<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:o:cisco:asyncos:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3ociscoasyncos/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 02 Sep 2026 18:06:39 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3ociscoasyncos/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Cisco Security Updates - September 2026</title><link>https://feed.craftedsignal.io/briefs/2026-09-cisco-security-updates/</link><pubDate>Wed, 02 Sep 2026 18:06:39 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cisco-security-updates/</guid><description>Roundup of Cisco security advisories published in September 2026.</description><content:encoded><![CDATA[<p>This roundup covers 78 Cisco security vulnerabilities. CVSS base scores range from 4.9 to 9.9. None are reported as actively exploited at the time of release. The issues affect Adaptive Security Appliance Software, AsyncOS Software, BroadWorks CommPilot Application Software, Desk Phone 9800 Series, Identity Services Engine, Nexus 9000 Series Switches, Nexus Dashboard, Secure Adaptive Security Appliance Software, Secure Email, Secure Email Gateway, Secure FMC Software, Secure Firewall Adaptive Security Appliance Software, Secure Firewall Management Center, Secure Firewall Management Center Software, Secure Firewall Threat Defense Software, ThousandEyes Virtual Appliance, UCS Servers.</p>
<h2 id="summary">Summary</h2>
<table>
	<thead>
			<tr>
					<th>CVE</th>
					<th>Product</th>
					<th>Severity</th>
					<th>CVSS</th>
					<th>EPSS</th>
					<th>KEV</th>
					<th>Source</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td><a href="#cve-2026-20354">CVE-2026-20354</a></td>
					<td>Secure Email</td>
					<td>Medium</td>
					<td>5.9</td>
					<td>0.15%</td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-smime-disc-dzw4rEdY?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Email%20Secure/Multipurpose%20Internet%20Mail%20Extensions%20Ciphertext%20Decryption%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20355">CVE-2026-20355</a></td>
					<td>Secure Email</td>
					<td>Medium</td>
					<td>5.9</td>
					<td>0.15%</td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-smime-disc-dzw4rEdY?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Email%20Secure/Multipurpose%20Internet%20Mail%20Extensions%20Ciphertext%20Decryption%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20212">CVE-2026-20212</a></td>
					<td>Nexus 9000 Series Switches</td>
					<td>Critical</td>
					<td>9.8</td>
					<td>0.53%</td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n9k-s1-rce-EH8dEtr?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Nexus%209000%20Series%20Switches%20Silicon%20One%20Remote%20Code%20Execution%20Vulnerability%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20281">CVE-2026-20281</a></td>
					<td>Desk Phone 9800 Series</td>
					<td>High</td>
					<td>7.5</td>
					<td>0.33%</td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-phone-dos-txMYNRzv?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Desk%20Phone%209800%20Series,%20IP%20Phone%207800%20and%208800%20Series,%20and%20Video%20Phone%208875%20with%20SIP%20Software%20Denial%20of%20Service%20Vulnerability%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20293">CVE-2026-20293</a></td>
					<td>UCS Servers</td>
					<td>High</td>
					<td>7.1</td>
					<td>0.13%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20293">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20353">CVE-2026-20353</a></td>
					<td>Secure Email Gateway</td>
					<td>Critical</td>
					<td>9.8</td>
					<td>0.37%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20353">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76440">CVE-2026-76440</a></td>
					<td>Secure Email Gateway</td>
					<td>Critical</td>
					<td>9.8</td>
					<td>0.43%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-76440">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76441">CVE-2026-76441</a></td>
					<td>Secure Email Gateway</td>
					<td>Critical</td>
					<td>9.8</td>
					<td>0.46%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-76441">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76443">CVE-2026-76443</a></td>
					<td>Secure Email Gateway</td>
					<td>Critical</td>
					<td>9.8</td>
					<td>0.37%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-76443">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76461">CVE-2026-76461</a></td>
					<td>AsyncOS Software</td>
					<td>Critical</td>
					<td>9.8</td>
					<td>2.16%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-76461">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76442">CVE-2026-76442</a></td>
					<td>Secure Email Gateway</td>
					<td>High</td>
					<td>7.5</td>
					<td>0.33%</td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-76442">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20234">CVE-2026-20234</a></td>
					<td>Identity Services Engine</td>
					<td>Critical</td>
					<td>9.9</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20234">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20305">CVE-2026-20305</a></td>
					<td>Identity Services Engine</td>
					<td>Critical</td>
					<td>9.1</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20305">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20306">CVE-2026-20306</a></td>
					<td>Identity Services Engine</td>
					<td>Critical</td>
					<td>9.1</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20306">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20307">CVE-2026-20307</a></td>
					<td>Identity Services Engine</td>
					<td>Critical</td>
					<td>9.9</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20307">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20331">CVE-2026-20331</a></td>
					<td>Secure Adaptive Security Appliance Software</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20331">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76420">CVE-2026-76420</a></td>
					<td>Secure FMC Software</td>
					<td>Critical</td>
					<td>9.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-76420">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76460">CVE-2026-76460</a></td>
					<td>Identity Services Engine</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://www.cve.org/CVERecord?id=CVE-2026-76460">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2024-20260">CVE-2024-20260</a></td>
					<td>Secure Firewall Adaptive Security Appliance Software</td>
					<td>High</td>
					<td>8.6</td>
					<td>0.62%</td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftdvirtual-dos-MuenGnYR?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Adaptive%20Security%20Appliance%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20SSL%20VPN%20Denial%20of%20Service%20Vulnerability%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20250">CVE-2026-20250</a></td>
					<td>Adaptive Security Appliance Software</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-dtls-dos-Kp57HkyO?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Adaptive%20Security%20Appliance%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20for%20Secure%20Firewall%203100%20and%204200%20Series%20DTLS%20Denial%20of%20Service%20Vulnerability%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20242">CVE-2026-20242</a></td>
					<td>Secure Firewall Management Center Software</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-javarce-y2NypXwk?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20Software%20Java%20Deserialization%20Remote%20Code%20Execution%20Vulnerability%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20282">CVE-2026-20282</a></td>
					<td>Identity Services Engine</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-mult-vul-ymSsTLCc?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Authenticated%20Remote%20Code%20Execution%20and%20API%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20283">CVE-2026-20283</a></td>
					<td>Identity Services Engine</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-mult-vul-ymSsTLCc?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Authenticated%20Remote%20Code%20Execution%20and%20API%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20284">CVE-2026-20284</a></td>
					<td>Identity Services Engine</td>
					<td>Critical</td>
					<td>9.1</td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-mult-vul-ymSsTLCc?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Authenticated%20Remote%20Code%20Execution%20and%20API%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76423">CVE-2026-76423</a></td>
					<td>Identity Services Engine</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76424">CVE-2026-76424</a></td>
					<td>Identity Services Engine</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76425">CVE-2026-76425</a></td>
					<td>Identity Services Engine</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76426">CVE-2026-76426</a></td>
					<td>Identity Services Engine</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76427">CVE-2026-76427</a></td>
					<td>Identity Services Engine</td>
					<td>Medium</td>
					<td>4.9</td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76428">CVE-2026-76428</a></td>
					<td>Identity Services Engine</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20352">CVE-2026-20352</a></td>
					<td>Identity Services Engine</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-RADIUS-dos-wR3hYPMw?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20RADIUS%20Denial%20of%20Service%20Vulnerability%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20295">CVE-2026-20295</a></td>
					<td>Secure Firewall Management Center Software</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmcftd-sftun-multivulns-WGVHOrN3?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20sftunnel%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20323">CVE-2026-20323</a></td>
					<td>Secure Firewall Management Center Software</td>
					<td>High</td>
					<td>8.3</td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmcftd-sftun-multivulns-WGVHOrN3?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20sftunnel%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20135">CVE-2026-20135</a></td>
					<td>Secure Firewall Threat Defense Software</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-tls1.3-dos-dLxwFWgF?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Threat%20Defense%20Software%20TLS%201.3%20Denial%20of%20Service%20Vulnerability%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20071">CVE-2026-20071</a></td>
					<td>Identity Services Engine</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-vuln-kWLeNnRD?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20802.1X%20Session%20Hijack%20and%20Information%20Disclosure%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20072">CVE-2026-20072</a></td>
					<td>Identity Services Engine</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-vuln-kWLeNnRD?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20802.1X%20Session%20Hijack%20and%20Information%20Disclosure%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20340">CVE-2026-20340</a></td>
					<td>Secure Firewall Management Center</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-mulivulns-4PsnFwvx?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20Software%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20341">CVE-2026-20341</a></td>
