update for Desktop
Google CA
Update for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv) models. However, it was later found that this vulnerability affects all Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software platforms. A vulnerability in the VPN and management web servers of the Cisco Secure Firewall ASA Software…
EPSS 0.01 CVE-2024-20260 Cisco US
A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands as root. This vulnerability exists because a registered sftunnel peer has incorrect permissions to write an arbitrary file to any location on the device. An attacker could exploit this vulnerability by hijacking the sftunnel communication connection or being a valid registered sftunnel peer and…
EPSS 0.00 CVE-2026-20324 Cisco US
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow a remote attacker to conduct SQL injection attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content…
EPSS 0.00 CVE-2026-20247 CVE-2026-20300 Cisco US
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct SQL or HQL injection attacks on an affected device. These vulnerabilities are due to insufficient validation of user-supplied input to the affected APIs before it is used to build database queries. An attacker could exploit these vulnerabilities by sending a crafted request to an affected device. A successful exploit could…
EPSS 0.00 CVE-2026-76448 CVE-2026-76449 CVE-2026-76450 CVE-2026-76451 Cisco US
A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2) for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly. This vulnerability is due to a logic error during the certificate authentication phase of the IKEv2 connection setup. An attacker could exploit this vulnerability by…
EPSS 0.00 CVE-2026-20249 Cisco US
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to access or manipulate data, obtain sensitive information, or cause a reload of certificate and key material on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these…
EPSS 0.00 CVE-2026-76439 CVE-2026-76444 CVE-2026-76446 CVE-2026-76447 Cisco US
A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to improper rate limiting for syslog message 419002. An attacker could exploit this vulnerability by sending a flood of…
EPSS 0.00 CVE-2026-20154 Cisco US
A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper resource management when handling EIGRP update messages. An attacker could exploit this vulnerability by sending crafted EIGRP updates at a high rate…
EPSS 0.00 CVE-2026-20222 Cisco US
A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker with low privileges to alter configurations on an affected device. This vulnerability is due to missing authorization checks. An attacker could exploit this vulnerability by sending a crafted HTTP request. A successful exploit could allow the attacker to alter configurations on select pages. Cisco has released software updates that address this…
EPSS 0.00 CVE-2026-76438 Cisco US
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by…
EPSS 0.00 CVE-2026-20322 CVE-2026-20325 CVE-2026-20326 CVE-2026-20360 CVE-2026-20361 CVE-2026-76409 Cisco US