<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>IOS XE Software - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/ios-xe-software/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 05 Aug 2026 17:20:12 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/ios-xe-software/feed.xml" rel="self" type="application/rss+xml"/><item><title>Cisco Security Updates - August 2026</title><link>https://feed.craftedsignal.io/briefs/2026-08-cisco-security-updates/</link><pubDate>Wed, 05 Aug 2026 17:20:12 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-cisco-security-updates/</guid><description>Roundup of Cisco security advisories published in August 2026.</description><content:encoded><![CDATA[<p>This roundup covers 19 Cisco security vulnerabilities. None are reported as actively exploited at the time of release. The issues affect Catalyst SD-WAN, Catalyst SD-WAN Manager, IOS Software, IOS XE Software, Integrated Management Controller, RoomOS, Terminal Services Agent.</p>
<h2 id="summary">Summary</h2>
<table>
	<thead>
			<tr>
					<th>CVE</th>
					<th>CVSS</th>
					<th>Product</th>
					<th>Summary</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td>CVE-2026-20267</td>
					<td>9.0</td>
					<td>IOS XE Software</td>
					<td>Cisco IOS XE Software contains multiple internally discovered vulnerabilities characterized by improper access control (CWE-284). These vulnerabilities were identified during an internal security review and addressed through software hardening releases, carrying a CVSS base score of 9.0.</td>
			</tr>
			<tr>
					<td>CVE-2026-20272</td>
					<td>9.8</td>
					<td>IOS XE Software</td>
					<td>CVE-2026-20272 represents a critical vulnerability in Cisco IOS XE Software, identified through internal security reviews as an issue involving improper neutralization of special elements, classified under CWE-74. With a CVSS base score of 9.8, the vulnerability allows for potential remote command injection, requiring immediate patching as part of Cisco's software hardening releases.</td>
			</tr>
			<tr>
					<td>CVE-2026-20310</td>
					<td>9.1</td>
					<td>Catalyst SD-WAN</td>
					<td>Cisco Catalyst SD-WAN is affected by a vulnerability (CVE-2026-20310) resulting from improper link resolution before file access, categorized as CWE-59. This internally discovered issue prompted security hardening updates for the affected platform.</td>
			</tr>
			<tr>
					<td>CVE-2026-20124</td>
					<td>0.0</td>
					<td>IOS XE Software</td>
					<td>CVE-2026-20124 is a denial of service vulnerability in the SNMP subsystem of Cisco IOS XE Software. An authenticated remote attacker with valid SNMP community strings (v1/v2c) or credentials (v3) can send a malformed SNMP request, causing the device to unexpectedly reload. Detection should focus on monitoring SNMP request traffic for anomalies or malformed packets targeting the SNMP subsystem.</td>
			</tr>
			<tr>
					<td>CVE-2026-20200</td>
					<td>8.8</td>
					<td>Integrated Management Controller</td>
					<td>Cisco IMC contains a vulnerability in its web-based management interface stemming from improper input validation. An authenticated remote attacker with low privileges can leverage this flaw to perform command injection, resulting in the execution of arbitrary commands with root-level privileges on the underlying operating system.</td>
			</tr>
			<tr>
					<td>CVE-2026-20263</td>
					<td>8.6</td>
					<td>IOS XE Software</td>
					<td>A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software allows unauthenticated remote attackers to trigger a device reload via a crafted BEEP SOAP request, resulting in a denial-of-service (DoS) condition.</td>
			</tr>
			<tr>
					<td>CVE-2026-20268</td>
					<td>8.6</td>
					<td>IOS XE Software</td>
					<td>Cisco IOS XE Software contains vulnerabilities related to improper restriction of operations within the bounds of a memory buffer, categorized under CWE-119. These issues were discovered during an internal security review and addressed via software hardening releases, carrying a CVSS v3.1 base score of 8.6.</td>
			</tr>
			<tr>
					<td>CVE-2026-20269</td>
					<td>8.6</td>
					<td>IOS XE Software</td>