					<td>Secure Firewall Management Center</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-mulivulns-4PsnFwvx?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20Software%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20342">CVE-2026-20342</a></td>
					<td>Secure Firewall Management Center</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-mulivulns-4PsnFwvx?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20Software%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20343">CVE-2026-20343</a></td>
					<td>Secure Firewall Management Center</td>
					<td>High</td>
					<td>7.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-mulivulns-4PsnFwvx?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20Software%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20344">CVE-2026-20344</a></td>
					<td>Secure Firewall Management Center</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-mulivulns-4PsnFwvx?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20Software%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20248">CVE-2026-20248</a></td>
					<td>Secure Firewall Adaptive Security Appliance Software</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-tcpdns-dos-p6dUnjr5?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Adaptive%20Security%20Appliance%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20TCP%20DNS%20Denial%20of%20Service%20Vulnerability%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20350">CVE-2026-20350</a></td>
					<td>ThousandEyes Virtual Appliance</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-teva-os-command-W4GAO6jp?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20ThousandEyes%20Virtual%20Appliance%20Authenticated%20Web%20Interface%20Command%20Injection%20Vulnerability%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20290">CVE-2026-20290</a></td>
					<td>Secure Firewall Threat Defense Software</td>
					<td>Medium</td>
					<td>5.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-snort2-ssldos-Mw7WYX9c?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Threat%20Defense%20Software%20Snort%202%20SSL/TLS%20Denial%20of%20Service%20Vulnerability%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76431">CVE-2026-76431</a></td>
					<td>Identity Services Engine</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-traversal-WDTgYCdn?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Multiple%20Path%20Traversal%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76432">CVE-2026-76432</a></td>
					<td>Identity Services Engine</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-traversal-WDTgYCdn?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Multiple%20Path%20Traversal%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76433">CVE-2026-76433</a></td>
					<td>Identity Services Engine</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-traversal-WDTgYCdn?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Multiple%20Path%20Traversal%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76434">CVE-2026-76434</a></td>
					<td>Identity Services Engine</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-traversal-WDTgYCdn?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Multiple%20Path%20Traversal%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20309">CVE-2026-20309</a></td>
					<td>Identity Services Engine</td>
					<td>Medium</td>
					<td>6.1</td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xss-Uz9VWRQ?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Cross-Site%20Scripting%20Vulnerability%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20120">CVE-2026-20120</a></td>
					<td>Secure Firewall Adaptive Security Appliance Software</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-acl-bypass-8p6vFvw?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Adaptive%20Security%20Appliance%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20Object%20Group%20Access%20Control%20List%20Bypass%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20121">CVE-2026-20121</a></td>
					<td>Secure Firewall Adaptive Security Appliance Software</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-acl-bypass-8p6vFvw?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Adaptive%20Security%20Appliance%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20Object%20Group%20Access%20Control%20List%20Bypass%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20285">CVE-2026-20285</a></td>
					<td>Identity Services Engine</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-auth-bypass-1-MxcTNgwx?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Authorization%20Bypass%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20286">CVE-2026-20286</a></td>
					<td>Identity Services Engine</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-auth-bypass-1-MxcTNgwx?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Authorization%20Bypass%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76438">CVE-2026-76438</a></td>
					<td>BroadWorks CommPilot Application Software</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-auth-bypass-broadwor-57m9dmm5?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20BroadWorks%20CommPilot%20Application%20Software%20Authorization%20Bypass%20Vulnerability%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20222">CVE-2026-20222</a></td>
					<td>Secure Firewall Adaptive Security Appliance Software</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-eigrp-dos-GOhNejSj?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Adaptive%20Security%20Appliance%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20EIGRP%20Denial%20of%20Service%20Vulnerability%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20154">CVE-2026-20154</a></td>
					<td>Secure Firewall Adaptive Security Appliance Software</td>
					<td>High</td>
					<td>8.6</td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ftd-logging-dos-ZXXNesfN?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Adaptive%20Security%20Appliance%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20Logging%20Denial%20of%20Service%20Vulnerability%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76439">CVE-2026-76439</a></td>
					<td>Identity Services Engine</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiauth-bypass-sgD2HbL4?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Authentication%20Bypass%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76444">CVE-2026-76444</a></td>
					<td>Identity Services Engine</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiauth-bypass-sgD2HbL4?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Authentication%20Bypass%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76446">CVE-2026-76446</a></td>
					<td>Identity Services Engine</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiauth-bypass-sgD2HbL4?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Authentication%20Bypass%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76447">CVE-2026-76447</a></td>
					<td>Identity Services Engine</td>
					<td>Medium</td>
					<td>5.3</td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiauth-bypass-sgD2HbL4?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Authentication%20Bypass%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20249">CVE-2026-20249</a></td>
					<td>Secure Firewall Adaptive Security Appliance Software</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ikev2cert-dos-uWyc2xtv?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Adaptive%20Security%20Appliance%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20IKEv2%20Certificate%20Authentication%20Denial%20of%20Service%20Vulnerability%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76448">CVE-2026-76448</a></td>
					<td>Identity Services Engine</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multisql-inject-JnHK54Rq?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20SQL%20and%20HQL%20Injection%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76449">CVE-2026-76449</a></td>
					<td>Identity Services Engine</td>
					<td>Medium</td>
					<td>4.9</td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multisql-inject-JnHK54Rq?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20SQL%20and%20HQL%20Injection%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76450">CVE-2026-76450</a></td>
					<td>Identity Services Engine</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multisql-inject-JnHK54Rq?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20SQL%20and%20HQL%20Injection%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76451">CVE-2026-76451</a></td>
					<td>Identity Services Engine</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multisql-inject-JnHK54Rq?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20SQL%20and%20HQL%20Injection%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20247">CVE-2026-20247</a></td>
					<td>Identity Services Engine</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-sql-inj-3QTKR947?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20SQL%20Injection%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20300">CVE-2026-20300</a></td>
					<td>Identity Services Engine</td>
					<td>High</td>
					<td>7.1</td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-sql-inj-3QTKR947?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20SQL%20Injection%20Vulnerabilities%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20324">CVE-2026-20324</a></td>
					<td>Secure Firewall Management Center Software</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-sftunn-codex-c3O4Jft2?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20Software%20sftunnel%20Root%20Arbitrary%20Code%20Execution%20Vulnerability%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20235">CVE-2026-20235</a></td>
					<td>Identity Services Engine</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-inf-disc-LFWvcCu?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Information%20Disclosure%20Vulnerability%26vs_k=1">source</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20176">CVE-2026-20176</a></td>
					<td>Identity Services Engine</td>
					<td>Critical</td>
					<td>9.1</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20176">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20211">CVE-2026-20211</a></td>
					<td>Identity Services Engine</td>
					<td>Critical</td>
					<td>9.1</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20211">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20322">CVE-2026-20322</a></td>
					<td>Nexus Dashboard</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20322">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20325">CVE-2026-20325</a></td>
					<td>Nexus Dashboard</td>
					<td>Critical</td>
					<td>9.9</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20325">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20326">CVE-2026-20326</a></td>
					<td>Nexus Dashboard</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20326">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20361">CVE-2026-20361</a></td>
					<td>Nexus Dashboard</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20361">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-20360">CVE-2026-20360</a></td>
					<td>Nexus Dashboard</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20360">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76409">CVE-2026-76409</a></td>
					<td>Nexus Dashboard</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-76409">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-76412">CVE-2026-76412</a></td>
