ALERTĂ: Vulnerabilitate exploatată activ la nivelul unor produse Cisco
CONTEXT La data de 16 septembrie 2026, Cisco a publicat informații privind o vulnerabilitate criti...
Cisco RO
CONTEXT La data de 16 septembrie 2026, Cisco a publicat informații privind o vulnerabilitate criti...
Cisco RO
Number: AL26-021Date: September 17, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Canadian…
KEV ✓ EPSS 0.01 CVE-2026-20192 CVE-2026-76423 CVE-2026-76460 Cisco CA
Serial number: AV26-932Date: September 17, 2026 As of September 16, 2026, Cisco is affected by vulnerabilities in the following products: Cisco Secure Firewall Threat Defense (FTD) Software Prior to 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 10.0.2 and 10.1.0 Cisco Secure Firewall Management Center (FMC) Software Prior to 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 10.0.2 and 10.1.0 Cisco Identity Services Engine (ISE) Software Prior to 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4…
KEV ✓ EPSS 0.01 CVE-2026-76460 Cisco CA SE HU IT FR US
Cisco heeft 21 kwetsbaarheden verholpen in Cisco Identity Services Engine (ISE) en Cisco ISE Passive Identity Connector (ISE-PIC). De kwetsbaarheden betreffen verschillende beveiligingsproblemen in Cisco ISE en ISE-PIC, waaronder mogelijkheden voor niet-geauthenticeerde en laaggeprivilegieerde kwaadwillenden om via netwerktoegang ongeautoriseerde acties uit te voeren. De kwetsbaarheden hebben CVSS-scores variërend van middel tot kritiek. Van de in totaal 21 kwetsbaarheden zijn 13 als kritiek…
KEV ✓ EPSS 0.01 CVE-2026-20130 CVE-2026-20192 CVE-2026-76423 CVE-2026-76460 Cisco NL
Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. [...]
KEV ✓ EPSS 0.68 CVE-2025-20337 CVE-2026-20176 CVE-2026-20211 CVE-2026-20284 CVE-2026-20307 CVE-2026-76423 CVE-2026-76460 Cisco US
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing. One of them is known to be actively exploited. For more information, see Cisco…
EPSS 0.00 CVE-2026-20130 CVE-2026-20192 CVE-2026-20194 CVE-2026-20234 CVE-2026-20237 CVE-2026-20287 Cisco US
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software and Cisco Secure Firewall Management Center (FMC) Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal…
EPSS 0.00 CVE-2026-20329 CVE-2026-20330 CVE-2026-20331 CVE-2026-20332 CVE-2026-20333 CVE-2026-20334 CVE-2026-20335 CVE-2026-20336 Cisco US
15. September 2026 Beschreibung In Cisco Secure Email Gateway existiert eine kritische Sicherheitslücke. Bei erfolgreicher Ausnutzung könnte diese Sicherheitslücke es nicht authentifizierten Angreifer:innen aus der Ferne ermöglichen Befehle mit Root-Rechten auf dem zugrunde liegenden Betriebssystem auszuführen. Laut Cisco wurde eine Ausnutzung der Sicherheitslücke bereits beobachtet. CVE-Nummer(n): CVE-2026-76461 CVSS Base Score: 9.8 Auswirkungen Ein Angreifer könnte diese Sicherheitslücke…
KEV ✓ EPSS 0.02 CVSS 9.8 CVE-2026-76461 Cisco veřejná správa AT SE US FI GB FR CA IT
DESCRIERE Experții în securitate cibernetică au descoperit o vulnerabilitate critică, CVE-...
Cisco RO
Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks. [...]
KEV ✓ EPSS 0.30 CVE-2025-20393 CVE-2026-20353 CVE-2026-76440 CVE-2026-76441 CVE-2026-76443 CVE-2026-76461 Cisco US
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: 9.8, CVEs: CVE-2026-20353, CVE-2026-76440, CVE-2026-76441, CVE-2026-76442, CVE-2026-76443, Summary: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally…
EPSS 0.00 CVSS 9.8 CVE-2026-20353 CVE-2026-76440 CVE-2026-76441 CVE-2026-76442 CVE-2026-76443 Cisco FI US
Cisco heeft een kwetsbaarheid verholpen in Cisco Secure Email Gateway. De kwetsbaarheid bevindt zich in de verwerking van e-mailberichten binnen Cisco AsyncOS Software voor Cisco Secure Email Gateway en wordt veroorzaakt door onvoldoende validatie van inkomende e-mailberichten. Een niet-geauthenticeerde kwaadwillende kan een speciaal vervaardigd e-mailbericht met kwaadaardige SQL-instructies naar een kwetsbaar systeem versturen. Succesvol misbruik kan leiden tot het uitvoeren van willekeurige…
Cisco NL
Cisco heeft een kwetsbaarheid verholpen in Cisco Secure Firewall Management Center. De kwetsbaarheid bevindt zich in de webinterface van Cisco Secure Firewall Management Center en betreft een hard-coded, statisch wachtwoord voor een laaggeprivilegieerd account. Hierdoor kunnen niet-geauthenticeerde externe aanvallers toegang verkrijgen zonder inloggegevens. Deze toegang kan leiden tot het blootstellen van gevoelige data die door het systeem wordt opgeslagen of beheerd. In combinatie met andere…
KEV ✓ · ransomware EPSS 0.11 CVSS 9.8 CVE-2026-20316 Cisco NL US
Cisco heeft kwetsbaarheden verholpen in Cisco Secure Firewall Management Center. De kwetsbaarheid met kenmerk CVE-2026-20079 bevindt zich in de webinterface van Cisco Secure Firewall Management Center. Een ongeauthenticeerde externe kwaadwillende kan de authenticatiecontroles omzeilen door een onjuist systeemproces dat bij het opstarten is aangemaakt te misbruiken. De kwaadwillende kan deze kwetsbaarheid misbruiken door speciaal geprepareerde HTTP-verzoeken naar een getroffen apparaat te sturen…
KEV ✓ · ransomware EPSS 0.76 CVE-2026-20079 CVE-2026-20131 Cisco NL CA
Welcome to this week’s edition of the Threat Source newsletter. Ask anybody in this industry what the work does to the health of the people who do it and you get one word back: burnout. It's a fine word, in and of itself. It’s easy to reach for, understandable to everyone… and it's the wrong one, most of the time. So, story time. Last year I gave an interview with the amazing Hazel Burton about VPNFilter, and my run-in with burnout. I was a manager during that time, and it took a toll on me and…
KEV ✓ · ransomware EPSS 0.76 CVSS 10.0 CVE-2026-20079 CVE-2026-20316 Cisco US
CONTEXT Compania Cisco a actualizat, pe 9 septembrie 2026, recomandările aferente vulnerabilităț...
Cisco RO
Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. [...]
KEV ✓ EPSS 0.76 CVE-2026-20079 Cisco veřejná správa US
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel…
KEV ✓ EPSS 0.76 CVE-2025-25249 CVE-2026-19490 CVE-2026-20079 CVE-2026-87491 Fortinet Citrix Google Cisco veřejná správa US