					<td>Cisco IOS XE Software contains multiple internally discovered vulnerabilities related to improper control of a resource through its lifetime, classified under CWE-664. These issues were identified during a proactive internal security review and have been addressed in software hardening releases.</td>
			</tr>
			<tr>
					<td>CVE-2026-20271</td>
					<td>0.0</td>
					<td>IOS XE Software</td>
					<td>Cisco IOS XE Software contains multiple vulnerabilities related to insufficient control flow management, categorized under CWE-691. These vulnerabilities were identified through an internal security review, and Cisco has released software updates to address the underlying issues.</td>
			</tr>
			<tr>
					<td>CVE-2026-20273</td>
					<td>8.6</td>
					<td>IOS XE Software</td>
					<td>CVE-2026-20273 refers to an improper input validation vulnerability (CWE-20) in Cisco IOS XE Software. With a CVSS base score of 8.6, this vulnerability is exploitable remotely by an unauthenticated attacker, potentially leading to a denial-of-service condition (AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H).</td>
			</tr>
			<tr>
					<td>CVE-2026-20301</td>
					<td>8.6</td>
					<td>IOS Software</td>
					<td>A vulnerability in the Extensible Messaging Client Protocol (XMCP) implementation within Cisco IOS and IOS XE software allows unauthenticated, remote attackers to trigger a device reload via malformed packets, resulting in a denial-of-service condition.</td>
			</tr>
			<tr>
					<td>CVE-2026-20312</td>
					<td>0.0</td>
					<td>Catalyst SD-WAN</td>
					<td>Cisco Catalyst SD-WAN software contains a vulnerability identified as CVE-2026-20312 involving the cleartext storage of sensitive information, classified under CWE-312. This vulnerability was identified during an internal security review and addressed through a software hardening release.</td>
			</tr>
			<tr>
					<td>CVE-2026-20313</td>
					<td>7.7</td>
					<td>Catalyst SD-WAN</td>
					<td>Cisco Catalyst SD-WAN is affected by a vulnerability involving improper link resolution before file access, categorized under CWE-1284. This vulnerability was identified during an internal security review and addressed via software hardening releases.</td>
			</tr>
			<tr>
					<td>CVE-2026-20311</td>
					<td>6.3</td>
					<td>IOS XE Software</td>
					<td>A vulnerability in the web-based management interface of Cisco IOS XE Software allows an authenticated, low-privileged remote attacker to trigger a denial-of-service condition. By submitting a malformed certificate to the interface, an attacker can cause the device to reload, resulting in an unexpected service disruption. Cisco has released software updates to address this flaw.</td>
			</tr>
			<tr>
					<td>CVE-2026-20198</td>
					<td>0.0</td>
					<td>Integrated Management Controller</td>
					<td>A cross-site scripting (XSS) vulnerability exists in the web-based management interface of the Cisco Integrated Management Controller due to improper input validation. An authenticated remote attacker can exploit this by convincing a user to interact with a malicious link, potentially leading to arbitrary script execution within the victim's browser context.</td>
			</tr>
			<tr>
					<td>CVE-2026-20289</td>
					<td>0.0</td>
					<td>RoomOS</td>
					<td>A vulnerability in the logging subsystem of Cisco RoomOS allows an authenticated, local attacker with low privileges to access sensitive information, such as user login credentials, by enabling specific logging levels and accessing system logs. There are no workarounds available, and patching is required.</td>
			</tr>
			<tr>
					<td>CVE-2026-20294</td>
					<td>0.0</td>
					<td>Catalyst SD-WAN Manager</td>
					<td>An information disclosure vulnerability exists in the web-based management interface of Cisco Catalyst SD-WAN Manager due to insufficient access control on specific template types. Authenticated attackers with low privileges can exploit this to view sensitive authentication credentials in clear text within local or remote logs, potentially leading to escalation of privilege and further infrastructure compromise.</td>
			</tr>
			<tr>
					<td>CVE-2026-20028</td>
					<td>0.0</td>
					<td>Terminal Services Agent</td>