					<td>Secure FMC Software</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-76412">NVD</a> (authoritative)</td>
			</tr>
	</tbody>
</table>
<h2 id="cve-2026-20354">CVE-2026-20354</h2>
<p>Cisco Secure Email contains multiple vulnerabilities in its S/MIME decryption functionality stemming from insufficient message integrity validation. These flaws allow an unauthenticated, remote attacker to perform machine-in-the-middle attacks to intercept encrypted email traffic, modify it, and subsequently recover the plaintext content of the communications.</p>
<p>Affected products:</p>
<ul>
<li>Secure Email</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-smime-disc-dzw4rEdY?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Email%20Secure/Multipurpose%20Internet%20Mail%20Extensions%20Ciphertext%20Decryption%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-smime-disc-dzw4rEdY?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Email%20Secure/Multipurpose%20Internet%20Mail%20Extensions%20Ciphertext%20Decryption%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20355">CVE-2026-20355</a>.</p>
<h2 id="cve-2026-20355">CVE-2026-20355</h2>
<p>Cisco Secure Email contains multiple vulnerabilities in its S/MIME decryption functionality stemming from insufficient message integrity validation. These flaws allow an unauthenticated, remote attacker to perform machine-in-the-middle attacks to intercept encrypted email traffic, modify it, and subsequently recover the plaintext content of the communications.</p>
<p>Affected products:</p>
<ul>
<li>Secure Email</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-smime-disc-dzw4rEdY?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Email%20Secure/Multipurpose%20Internet%20Mail%20Extensions%20Ciphertext%20Decryption%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-smime-disc-dzw4rEdY?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Email%20Secure/Multipurpose%20Internet%20Mail%20Extensions%20Ciphertext%20Decryption%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20354">CVE-2026-20354</a>.</p>
<h2 id="cve-2026-20212">CVE-2026-20212</h2>
<p>A critical vulnerability exists in the Silicon One integration for Cisco Nexus 9000 Series Switches, stemming from exposed TCP ports 43210 and 43211 in the default Layer 3 VRF. An unauthenticated remote attacker can leverage this access to execute arbitrary code with root privileges or cause a device reload via the S1HAL process crash.</p>
<p>Affected products:</p>
<ul>
<li>Nexus 9000 Series Switches</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n9k-s1-rce-EH8dEtr?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Nexus%209000%20Series%20Switches%20Silicon%20One%20Remote%20Code%20Execution%20Vulnerability%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n9k-s1-rce-EH8dEtr?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Nexus%209000%20Series%20Switches%20Silicon%20One%20Remote%20Code%20Execution%20Vulnerability%26vs_k=1</a></p>
<h2 id="cve-2026-20281">CVE-2026-20281</h2>
<p>Cisco SIP-enabled desk and video phones are vulnerable to a remote denial-of-service condition due to improper memory management when processing HTTP packets. An unauthenticated attacker can trigger this by sending a continuous stream of crafted HTTP packets to the device, provided the phone is registered to Cisco Unified Communications Manager and has Web Access enabled. Exploitation results in memory exhaustion, necessitating a manual reboot of the device for recovery.</p>
<p>Affected products:</p>
<ul>
<li>Desk Phone 9800 Series</li>
<li>IP Phone 7800 Series</li>
<li>IP Phone 8800 Series</li>
<li>Video Phone 8875</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-phone-dos-txMYNRzv?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Desk%20Phone%209800%20Series,%20IP%20Phone%207800%20and%208800%20Series,%20and%20Video%20Phone%208875%20with%20SIP%20Software%20Denial%20of%20Service%20Vulnerability%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-phone-dos-txMYNRzv?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Desk%20Phone%209800%20Series,%20IP%20Phone%207800%20and%208800%20Series,%20and%20Video%20Phone%208875%20with%20SIP%20Software%20Denial%20of%20Service%20Vulnerability%26vs_k=1</a></p>
<h2 id="cve-2026-20293">CVE-2026-20293</h2>
<p>A vulnerability in the UEFI Shell implementation of Cisco UCS Servers and UCS-based appliances allows authenticated users or attackers with physical access to bypass UEFI Secure Boot validation. By using memory write commands available within the UEFI Shell, an attacker can modify UEFI memory variables to overwrite Secure Boot-related values, enabling the execution of unauthorized software in the preboot environment.</p>
<p>Affected products:</p>
<ul>
<li>UCS Servers</li>
<li>UCS-based appliances</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20293">https://nvd.nist.gov/vuln/detail/CVE-2026-20293</a></p>
<h2 id="cve-2026-20353">CVE-2026-20353</h2>
<p>CVE-2026-20353 refers to vulnerabilities in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager caused by improper control of a resource through its lifetime (CWE-664). This vulnerability carries a CVSS v3.1 base score of 9.8, indicating a critical security flaw identified during an internal security review.</p>
<p>Affected products:</p>
<ul>
<li>Secure Email Gateway</li>
<li>Secure Email and Web Manager</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20353">https://nvd.nist.gov/vuln/detail/CVE-2026-20353</a></p>
<p>Related in this roundup: <a href="#cve-2026-76440">CVE-2026-76440</a>, <a href="#cve-2026-76441">CVE-2026-76441</a>, <a href="#cve-2026-76443">CVE-2026-76443</a>, <a href="#cve-2026-76442">CVE-2026-76442</a>.</p>
<h2 id="cve-2026-76440">CVE-2026-76440</h2>
<p>CVE-2026-76440 identifies a path traversal vulnerability in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager, discovered during an internal security review. The vulnerability allows for unauthorized file system access due to improper input validation, carrying a CVSS base score of 9.8.</p>
<p>Affected products:</p>
<ul>
<li>Secure Email Gateway</li>
<li>Secure Email and Web Manager</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-76440">https://nvd.nist.gov/vuln/detail/CVE-2026-76440</a></p>
<p>Related in this roundup: <a href="#cve-2026-20353">CVE-2026-20353</a>, <a href="#cve-2026-76441">CVE-2026-76441</a>, <a href="#cve-2026-76443">CVE-2026-76443</a>, <a href="#cve-2026-76442">CVE-2026-76442</a>.</p>
<h2 id="cve-2026-76441">CVE-2026-76441</h2>
<p>CVE-2026-76441 identifies multiple improper access control vulnerabilities within Cisco Secure Email Gateway and Cisco Secure Email and Web Manager, discovered during an internal security review. These vulnerabilities carry a high CVSS score of 9.8 and highlight a failure to properly restrict access to sensitive components, requiring updates to the affected software.</p>
<p>Affected products:</p>
<ul>
<li>Secure Email Gateway</li>
<li>Secure Email and Web Manager</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-76441">https://nvd.nist.gov/vuln/detail/CVE-2026-76441</a></p>
<p>Related in this roundup: <a href="#cve-2026-20353">CVE-2026-20353</a>, <a href="#cve-2026-76440">CVE-2026-76440</a>, <a href="#cve-2026-76443">CVE-2026-76443</a>, <a href="#cve-2026-76442">CVE-2026-76442</a>.</p>
<h2 id="cve-2026-76443">CVE-2026-76443</h2>
<p>Cisco has released patches for multiple internally discovered vulnerabilities in the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager, tracked under CVE-2026-76443. The vulnerabilities are identified as improper neutralization issues (CWE-707) and carry a CVSS base score of 9.8, indicating a critical severity level requiring immediate attention from administrators.</p>
<p>Affected products:</p>
<ul>
<li>Secure Email Gateway</li>
<li>Secure Email and Web Manager</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-76443">https://nvd.nist.gov/vuln/detail/CVE-2026-76443</a></p>
<p>Related in this roundup: <a href="#cve-2026-20353">CVE-2026-20353</a>, <a href="#cve-2026-76440">CVE-2026-76440</a>, <a href="#cve-2026-76441">CVE-2026-76441</a>, <a href="#cve-2026-76442">CVE-2026-76442</a>.</p>
<h2 id="cve-2026-76461">CVE-2026-76461</h2>
<p>CVE-2026-76461 is a critical vulnerability in Cisco AsyncOS Software for Secure Email Gateway caused by insufficient validation during email parsing. An unauthenticated remote attacker can leverage a crafted email containing malicious SQL statements to achieve arbitrary command execution with root privileges on the underlying operating system.</p>
<p>Affected products:</p>
<ul>
<li>AsyncOS Software</li>
<li>Secure Email Gateway</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-76461">https://nvd.nist.gov/vuln/detail/CVE-2026-76461</a></p>
<h2 id="cve-2026-76442">CVE-2026-76442</h2>
<p>CVE-2026-76442 describes a vulnerability in Cisco Secure Email Gateway and Cisco Secure Email and Web Manager identified during an internal security review. The vulnerability relates to improper validation of input quantity (CWE-1284), which can lead to potential service disruption or security bypass. Remediation involves applying the provided software hardening releases from the vendor.</p>
<p>Affected products:</p>
<ul>
<li>Secure Email Gateway</li>
<li>Secure Email and Web Manager</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-76442">https://nvd.nist.gov/vuln/detail/CVE-2026-76442</a></p>
<p>Related in this roundup: <a href="#cve-2026-20353">CVE-2026-20353</a>, <a href="#cve-2026-76440">CVE-2026-76440</a>, <a href="#cve-2026-76441">CVE-2026-76441</a>, <a href="#cve-2026-76443">CVE-2026-76443</a>.</p>
<h2 id="cve-2026-20234">CVE-2026-20234</h2>
<p>Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) contain a vulnerability related to insufficiently protected credentials, categorized under CWE-522. The vulnerability carries a high CVSS v3.1 base score of 9.9, and was identified during an internal security review, prompting a software hardening release to address the credential protection flaws.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
<li>ISE Passive Identity Connector</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20234">https://nvd.nist.gov/vuln/detail/CVE-2026-20234</a></p>
<p>Related in this roundup: <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-20305">CVE-2026-20305</h2>
<p>CVE-2026-20305 is a command injection vulnerability within the diagnostic tools of Cisco ISE and ISE-PIC. An authenticated remote attacker with administrative credentials can exploit improper input validation via the web-based management interface to execute arbitrary code with root privileges. Successful exploitation may result in a denial of service condition by rendering the affected node unavailable.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
<li>ISE-PIC</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20305">https://nvd.nist.gov/vuln/detail/CVE-2026-20305</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-20306">CVE-2026-20306</h2>
<p>CVE-2026-20306 is a command injection vulnerability in the REST API of Cisco Identity Services Engine (ISE) and ISE-PIC. An authenticated remote attacker with administrative credentials can supply crafted commands to the management interface, leading to arbitrary code execution with root privileges or a denial-of-service condition.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
