Product
Critical Vulnerabilities Patched in Cisco FMC, ISE, and Nexus Dashboard
2 TTPs 3 CVEsCisco has released emergency patches for dozens of critical vulnerabilities across Identity Services Engine (ISE), Secure Firewall Management Center (FMC), and Nexus Dashboard, including several flaws currently exploited in the wild.
Active Exploitation of Cisco Secure Firewall Management Center
5 TTPs 2 CVEs 1 IOCMultiple threat actors, including state-sponsored groups and ransomware operators, are actively exploiting authentication bypass (CVE-2026-20079) and static credential (CVE-2026-20316) vulnerabilities in Cisco Secure Firewall Management Center to achieve root-level code execution and deploy malware.
Denial of Service Vulnerability in Cisco ASA and FTD
1 CVEA vulnerability in the web-based management interface of Cisco ASA and Secure Firewall Threat Defense allows an unauthenticated, remote attacker to trigger a device crash via crafted HTTP requests.
Active Exploitation of CVE-2026-20349 in Cisco Secure Firewall
1 TTP 1 CVECisco Secure Firewall ASA and FTD devices are subject to active exploitation of a zero-day vulnerability, CVE-2026-20349, which allows remote, unauthenticated attackers to cause a denial-of-service condition via crafted HTTP requests.
Prohibited Network Traffic Allowed
2 rules 1 TTPThis analytic detects instances where prohibited network traffic is allowed, highlighting potential misconfigurations or policy violations that could lead to unauthorized access or data exfiltration, ultimately allowing attackers to bypass network defenses.
Cisco Privileged Account Creation with Suspicious SSH Activity
3 rules 2 TTPsThis analytic detects a correlation between privileged account creation on Cisco IOS devices and subsequent inbound SSH connections to non-standard ports or sshd_operns, indicating persistence establishment following initial compromise.
Cisco Secure Firewall - High Volume of Intrusion Events Per Host
2 rules 3 TTPsThis analytic detects internal systems generating an unusually high volume of intrusion detections within a 30-minute window using Cisco Secure Firewall Threat Defense logs, identifying hosts triggering more than 15 Snort-based signatures, which may indicate suspicious activity like malware execution, command-and-control communication, vulnerability scanning, or lateral movement.
Multiple Vulnerabilities in Cisco Products Allow for Remote Code Execution
2 rules 4 TTPs 3 CVEsMultiple vulnerabilities in Cisco ASA, Secure Firewall Threat Defense, IOS, IOS XE, and IOS XR allow a remote attacker to bypass authentication and execute arbitrary code with administrator privileges.
Outbound SMB Traffic Detection
2 rules 1 TTPThis analytic detects outbound SMB connections from internal hosts to external servers, potentially indicating lateral movement and credential theft attempts.