					<td>A vulnerability in the Cisco Terminal Services Agent network driver allows an authenticated remote attacker with user-level credentials to bypass firewall rules by incorrectly mapping network connections to user accounts, effectively inheriting the firewall policy of another user.</td>
			</tr>
			<tr>
					<td>CVE-2026-20308</td>
					<td>0.0</td>
					<td>IOS XE Software</td>
					<td>An authenticated remote attacker with low privileges can trigger a denial of service (DoS) condition in the web-based management interface of Cisco IOS XE Software by sending crafted input, resulting in the interface becoming unresponsive due to insufficient input validation.</td>
			</tr>
	</tbody>
</table>
<h2 id="cve-2026-20267">CVE-2026-20267</h2>
<p>Cisco IOS XE Software contains multiple internally discovered vulnerabilities characterized by improper access control (CWE-284). These vulnerabilities were identified during an internal security review and addressed through software hardening releases, carrying a CVSS base score of 9.0.</p>
<p>Affected products:</p>
<ul>
<li>IOS XE Software</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20267">https://nvd.nist.gov/vuln/detail/CVE-2026-20267</a></p>
<h2 id="cve-2026-20272">CVE-2026-20272</h2>
<p>CVE-2026-20272 represents a critical vulnerability in Cisco IOS XE Software, identified through internal security reviews as an issue involving improper neutralization of special elements, classified under CWE-74. With a CVSS base score of 9.8, the vulnerability allows for potential remote command injection, requiring immediate patching as part of Cisco's software hardening releases.</p>
<p>Affected products:</p>
<ul>
<li>IOS XE Software</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20272">https://nvd.nist.gov/vuln/detail/CVE-2026-20272</a></p>
<h2 id="cve-2026-20310">CVE-2026-20310</h2>
<p>Cisco Catalyst SD-WAN is affected by a vulnerability (CVE-2026-20310) resulting from improper link resolution before file access, categorized as CWE-59. This internally discovered issue prompted security hardening updates for the affected platform.</p>
<p>Affected products:</p>
<ul>
<li>Catalyst SD-WAN</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20310">https://nvd.nist.gov/vuln/detail/CVE-2026-20310</a></p>
<h2 id="cve-2026-20124">CVE-2026-20124</h2>
<p>CVE-2026-20124 is a denial of service vulnerability in the SNMP subsystem of Cisco IOS XE Software. An authenticated remote attacker with valid SNMP community strings (v1/v2c) or credentials (v3) can send a malformed SNMP request, causing the device to unexpectedly reload. Detection should focus on monitoring SNMP request traffic for anomalies or malformed packets targeting the SNMP subsystem.</p>
<p>Affected products:</p>
<ul>
<li>IOS XE Software</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20124">https://nvd.nist.gov/vuln/detail/CVE-2026-20124</a></p>
<h2 id="cve-2026-20200">CVE-2026-20200</h2>
<p>Cisco IMC contains a vulnerability in its web-based management interface stemming from improper input validation. An authenticated remote attacker with low privileges can leverage this flaw to perform command injection, resulting in the execution of arbitrary commands with root-level privileges on the underlying operating system.</p>
<p>Affected products:</p>
<ul>
<li>Integrated Management Controller</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20200">https://nvd.nist.gov/vuln/detail/CVE-2026-20200</a></p>
<h2 id="cve-2026-20263">CVE-2026-20263</h2>
<p>A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software allows unauthenticated remote attackers to trigger a device reload via a crafted BEEP SOAP request, resulting in a denial-of-service (DoS) condition.</p>
<p>Affected products:</p>
<ul>
<li>IOS XE Software</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20263">https://nvd.nist.gov/vuln/detail/CVE-2026-20263</a></p>
<h2 id="cve-2026-20268">CVE-2026-20268</h2>
<p>Cisco IOS XE Software contains vulnerabilities related to improper restriction of operations within the bounds of a memory buffer, categorized under CWE-119. These issues were discovered during an internal security review and addressed via software hardening releases, carrying a CVSS v3.1 base score of 8.6.</p>
<p>Affected products:</p>
<ul>