<li>ISE-PIC</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20306">https://nvd.nist.gov/vuln/detail/CVE-2026-20306</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-20307">CVE-2026-20307</h2>
<p>CVE-2026-20307 is a critical remote code execution vulnerability in the web management interface of Cisco Identity Services Engine (ISE). The vulnerability arises from insecure deserialization of Java byte streams, allowing an authenticated, low-privileged administrator to execute arbitrary commands as root on the underlying operating system. Successful exploitation can lead to full system compromise or a denial of service condition affecting network authentication.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20307">https://nvd.nist.gov/vuln/detail/CVE-2026-20307</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-20331">CVE-2026-20331</h2>
<p>CVE-2026-20331 refers to a set of internally discovered vulnerabilities affecting Cisco Secure Adaptive Security Appliance (ASA), Firepower Threat Defense (FTD), and Firepower Management Center (FMC) software. These vulnerabilities are classified under CWE-693 (Protection Mechanism Failure) and carry a CVSS base score of 9.6, indicating critical security implications requiring software hardening updates.</p>
<p>Affected products:</p>
<ul>
<li>Secure Adaptive Security Appliance Software</li>
<li>Secure Firewall Threat Defense Software</li>
<li>Secure Firewall Management Center Software</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20331">https://nvd.nist.gov/vuln/detail/CVE-2026-20331</a></p>
<h2 id="cve-2026-76420">CVE-2026-76420</h2>
<p>CVE-2026-76420 is a critical vulnerability in the Apache JServ Protocol (AJP) connector within Cisco Secure FMC Software caused by improper encryption parameter initialization during boot. An unauthenticated, remote attacker can exploit this via crafted packets when the sftunnel connection to Cisco Secure FTD Software is inactive, potentially achieving remote code execution as root and gaining unauthorized control over the FMC REST APIs.</p>
<p>Affected products:</p>
<ul>
<li>Secure FMC Software</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-76420">https://nvd.nist.gov/vuln/detail/CVE-2026-76420</a></p>
<p>Related in this roundup: <a href="#cve-2026-76412">CVE-2026-76412</a>.</p>
<h2 id="cve-2026-76460">CVE-2026-76460</h2>
<p>Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that allows unauthenticated remote attackers to bypass the web-based management interface and gain unauthorized access to the device.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
<li>ISE Passive Identity Connector</li>
</ul>
<p>Source: <a href="https://www.cve.org/CVERecord?id=CVE-2026-76460">https://www.cve.org/CVERecord?id=CVE-2026-76460</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2024-20260">CVE-2024-20260</h2>
<p>A vulnerability in the VPN and management web servers of Cisco Secure Firewall ASA and FTD software allows an unauthenticated remote attacker to cause a denial of service (DoS) by sending a high volume of SSL/TLS connection requests. The attack depletes system memory or buffer blocks, causing connection processing to slow down or fail entirely. A manual reload may be required to restore services.</p>
<p>Affected products:</p>
<ul>
<li>Secure Firewall Adaptive Security Appliance Software</li>
<li>Secure Firewall Threat Defense Software</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftdvirtual-dos-MuenGnYR?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Adaptive%20Security%20Appliance%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20SSL%20VPN%20Denial%20of%20Service%20Vulnerability%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftdvirtual-dos-MuenGnYR?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Adaptive%20Security%20Appliance%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20SSL%20VPN%20Denial%20of%20Service%20Vulnerability%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20248">CVE-2026-20248</a>, <a href="#cve-2026-20120">CVE-2026-20120</a>, <a href="#cve-2026-20121">CVE-2026-20121</a>, <a href="#cve-2026-20222">CVE-2026-20222</a>, <a href="#cve-2026-20154">CVE-2026-20154</a>, <a href="#cve-2026-20249">CVE-2026-20249</a>.</p>
<h2 id="cve-2026-20250">CVE-2026-20250</h2>
<p>A vulnerability in the DTLS message handling of Cisco Secure Firewall ASA and FTD software for 3100 and 4200 series devices allows an unauthenticated, remote attacker to trigger a denial-of-service (DoS) condition. The issue stems from improper resource management during the processing of crafted DTLS traffic, which can force the device to reload. Detection engineers should monitor for anomalous spikes or malformed DTLS traffic patterns directed at the firewall's management or data plane interfaces.</p>
<p>Affected products:</p>
<ul>
<li>Adaptive Security Appliance Software</li>
<li>Secure Firewall Threat Defense Software</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-dtls-dos-Kp57HkyO?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Adaptive%20Security%20Appliance%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20for%20Secure%20Firewall%203100%20and%204200%20Series%20DTLS%20Denial%20of%20Service%20Vulnerability%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-dtls-dos-Kp57HkyO?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Adaptive%20Security%20Appliance%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20for%20Secure%20Firewall%203100%20and%204200%20Series%20DTLS%20Denial%20of%20Service%20Vulnerability%26vs_k=1</a></p>
<h2 id="cve-2026-20242">CVE-2026-20242</h2>
<p>A critical remote code execution vulnerability exists in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software. The flaw arises from insecure deserialization of user-supplied Java byte streams. An unauthenticated, remote attacker who already controls a host authorized in the external database access list can send a crafted Java object to a specific TCP port to execute arbitrary commands as the root user.</p>
<p>Affected products:</p>
<ul>
<li>Secure Firewall Management Center Software</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-javarce-y2NypXwk?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20Software%20Java%20Deserialization%20Remote%20Code%20Execution%20Vulnerability%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-javarce-y2NypXwk?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20Software%20Java%20Deserialization%20Remote%20Code%20Execution%20Vulnerability%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20295">CVE-2026-20295</a>, <a href="#cve-2026-20323">CVE-2026-20323</a>, <a href="#cve-2026-20324">CVE-2026-20324</a>.</p>
<h2 id="cve-2026-20282">CVE-2026-20282</h2>
<p>Cisco Identity Services Engine (ISE) contains multiple vulnerabilities allowing authenticated, remote attackers to perform SQL injections, modify database contents, and execute arbitrary operating system commands. These vulnerabilities are particularly severe as they can be leveraged to escalate privileges to the root level on the affected device.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-mult-vul-ymSsTLCc?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Authenticated%20Remote%20Code%20Execution%20and%20API%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-mult-vul-ymSsTLCc?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Authenticated%20Remote%20Code%20Execution%20and%20API%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-20283">CVE-2026-20283</h2>
<p>Cisco Identity Services Engine (ISE) contains multiple vulnerabilities allowing authenticated, remote attackers to perform SQL injections, modify database contents, and execute arbitrary operating system commands. These vulnerabilities are particularly severe as they can be leveraged to escalate privileges to the root level on the affected device.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-mult-vul-ymSsTLCc?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Authenticated%20Remote%20Code%20Execution%20and%20API%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-mult-vul-ymSsTLCc?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Authenticated%20Remote%20Code%20Execution%20and%20API%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-20284">CVE-2026-20284</h2>
<p>Cisco Identity Services Engine (ISE) contains multiple vulnerabilities allowing authenticated, remote attackers to perform SQL injections, modify database contents, and execute arbitrary operating system commands. These vulnerabilities are particularly severe as they can be leveraged to escalate privileges to the root level on the affected device.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-mult-vul-ymSsTLCc?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Authenticated%20Remote%20Code%20Execution%20and%20API%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-mult-vul-ymSsTLCc?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Authenticated%20Remote%20Code%20Execution%20and%20API%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-76423">CVE-2026-76423</h2>
<p>Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector are vulnerable to multiple critical security flaws, including authentication bypass, remote code execution (RCE), SQL injection, and XML External Entity (XXE) injection via the REST API. These vulnerabilities allow unauthenticated remote attackers to compromise the appliance. Organizations are advised to apply the provided software updates immediately, as no workarounds are available.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
<li>ISE Passive Identity Connector</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-76424">CVE-2026-76424</h2>
<p>Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector are vulnerable to multiple critical security flaws, including authentication bypass, remote code execution (RCE), SQL injection, and XML External Entity (XXE) injection via the REST API. These vulnerabilities allow unauthenticated remote attackers to compromise the appliance. Organizations are advised to apply the provided software updates immediately, as no workarounds are available.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
<li>ISE Passive Identity Connector</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-76425">CVE-2026-76425</h2>
<p>Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector are vulnerable to multiple critical security flaws, including authentication bypass, remote code execution (RCE), SQL injection, and XML External Entity (XXE) injection via the REST API. These vulnerabilities allow unauthenticated remote attackers to compromise the appliance. Organizations are advised to apply the provided software updates immediately, as no workarounds are available.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
<li>ISE Passive Identity Connector</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-76426">CVE-2026-76426</h2>
<p>Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector are vulnerable to multiple critical security flaws, including authentication bypass, remote code execution (RCE), SQL injection, and XML External Entity (XXE) injection via the REST API. These vulnerabilities allow unauthenticated remote attackers to compromise the appliance. Organizations are advised to apply the provided software updates immediately, as no workarounds are available.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
<li>ISE Passive Identity Connector</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-76427">CVE-2026-76427</h2>
<p>Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector are vulnerable to multiple critical security flaws, including authentication bypass, remote code execution (RCE), SQL injection, and XML External Entity (XXE) injection via the REST API. These vulnerabilities allow unauthenticated remote attackers to compromise the appliance. Organizations are advised to apply the provided software updates immediately, as no workarounds are available.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
<li>ISE Passive Identity Connector</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-76428">CVE-2026-76428</h2>
<p>Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector are vulnerable to multiple critical security flaws, including authentication bypass, remote code execution (RCE), SQL injection, and XML External Entity (XXE) injection via the REST API. These vulnerabilities allow unauthenticated remote attackers to compromise the appliance. Organizations are advised to apply the provided software updates immediately, as no workarounds are available.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
<li>ISE Passive Identity Connector</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-20352">CVE-2026-20352</h2>
<p>A vulnerability in the RADIUS implementation of Cisco Identity Services Engine (ISE) allows an unauthenticated, remote attacker to trigger a denial of service (DoS) by sending a specially crafted RADIUS request. This exploit can cause the ISE node to become unresponsive, effectively preventing new authentication attempts until the service recovers.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-RADIUS-dos-wR3hYPMw?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20RADIUS%20Denial%20of%20Service%20Vulnerability%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-RADIUS-dos-wR3hYPMw?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20RADIUS%20Denial%20of%20Service%20Vulnerability%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-20295">CVE-2026-20295</h2>
<p>Cisco Secure Firewall Management Center (FMC) and Secure Firewall Threat Defense (FTD) software contain multiple vulnerabilities in the sftunnel component. These vulnerabilities allow an unauthenticated attacker to bypass authentication or trigger a denial of service (DoS) condition on affected devices. There are no known workarounds, and users are advised to apply the software updates provided by Cisco.</p>
<p>Affected products:</p>
<ul>
<li>Secure Firewall Management Center Software</li>
<li>Secure Firewall Threat Defense Software</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmcftd-sftun-multivulns-WGVHOrN3?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20sftunnel%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmcftd-sftun-multivulns-WGVHOrN3?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20sftunnel%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20242">CVE-2026-20242</a>, <a href="#cve-2026-20323">CVE-2026-20323</a>, <a href="#cve-2026-20324">CVE-2026-20324</a>.</p>
<h2 id="cve-2026-20323">CVE-2026-20323</h2>
<p>Cisco Secure Firewall Management Center (FMC) and Secure Firewall Threat Defense (FTD) software contain multiple vulnerabilities in the sftunnel component. These vulnerabilities allow an unauthenticated attacker to bypass authentication or trigger a denial of service (DoS) condition on affected devices. There are no known workarounds, and users are advised to apply the software updates provided by Cisco.</p>
<p>Affected products:</p>
<ul>
<li>Secure Firewall Management Center Software</li>
<li>Secure Firewall Threat Defense Software</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmcftd-sftun-multivulns-WGVHOrN3?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20sftunnel%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmcftd-sftun-multivulns-WGVHOrN3?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20sftunnel%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20242">CVE-2026-20242</a>, <a href="#cve-2026-20295">CVE-2026-20295</a>, <a href="#cve-2026-20324">CVE-2026-20324</a>.</p>
<h2 id="cve-2026-20135">CVE-2026-20135</h2>
<p>A vulnerability in the TLS 1.3 implementation of Cisco Secure Firewall Threat Defense (FTD) Software due to improper buffer management allows an unauthenticated, remote attacker to trigger a crash of the LINA process. Exploitation involves sending a crafted TLS 1.3 packet to a listening socket, resulting in an unexpected device reload and a denial of service condition.</p>
<p>Affected products:</p>
<ul>
<li>Secure Firewall Threat Defense Software</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-tls1.3-dos-dLxwFWgF?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Threat%20Defense%20Software%20TLS%201.3%20Denial%20of%20Service%20Vulnerability%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-tls1.3-dos-dLxwFWgF?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Threat%20Defense%20Software%20TLS%201.3%20Denial%20of%20Service%20Vulnerability%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20290">CVE-2026-20290</a>.</p>
<h2 id="cve-2026-20071">CVE-2026-20071</h2>
<p>Cisco Identity Services Engine (ISE) is affected by multiple vulnerabilities that allow an unauthenticated, local attacker to perform authentication bypass or disclose sensitive information. These issues relate to 802.1X session management and security hardening. Cisco has released software updates to remediate these flaws.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-vuln-kWLeNnRD?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20802.1X%20Session%20Hijack%20and%20Information%20Disclosure%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-vuln-kWLeNnRD?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20802.1X%20Session%20Hijack%20and%20Information%20Disclosure%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-20072">CVE-2026-20072</h2>
<p>Cisco Identity Services Engine (ISE) is affected by multiple vulnerabilities that allow an unauthenticated, local attacker to perform authentication bypass or disclose sensitive information. These issues relate to 802.1X session management and security hardening. Cisco has released software updates to remediate these flaws.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-vuln-kWLeNnRD?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20802.1X%20Session%20Hijack%20and%20Information%20Disclosure%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-vuln-kWLeNnRD?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20802.1X%20Session%20Hijack%20and%20Information%20Disclosure%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-20340">CVE-2026-20340</h2>
<p>Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software allow remote attackers to achieve root-level system access, perform unauthorized sensitive file downloads, execute SQL injection attacks, or trigger denial-of-service conditions. No workarounds are available, necessitating immediate application of vendor-provided software updates.</p>
<p>Affected products:</p>
<ul>
<li>Secure Firewall Management Center</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-mulivulns-4PsnFwvx?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20Software%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-mulivulns-4PsnFwvx?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20Software%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20341">CVE-2026-20341</a>, <a href="#cve-2026-20342">CVE-2026-20342</a>, <a href="#cve-2026-20343">CVE-2026-20343</a>, <a href="#cve-2026-20344">CVE-2026-20344</a>.</p>
<h2 id="cve-2026-20341">CVE-2026-20341</h2>
<p>Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software allow remote attackers to achieve root-level system access, perform unauthorized sensitive file downloads, execute SQL injection attacks, or trigger denial-of-service conditions. No workarounds are available, necessitating immediate application of vendor-provided software updates.</p>
<p>Affected products:</p>
<ul>
<li>Secure Firewall Management Center</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-mulivulns-4PsnFwvx?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20Software%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-mulivulns-4PsnFwvx?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20Software%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20340">CVE-2026-20340</a>, <a href="#cve-2026-20342">CVE-2026-20342</a>, <a href="#cve-2026-20343">CVE-2026-20343</a>, <a href="#cve-2026-20344">CVE-2026-20344</a>.</p>
<h2 id="cve-2026-20342">CVE-2026-20342</h2>
<p>Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software allow remote attackers to achieve root-level system access, perform unauthorized sensitive file downloads, execute SQL injection attacks, or trigger denial-of-service conditions. No workarounds are available, necessitating immediate application of vendor-provided software updates.</p>
<p>Affected products:</p>
<ul>
<li>Secure Firewall Management Center</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-mulivulns-4PsnFwvx?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20Software%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-mulivulns-4PsnFwvx?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20Software%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20340">CVE-2026-20340</a>, <a href="#cve-2026-20341">CVE-2026-20341</a>, <a href="#cve-2026-20343">CVE-2026-20343</a>, <a href="#cve-2026-20344">CVE-2026-20344</a>.</p>
<h2 id="cve-2026-20343">CVE-2026-20343</h2>
<p>Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software allow remote attackers to achieve root-level system access, perform unauthorized sensitive file downloads, execute SQL injection attacks, or trigger denial-of-service conditions. No workarounds are available, necessitating immediate application of vendor-provided software updates.</p>
<p>Affected products:</p>
<ul>
<li>Secure Firewall Management Center</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-mulivulns-4PsnFwvx?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20Software%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-mulivulns-4PsnFwvx?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20Software%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20340">CVE-2026-20340</a>, <a href="#cve-2026-20341">CVE-2026-20341</a>, <a href="#cve-2026-20342">CVE-2026-20342</a>, <a href="#cve-2026-20344">CVE-2026-20344</a>.</p>
<h2 id="cve-2026-20344">CVE-2026-20344</h2>
<p>Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software allow remote attackers to achieve root-level system access, perform unauthorized sensitive file downloads, execute SQL injection attacks, or trigger denial-of-service conditions. No workarounds are available, necessitating immediate application of vendor-provided software updates.</p>
<p>Affected products:</p>
<ul>
<li>Secure Firewall Management Center</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-mulivulns-4PsnFwvx?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20Software%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-mulivulns-4PsnFwvx?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20Software%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20340">CVE-2026-20340</a>, <a href="#cve-2026-20341">CVE-2026-20341</a>, <a href="#cve-2026-20342">CVE-2026-20342</a>, <a href="#cve-2026-20343">CVE-2026-20343</a>.</p>
<h2 id="cve-2026-20248">CVE-2026-20248</h2>