<li>IOS XE Software</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20268">https://nvd.nist.gov/vuln/detail/CVE-2026-20268</a></p>
<h2 id="cve-2026-20269">CVE-2026-20269</h2>
<p>Cisco IOS XE Software contains multiple internally discovered vulnerabilities related to improper control of a resource through its lifetime, classified under CWE-664. These issues were identified during a proactive internal security review and have been addressed in software hardening releases.</p>
<p>Affected products:</p>
<ul>
<li>IOS XE Software</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20269">https://nvd.nist.gov/vuln/detail/CVE-2026-20269</a></p>
<h2 id="cve-2026-20271">CVE-2026-20271</h2>
<p>Cisco IOS XE Software contains multiple vulnerabilities related to insufficient control flow management, categorized under CWE-691. These vulnerabilities were identified through an internal security review, and Cisco has released software updates to address the underlying issues.</p>
<p>Affected products:</p>
<ul>
<li>IOS XE Software</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20271">https://nvd.nist.gov/vuln/detail/CVE-2026-20271</a></p>
<h2 id="cve-2026-20273">CVE-2026-20273</h2>
<p>CVE-2026-20273 refers to an improper input validation vulnerability (CWE-20) in Cisco IOS XE Software. With a CVSS base score of 8.6, this vulnerability is exploitable remotely by an unauthenticated attacker, potentially leading to a denial-of-service condition (AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H).</p>
<p>Affected products:</p>
<ul>
<li>IOS XE Software</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20273">https://nvd.nist.gov/vuln/detail/CVE-2026-20273</a></p>
<h2 id="cve-2026-20301">CVE-2026-20301</h2>
<p>A vulnerability in the Extensible Messaging Client Protocol (XMCP) implementation within Cisco IOS and IOS XE software allows unauthenticated, remote attackers to trigger a device reload via malformed packets, resulting in a denial-of-service condition.</p>
<p>Affected products:</p>
<ul>
<li>IOS Software</li>
<li>IOS XE Software</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20301">https://nvd.nist.gov/vuln/detail/CVE-2026-20301</a></p>
<h2 id="cve-2026-20312">CVE-2026-20312</h2>
<p>Cisco Catalyst SD-WAN software contains a vulnerability identified as CVE-2026-20312 involving the cleartext storage of sensitive information, classified under CWE-312. This vulnerability was identified during an internal security review and addressed through a software hardening release.</p>
<p>Affected products:</p>
<ul>
<li>Catalyst SD-WAN</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20312">https://nvd.nist.gov/vuln/detail/CVE-2026-20312</a></p>
<h2 id="cve-2026-20313">CVE-2026-20313</h2>
<p>Cisco Catalyst SD-WAN is affected by a vulnerability involving improper link resolution before file access, categorized under CWE-1284. This vulnerability was identified during an internal security review and addressed via software hardening releases.</p>
<p>Affected products:</p>
<ul>
<li>Catalyst SD-WAN</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20313">https://nvd.nist.gov/vuln/detail/CVE-2026-20313</a></p>
<h2 id="cve-2026-20311">CVE-2026-20311</h2>
<p>A vulnerability in the web-based management interface of Cisco IOS XE Software allows an authenticated, low-privileged remote attacker to trigger a denial-of-service condition. By submitting a malformed certificate to the interface, an attacker can cause the device to reload, resulting in an unexpected service disruption. Cisco has released software updates to address this flaw.</p>
<p>Affected products:</p>
<ul>
<li>IOS XE Software</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-xe-webui-dos-PtAODAWW?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20IOS%20XE%20Software%20Web-Based%20Management%20Interface%20Denial%20of%20Service%20Vulnerability%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-xe-webui-dos-PtAODAWW?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20IOS%20XE%20Software%20Web-Based%20Management%20Interface%20Denial%20of%20Service%20Vulnerability%26vs_k=1</a></p>
<h2 id="cve-2026-20198">CVE-2026-20198</h2>