<p>A logic error in the DNS over TCP implementation within Cisco Secure Firewall ASA and FTD software allows an unauthenticated remote attacker to trigger a device reload via a crafted DNS response. This vulnerability requires the attacker to be able to respond to DNS queries from the target device, potentially through a man-in-the-middle position or by controlling the DNS service, resulting in a denial-of-service condition.</p>
<p>Affected products:</p>
<ul>
<li>Secure Firewall Adaptive Security Appliance Software</li>
<li>Secure Firewall Threat Defense Software</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-tcpdns-dos-p6dUnjr5?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Adaptive%20Security%20Appliance%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20TCP%20DNS%20Denial%20of%20Service%20Vulnerability%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-tcpdns-dos-p6dUnjr5?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Adaptive%20Security%20Appliance%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20TCP%20DNS%20Denial%20of%20Service%20Vulnerability%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2024-20260">CVE-2024-20260</a>, <a href="#cve-2026-20120">CVE-2026-20120</a>, <a href="#cve-2026-20121">CVE-2026-20121</a>, <a href="#cve-2026-20222">CVE-2026-20222</a>, <a href="#cve-2026-20154">CVE-2026-20154</a>, <a href="#cve-2026-20249">CVE-2026-20249</a>.</p>
<h2 id="cve-2026-20350">CVE-2026-20350</h2>
<p>Cisco ThousandEyes Virtual Appliance contains an OS command injection vulnerability in its web-based management interface. An authenticated attacker with administrative credentials can supply malicious input during configuration to execute arbitrary commands with root privileges.</p>
<p>Affected products:</p>
<ul>
<li>ThousandEyes Virtual Appliance</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-teva-os-command-W4GAO6jp?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20ThousandEyes%20Virtual%20Appliance%20Authenticated%20Web%20Interface%20Command%20Injection%20Vulnerability%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-teva-os-command-W4GAO6jp?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20ThousandEyes%20Virtual%20Appliance%20Authenticated%20Web%20Interface%20Command%20Injection%20Vulnerability%26vs_k=1</a></p>
<h2 id="cve-2026-20290">CVE-2026-20290</h2>
<p>A vulnerability in the Snort 2 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software arises from incomplete SSL/TLS certificate validation. An unauthenticated remote attacker can exploit this by sending a crafted SSL connection setup request, causing the Snort 2 process to restart unexpectedly and resulting in a denial of service condition.</p>
<p>Affected products:</p>
<ul>
<li>Secure Firewall Threat Defense Software</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-snort2-ssldos-Mw7WYX9c?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Threat%20Defense%20Software%20Snort%202%20SSL/TLS%20Denial%20of%20Service%20Vulnerability%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-snort2-ssldos-Mw7WYX9c?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Threat%20Defense%20Software%20Snort%202%20SSL/TLS%20Denial%20of%20Service%20Vulnerability%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20135">CVE-2026-20135</a>.</p>
<h2 id="cve-2026-76431">CVE-2026-76431</h2>
<p>Multiple path traversal vulnerabilities exist in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), potentially allowing a remote attacker to read or access sensitive files on an affected device. Cisco has released software updates to address these vulnerabilities; there are no known workarounds.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
<li>ISE Passive Identity Connector</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-traversal-WDTgYCdn?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Multiple%20Path%20Traversal%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-traversal-WDTgYCdn?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Multiple%20Path%20Traversal%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-76432">CVE-2026-76432</h2>
<p>Multiple path traversal vulnerabilities exist in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), potentially allowing a remote attacker to read or access sensitive files on an affected device. Cisco has released software updates to address these vulnerabilities; there are no known workarounds.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
<li>ISE Passive Identity Connector</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-traversal-WDTgYCdn?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Multiple%20Path%20Traversal%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-traversal-WDTgYCdn?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Multiple%20Path%20Traversal%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-76433">CVE-2026-76433</h2>
<p>Multiple path traversal vulnerabilities exist in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), potentially allowing a remote attacker to read or access sensitive files on an affected device. Cisco has released software updates to address these vulnerabilities; there are no known workarounds.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
<li>ISE Passive Identity Connector</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-traversal-WDTgYCdn?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Multiple%20Path%20Traversal%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-traversal-WDTgYCdn?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Multiple%20Path%20Traversal%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-76434">CVE-2026-76434</h2>
<p>Multiple path traversal vulnerabilities exist in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), potentially allowing a remote attacker to read or access sensitive files on an affected device. Cisco has released software updates to address these vulnerabilities; there are no known workarounds.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
<li>ISE Passive Identity Connector</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-traversal-WDTgYCdn?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Multiple%20Path%20Traversal%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-traversal-WDTgYCdn?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Multiple%20Path%20Traversal%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-20309">CVE-2026-20309</h2>
<p>Cisco Identity Services Engine (ISE) is vulnerable to a reflected cross-site scripting (XSS) attack due to improper validation of user-supplied input in its web-based management interface. An unauthenticated remote attacker can exploit this by enticing an authenticated user to click a crafted link, potentially allowing the execution of arbitrary script code within the context of the interface or unauthorized access to sensitive browser-based information.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xss-Uz9VWRQ?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Cross-Site%20Scripting%20Vulnerability%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xss-Uz9VWRQ?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Cross-Site%20Scripting%20Vulnerability%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-20120">CVE-2026-20120</h2>
<p>Multiple vulnerabilities in the Object Group Search (OGS) implementation of Cisco Secure Firewall ASA and FTD software allow unauthenticated, remote attackers to bypass access control lists. The vulnerabilities stem from a logic error in how group access control policies are populated, potentially allowing traffic that should be blocked to pass through the device to protected networks.</p>
<p>Affected products:</p>
<ul>
<li>Secure Firewall Adaptive Security Appliance Software</li>
<li>Secure Firewall Threat Defense Software</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-acl-bypass-8p6vFvw?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Adaptive%20Security%20Appliance%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20Object%20Group%20Access%20Control%20List%20Bypass%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-acl-bypass-8p6vFvw?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Adaptive%20Security%20Appliance%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20Object%20Group%20Access%20Control%20List%20Bypass%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2024-20260">CVE-2024-20260</a>, <a href="#cve-2026-20248">CVE-2026-20248</a>, <a href="#cve-2026-20121">CVE-2026-20121</a>, <a href="#cve-2026-20222">CVE-2026-20222</a>, <a href="#cve-2026-20154">CVE-2026-20154</a>, <a href="#cve-2026-20249">CVE-2026-20249</a>.</p>
<h2 id="cve-2026-20121">CVE-2026-20121</h2>
<p>Multiple vulnerabilities in the Object Group Search (OGS) implementation of Cisco Secure Firewall ASA and FTD software allow unauthenticated, remote attackers to bypass access control lists. The vulnerabilities stem from a logic error in how group access control policies are populated, potentially allowing traffic that should be blocked to pass through the device to protected networks.</p>
<p>Affected products:</p>
<ul>
<li>Secure Firewall Adaptive Security Appliance Software</li>
<li>Secure Firewall Threat Defense Software</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-acl-bypass-8p6vFvw?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Adaptive%20Security%20Appliance%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20Object%20Group%20Access%20Control%20List%20Bypass%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-acl-bypass-8p6vFvw?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Adaptive%20Security%20Appliance%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20Object%20Group%20Access%20Control%20List%20Bypass%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2024-20260">CVE-2024-20260</a>, <a href="#cve-2026-20248">CVE-2026-20248</a>, <a href="#cve-2026-20120">CVE-2026-20120</a>, <a href="#cve-2026-20222">CVE-2026-20222</a>, <a href="#cve-2026-20154">CVE-2026-20154</a>, <a href="#cve-2026-20249">CVE-2026-20249</a>.</p>
<h2 id="cve-2026-20285">CVE-2026-20285</h2>
<p>Multiple authorization bypass vulnerabilities exist in the web-based management interface of Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). The vulnerabilities stem from insufficient server-side validation of Administrator permissions. An authenticated remote attacker possessing valid Administrator credentials can exploit these flaws by submitting crafted HTTP requests to modify file descriptions on specific system pages.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
<li>ISE Passive Identity Connector</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-auth-bypass-1-MxcTNgwx?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Authorization%20Bypass%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-auth-bypass-1-MxcTNgwx?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Authorization%20Bypass%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-20286">CVE-2026-20286</h2>
<p>Multiple authorization bypass vulnerabilities exist in the web-based management interface of Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). The vulnerabilities stem from insufficient server-side validation of Administrator permissions. An authenticated remote attacker possessing valid Administrator credentials can exploit these flaws by submitting crafted HTTP requests to modify file descriptions on specific system pages.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
<li>ISE Passive Identity Connector</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-auth-bypass-1-MxcTNgwx?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Authorization%20Bypass%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-auth-bypass-1-MxcTNgwx?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Authorization%20Bypass%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-76438">CVE-2026-76438</h2>
<p>A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software allows authenticated remote attackers with low privileges to bypass authorization checks and modify device configurations via crafted HTTP requests.</p>
<p>Affected products:</p>
<ul>
<li>BroadWorks CommPilot Application Software</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-auth-bypass-broadwor-57m9dmm5?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20BroadWorks%20CommPilot%20Application%20Software%20Authorization%20Bypass%20Vulnerability%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-auth-bypass-broadwor-57m9dmm5?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20BroadWorks%20CommPilot%20Application%20Software%20Authorization%20Bypass%20Vulnerability%26vs_k=1</a></p>
<h2 id="cve-2026-20222">CVE-2026-20222</h2>
<p>A vulnerability in the EIGRP implementation of Cisco Secure Firewall ASA and FTD software allows an unauthenticated, adjacent attacker to trigger a memory leak by sending crafted EIGRP update messages at a high rate. This can lead to an unexpected device reload and a denial of service condition.</p>
<p>Affected products:</p>
<ul>
<li>Secure Firewall Adaptive Security Appliance Software</li>
<li>Secure Firewall Threat Defense Software</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-eigrp-dos-GOhNejSj?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Adaptive%20Security%20Appliance%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20EIGRP%20Denial%20of%20Service%20Vulnerability%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-eigrp-dos-GOhNejSj?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Adaptive%20Security%20Appliance%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20EIGRP%20Denial%20of%20Service%20Vulnerability%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2024-20260">CVE-2024-20260</a>, <a href="#cve-2026-20248">CVE-2026-20248</a>, <a href="#cve-2026-20120">CVE-2026-20120</a>, <a href="#cve-2026-20121">CVE-2026-20121</a>, <a href="#cve-2026-20154">CVE-2026-20154</a>, <a href="#cve-2026-20249">CVE-2026-20249</a>.</p>
<h2 id="cve-2026-20154">CVE-2026-20154</h2>
<p>A denial of service (DoS) vulnerability exists in Cisco Secure Firewall ASA and FTD software due to improper rate limiting for syslog message 419002. An unauthenticated, remote attacker can exploit this by sending a flood of TCP SYN packets, causing high CPU utilization and performance degradation on the affected appliance.</p>
<p>Affected products:</p>
<ul>
<li>Secure Firewall Adaptive Security Appliance Software</li>
<li>Secure Firewall Threat Defense Software</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ftd-logging-dos-ZXXNesfN?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Adaptive%20Security%20Appliance%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20Logging%20Denial%20of%20Service%20Vulnerability%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ftd-logging-dos-ZXXNesfN?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Adaptive%20Security%20Appliance%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20Logging%20Denial%20of%20Service%20Vulnerability%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2024-20260">CVE-2024-20260</a>, <a href="#cve-2026-20248">CVE-2026-20248</a>, <a href="#cve-2026-20120">CVE-2026-20120</a>, <a href="#cve-2026-20121">CVE-2026-20121</a>, <a href="#cve-2026-20222">CVE-2026-20222</a>, <a href="#cve-2026-20249">CVE-2026-20249</a>.</p>
<h2 id="cve-2026-76439">CVE-2026-76439</h2>
<p>Multiple authentication bypass vulnerabilities exist in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). These vulnerabilities could allow a remote attacker to manipulate data, access sensitive information, or trigger a reload of certificate and key material on affected devices. There are no workarounds; patching is required.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
<li>ISE Passive Identity Connector</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiauth-bypass-sgD2HbL4?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Authentication%20Bypass%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiauth-bypass-sgD2HbL4?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Authentication%20Bypass%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-76444">CVE-2026-76444</h2>
<p>Multiple authentication bypass vulnerabilities exist in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). These vulnerabilities could allow a remote attacker to manipulate data, access sensitive information, or trigger a reload of certificate and key material on affected devices. There are no workarounds; patching is required.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
<li>ISE Passive Identity Connector</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiauth-bypass-sgD2HbL4?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Authentication%20Bypass%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiauth-bypass-sgD2HbL4?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Authentication%20Bypass%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-76446">CVE-2026-76446</h2>
<p>Multiple authentication bypass vulnerabilities exist in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). These vulnerabilities could allow a remote attacker to manipulate data, access sensitive information, or trigger a reload of certificate and key material on affected devices. There are no workarounds; patching is required.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
<li>ISE Passive Identity Connector</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiauth-bypass-sgD2HbL4?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Authentication%20Bypass%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiauth-bypass-sgD2HbL4?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Authentication%20Bypass%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-76447">CVE-2026-76447</h2>
<p>Multiple authentication bypass vulnerabilities exist in Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). These vulnerabilities could allow a remote attacker to manipulate data, access sensitive information, or trigger a reload of certificate and key material on affected devices. There are no workarounds; patching is required.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
<li>ISE Passive Identity Connector</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiauth-bypass-sgD2HbL4?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Authentication%20Bypass%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiauth-bypass-sgD2HbL4?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Authentication%20Bypass%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-20249">CVE-2026-20249</h2>
<p>A logic error exists in the IKEv2 certificate authentication process of Cisco Secure Firewall Adaptive Security Appliance (ASA) and Threat Defense (FTD) software. An unauthenticated remote attacker can exploit this by sending a crafted certificate during the IKEv2 connection setup, causing the IKEv2 process to crash and resulting in a device reload and denial of service condition.</p>
<p>Affected products:</p>
<ul>
<li>Secure Firewall Adaptive Security Appliance Software</li>
<li>Secure Firewall Threat Defense Software</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ikev2cert-dos-uWyc2xtv?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Adaptive%20Security%20Appliance%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20IKEv2%20Certificate%20Authentication%20Denial%20of%20Service%20Vulnerability%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ikev2cert-dos-uWyc2xtv?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Adaptive%20Security%20Appliance%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20IKEv2%20Certificate%20Authentication%20Denial%20of%20Service%20Vulnerability%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2024-20260">CVE-2024-20260</a>, <a href="#cve-2026-20248">CVE-2026-20248</a>, <a href="#cve-2026-20120">CVE-2026-20120</a>, <a href="#cve-2026-20121">CVE-2026-20121</a>, <a href="#cve-2026-20222">CVE-2026-20222</a>, <a href="#cve-2026-20154">CVE-2026-20154</a>.</p>
<h2 id="cve-2026-76448">CVE-2026-76448</h2>
<p>Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) contain multiple vulnerabilities due to improper input validation in APIs. An authenticated remote attacker with administrative credentials can exploit these flaws to perform SQL or HQL injection, allowing unauthorized data access or modification in the underlying database.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
<li>ISE Passive Identity Connector</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multisql-inject-JnHK54Rq?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20SQL%20and%20HQL%20Injection%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multisql-inject-JnHK54Rq?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20SQL%20and%20HQL%20Injection%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-76449">CVE-2026-76449</h2>
<p>Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) contain multiple vulnerabilities due to improper input validation in APIs. An authenticated remote attacker with administrative credentials can exploit these flaws to perform SQL or HQL injection, allowing unauthorized data access or modification in the underlying database.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
<li>ISE Passive Identity Connector</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multisql-inject-JnHK54Rq?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20SQL%20and%20HQL%20Injection%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multisql-inject-JnHK54Rq?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20SQL%20and%20HQL%20Injection%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-76450">CVE-2026-76450</h2>
<p>Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) contain multiple vulnerabilities due to improper input validation in APIs. An authenticated remote attacker with administrative credentials can exploit these flaws to perform SQL or HQL injection, allowing unauthorized data access or modification in the underlying database.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
<li>ISE Passive Identity Connector</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multisql-inject-JnHK54Rq?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20SQL%20and%20HQL%20Injection%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multisql-inject-JnHK54Rq?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20SQL%20and%20HQL%20Injection%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-76451">CVE-2026-76451</h2>
<p>Cisco Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) contain multiple vulnerabilities due to improper input validation in APIs. An authenticated remote attacker with administrative credentials can exploit these flaws to perform SQL or HQL injection, allowing unauthorized data access or modification in the underlying database.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