<p>A cross-site scripting (XSS) vulnerability exists in the web-based management interface of the Cisco Integrated Management Controller due to improper input validation. An authenticated remote attacker can exploit this by convincing a user to interact with a malicious link, potentially leading to arbitrary script execution within the victim's browser context.</p>
<p>Affected products:</p>
<ul>
<li>Integrated Management Controller</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-xss-7EhBFxBp?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Integrated%20Management%20Controller%20Cross-Site%20Scripting%20Vulnerability%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-xss-7EhBFxBp?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Integrated%20Management%20Controller%20Cross-Site%20Scripting%20Vulnerability%26vs_k=1</a></p>
<h2 id="cve-2026-20289">CVE-2026-20289</h2>
<p>A vulnerability in the logging subsystem of Cisco RoomOS allows an authenticated, local attacker with low privileges to access sensitive information, such as user login credentials, by enabling specific logging levels and accessing system logs. There are no workarounds available, and patching is required.</p>
<p>Affected products:</p>
<ul>
<li>RoomOS</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-infodisc-qBXjfmWm?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20RoomOS%20Logging%20Subsystem%20Information%20Disclosure%20Vulnerability%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-infodisc-qBXjfmWm?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20RoomOS%20Logging%20Subsystem%20Information%20Disclosure%20Vulnerability%26vs_k=1</a></p>
<h2 id="cve-2026-20294">CVE-2026-20294</h2>
<p>An information disclosure vulnerability exists in the web-based management interface of Cisco Catalyst SD-WAN Manager due to insufficient access control on specific template types. Authenticated attackers with low privileges can exploit this to view sensitive authentication credentials in clear text within local or remote logs, potentially leading to escalation of privilege and further infrastructure compromise.</p>
<p>Affected products:</p>
<ul>
<li>Catalyst SD-WAN Manager</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-infodis-SPuJBDCe?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Catalyst%20SD-WAN%20Manager%20Information%20Disclosure%20Vulnerability%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-infodis-SPuJBDCe?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Catalyst%20SD-WAN%20Manager%20Information%20Disclosure%20Vulnerability%26vs_k=1</a></p>
<h2 id="cve-2026-20028">CVE-2026-20028</h2>
<p>A vulnerability in the Cisco Terminal Services Agent network driver allows an authenticated remote attacker with user-level credentials to bypass firewall rules by incorrectly mapping network connections to user accounts, effectively inheriting the firewall policy of another user.</p>
<p>Affected products:</p>
<ul>
<li>Terminal Services Agent</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ts-agent-fw-bypass-MYBTMrev?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Terminal%20Services%20Agent%20Firewall%20Rules%20Bypass%20Vulnerability%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ts-agent-fw-bypass-MYBTMrev?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Terminal%20Services%20Agent%20Firewall%20Rules%20Bypass%20Vulnerability%26vs_k=1</a></p>
<h2 id="cve-2026-20308">CVE-2026-20308</h2>
<p>An authenticated remote attacker with low privileges can trigger a denial of service (DoS) condition in the web-based management interface of Cisco IOS XE Software by sending crafted input, resulting in the interface becoming unresponsive due to insufficient input validation.</p>
<p>Affected products:</p>
<ul>
<li>IOS XE Software</li>
</ul>
<p>Source: <a href="https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webui-dos-qdc7qx3?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20IOS%20XE%20Software%20Web-Based%20Management%20Interface%20Denial%20of%20Service%20Vulnerability%26vs_k=1">https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webui-dos-qdc7qx3?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20IOS%20XE%20Software%20Web-Based%20Management%20Interface%20Denial%20of%20Service%20Vulnerability%26vs_k=1</a></p>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>roundup</category></item></channel></rss>