<li>ISE Passive Identity Connector</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multisql-inject-JnHK54Rq?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20SQL%20and%20HQL%20Injection%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multisql-inject-JnHK54Rq?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20SQL%20and%20HQL%20Injection%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-20247">CVE-2026-20247</h2>
<p>Multiple SQL injection vulnerabilities exist in Cisco Identity Services Engine (ISE) that allow a remote attacker to execute arbitrary SQL commands on the affected device. These vulnerabilities are addressed in official software updates provided by Cisco.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-sql-inj-3QTKR947?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20SQL%20Injection%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-sql-inj-3QTKR947?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20SQL%20Injection%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-20300">CVE-2026-20300</h2>
<p>Multiple SQL injection vulnerabilities exist in Cisco Identity Services Engine (ISE) that allow a remote attacker to execute arbitrary SQL commands on the affected device. These vulnerabilities are addressed in official software updates provided by Cisco.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-sql-inj-3QTKR947?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20SQL%20Injection%20Vulnerabilities%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-sql-inj-3QTKR947?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20SQL%20Injection%20Vulnerabilities%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-20324">CVE-2026-20324</h2>
<p>A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software allows an authenticated, remote attacker to execute arbitrary commands as root. The issue stems from improper file system permissions granted to registered sftunnel peers, enabling the writing and subsequent execution of malicious files. Successful exploitation requires valid user credentials on the affected device.</p>
<p>Affected products:</p>
<ul>
<li>Secure Firewall Management Center Software</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-sftunn-codex-c3O4Jft2?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20Software%20sftunnel%20Root%20Arbitrary%20Code%20Execution%20Vulnerability%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-sftunn-codex-c3O4Jft2?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20Software%20sftunnel%20Root%20Arbitrary%20Code%20Execution%20Vulnerability%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20242">CVE-2026-20242</a>, <a href="#cve-2026-20295">CVE-2026-20295</a>, <a href="#cve-2026-20323">CVE-2026-20323</a>.</p>
<h2 id="cve-2026-20235">CVE-2026-20235</h2>
<p>An information disclosure vulnerability in the Cisco Identity Services Engine (ISE) API allows an authenticated remote attacker with administrative credentials to access sensitive data, including hashed credentials, by sending crafted API requests. The vulnerability stems from improper validation of user-supplied parameters.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-inf-disc-LFWvcCu?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Information%20Disclosure%20Vulnerability%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-inf-disc-LFWvcCu?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Information%20Disclosure%20Vulnerability%26vs_k=1</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-20176">CVE-2026-20176</h2>
<p>CVE-2026-20176 is a command injection vulnerability in Cisco Identity Services Engine (ISE) arising from insufficient validation of user-supplied input in HTTP requests. Authenticated, high-privileged remote attackers can leverage this flaw to execute arbitrary system-level commands on the underlying OS, potentially leading to privilege escalation to root or a Denial of Service (DoS) condition on single-node deployments.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20176">https://nvd.nist.gov/vuln/detail/CVE-2026-20176</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20211">CVE-2026-20211</a>.</p>
<h2 id="cve-2026-20211">CVE-2026-20211</h2>
<p>Cisco Identity Services Engine (ISE) is susceptible to a remote code execution vulnerability caused by insecure deserialization of Java objects. An authenticated, high-privileged attacker can exploit this by sending a crafted serialized object to the device, leading to arbitrary command execution on the underlying OS, privilege escalation to root, and potential denial-of-service in single-node deployments.</p>
<p>Affected products:</p>
<ul>
<li>Identity Services Engine</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20211">https://nvd.nist.gov/vuln/detail/CVE-2026-20211</a></p>
<p>Related in this roundup: <a href="#cve-2026-20234">CVE-2026-20234</a>, <a href="#cve-2026-20305">CVE-2026-20305</a>, <a href="#cve-2026-20306">CVE-2026-20306</a>, <a href="#cve-2026-20307">CVE-2026-20307</a>, <a href="#cve-2026-76460">CVE-2026-76460</a>, <a href="#cve-2026-20282">CVE-2026-20282</a>, <a href="#cve-2026-20283">CVE-2026-20283</a>, <a href="#cve-2026-20284">CVE-2026-20284</a>, <a href="#cve-2026-76423">CVE-2026-76423</a>, <a href="#cve-2026-76424">CVE-2026-76424</a>, <a href="#cve-2026-76425">CVE-2026-76425</a>, <a href="#cve-2026-76426">CVE-2026-76426</a>, <a href="#cve-2026-76427">CVE-2026-76427</a>, <a href="#cve-2026-76428">CVE-2026-76428</a>, <a href="#cve-2026-20352">CVE-2026-20352</a>, <a href="#cve-2026-20071">CVE-2026-20071</a>, <a href="#cve-2026-20072">CVE-2026-20072</a>, <a href="#cve-2026-76431">CVE-2026-76431</a>, <a href="#cve-2026-76432">CVE-2026-76432</a>, <a href="#cve-2026-76433">CVE-2026-76433</a>, <a href="#cve-2026-76434">CVE-2026-76434</a>, <a href="#cve-2026-20309">CVE-2026-20309</a>, <a href="#cve-2026-20285">CVE-2026-20285</a>, <a href="#cve-2026-20286">CVE-2026-20286</a>, <a href="#cve-2026-76439">CVE-2026-76439</a>, <a href="#cve-2026-76444">CVE-2026-76444</a>, <a href="#cve-2026-76446">CVE-2026-76446</a>, <a href="#cve-2026-76447">CVE-2026-76447</a>, <a href="#cve-2026-76448">CVE-2026-76448</a>, <a href="#cve-2026-76449">CVE-2026-76449</a>, <a href="#cve-2026-76450">CVE-2026-76450</a>, <a href="#cve-2026-76451">CVE-2026-76451</a>, <a href="#cve-2026-20247">CVE-2026-20247</a>, <a href="#cve-2026-20300">CVE-2026-20300</a>, <a href="#cve-2026-20235">CVE-2026-20235</a>, <a href="#cve-2026-20176">CVE-2026-20176</a>.</p>
<h2 id="cve-2026-20322">CVE-2026-20322</h2>
<p>Cisco Nexus Dashboard contains an improper access control vulnerability (CWE-284) identified during an internal security review. The vulnerability is rated with a CVSS v3.1 base score of 9.9, indicating a high risk of unauthorized access or security bypass.</p>
<p>Affected products:</p>
<ul>
<li>Nexus Dashboard</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20322">https://nvd.nist.gov/vuln/detail/CVE-2026-20322</a></p>
<p>Related in this roundup: <a href="#cve-2026-20325">CVE-2026-20325</a>, <a href="#cve-2026-20326">CVE-2026-20326</a>, <a href="#cve-2026-20361">CVE-2026-20361</a>, <a href="#cve-2026-20360">CVE-2026-20360</a>, <a href="#cve-2026-76409">CVE-2026-76409</a>.</p>
<h2 id="cve-2026-20325">CVE-2026-20325</h2>
<p>CVE-2026-20325 is a critical vulnerability found in Cisco Nexus Dashboard, identified as CWE-77 (Improper Neutralization of Special Elements used in a Command). This vulnerability allows for command injection, potentially enabling an attacker to execute arbitrary commands on the affected system with high privileges.</p>
<p>Affected products:</p>
<ul>
<li>Nexus Dashboard</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20325">https://nvd.nist.gov/vuln/detail/CVE-2026-20325</a></p>
<p>Related in this roundup: <a href="#cve-2026-20322">CVE-2026-20322</a>, <a href="#cve-2026-20326">CVE-2026-20326</a>, <a href="#cve-2026-20361">CVE-2026-20361</a>, <a href="#cve-2026-20360">CVE-2026-20360</a>, <a href="#cve-2026-76409">CVE-2026-76409</a>.</p>
<h2 id="cve-2026-20326">CVE-2026-20326</h2>
<p>CVE-2026-20326 describes a vulnerability in Cisco Nexus Dashboard resulting from missing authentication for critical functions (CWE-306). This flaw allows an unauthenticated, remote attacker to perform unauthorized actions on the affected system, resulting in a CVSS base score of 9.8.</p>
<p>Affected products:</p>
<ul>
<li>Nexus Dashboard</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20326">https://nvd.nist.gov/vuln/detail/CVE-2026-20326</a></p>
<p>Related in this roundup: <a href="#cve-2026-20322">CVE-2026-20322</a>, <a href="#cve-2026-20325">CVE-2026-20325</a>, <a href="#cve-2026-20361">CVE-2026-20361</a>, <a href="#cve-2026-20360">CVE-2026-20360</a>, <a href="#cve-2026-76409">CVE-2026-76409</a>.</p>
<h2 id="cve-2026-20361">CVE-2026-20361</h2>
<p>Cisco Nexus Dashboard contains a vulnerability that allows for SQL injection due to improper input sanitization, potentially permitting an attacker to execute arbitrary SQL commands against the underlying database.</p>
<p>Affected products:</p>
<ul>
<li>Nexus Dashboard</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20361">https://nvd.nist.gov/vuln/detail/CVE-2026-20361</a></p>
<p>Related in this roundup: <a href="#cve-2026-20322">CVE-2026-20322</a>, <a href="#cve-2026-20325">CVE-2026-20325</a>, <a href="#cve-2026-20326">CVE-2026-20326</a>, <a href="#cve-2026-20360">CVE-2026-20360</a>, <a href="#cve-2026-76409">CVE-2026-76409</a>.</p>
<h2 id="cve-2026-20360">CVE-2026-20360</h2>
<p>Cisco Nexus Dashboard contains an information exposure vulnerability (CVE-2026-20360) resulting from insecure handling of data, identified during an internal security review. The vulnerability is classified under CWE-200 and carries a CVSS v3.1 base score of 8.8.</p>
<p>Affected products:</p>
<ul>
<li>Nexus Dashboard</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20360">https://nvd.nist.gov/vuln/detail/CVE-2026-20360</a></p>
<p>Related in this roundup: <a href="#cve-2026-20322">CVE-2026-20322</a>, <a href="#cve-2026-20325">CVE-2026-20325</a>, <a href="#cve-2026-20326">CVE-2026-20326</a>, <a href="#cve-2026-20361">CVE-2026-20361</a>, <a href="#cve-2026-76409">CVE-2026-76409</a>.</p>
<h2 id="cve-2026-76409">CVE-2026-76409</h2>
<p>Cisco Nexus Dashboard contains a vulnerability identified as CVE-2026-76409 related to improper limitation of a pathname (CWE-22). This vulnerability, discovered during an internal security review, requires a software hardening release to mitigate the associated risks, which carry a CVSS v3.1 base score of 8.8.</p>
<p>Affected products:</p>
<ul>
<li>Nexus Dashboard</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-76409">https://nvd.nist.gov/vuln/detail/CVE-2026-76409</a></p>
<p>Related in this roundup: <a href="#cve-2026-20322">CVE-2026-20322</a>, <a href="#cve-2026-20325">CVE-2026-20325</a>, <a href="#cve-2026-20326">CVE-2026-20326</a>, <a href="#cve-2026-20361">CVE-2026-20361</a>, <a href="#cve-2026-20360">CVE-2026-20360</a>.</p>
<h2 id="cve-2026-76412">CVE-2026-76412</h2>
<p>A privilege escalation vulnerability exists in the remote diagnostics debugger of Cisco Secure FMC Software. An authenticated remote attacker can exploit an improper privilege check during the invocation of the diagnostics debugger to elevate their privileges to root. The exploit requires valid credentials and a complex, multistage execution process.</p>
<p>Affected products:</p>
<ul>
<li>Secure FMC Software</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-76412">https://nvd.nist.gov/vuln/detail/CVE-2026-76412</a></p>
<p>Related in this roundup: <a href="#cve-2026-76420">CVE-2026-76420</a>.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>roundup</category></item></channel></rss>