Skip to content
Threat Feed

Product

Secure Firewall Threat Defense

9 briefs RSS
critical threat

Critical Vulnerabilities Patched in Cisco FMC, ISE, and Nexus Dashboard

Cisco has released emergency patches for dozens of critical vulnerabilities across Identity Services Engine (ISE), Secure Firewall Management Center (FMC), and Nexus Dashboard, including several flaws currently exploited in the wild.

exploited Secure Firewall Management Center +4 vulnerability cisco network-security patch-management
2t 3c
critical threat

Active Exploitation of Cisco Secure Firewall Management Center

Multiple threat actors, including state-sponsored groups and ransomware operators, are actively exploiting authentication bypass (CVE-2026-20079) and static credential (CVE-2026-20316) vulnerabilities in Cisco Secure Firewall Management Center to achieve root-level code execution and deploy malware.

exploited Secure Firewall Management Center +1 cisco fmc exploitation cve-2026-20079 cve-2026-20316 ransomware apt
5t 2c 1i updated
low advisory

Denial of Service Vulnerability in Cisco ASA and FTD

A vulnerability in the web-based management interface of Cisco ASA and Secure Firewall Threat Defense allows an unauthenticated, remote attacker to trigger a device crash via crafted HTTP requests.

Adaptive Security Appliance +1 denial-of-service networking security-appliance
1c
critical threat

Active Exploitation of CVE-2026-20349 in Cisco Secure Firewall

Cisco Secure Firewall ASA and FTD devices are subject to active exploitation of a zero-day vulnerability, CVE-2026-20349, which allows remote, unauthenticated attackers to cause a denial-of-service condition via crafted HTTP requests.

exploited Secure Firewall Adaptive Security Appliance +1
1t 1c
high advisory

Prohibited Network Traffic Allowed

This analytic detects instances where prohibited network traffic is allowed, highlighting potential misconfigurations or policy violations that could lead to unauthorized access or data exfiltration, ultimately allowing attackers to bypass network defenses.

Secure Firewall Threat Defense +3 network policy-violation firewall traffic-monitoring
2r 1t
high advisory

Cisco Privileged Account Creation with Suspicious SSH Activity

This analytic detects a correlation between privileged account creation on Cisco IOS devices and subsequent inbound SSH connections to non-standard ports or sshd_operns, indicating persistence establishment following initial compromise.

IOS +4 network persistence initial-access
3r 2t
medium threat

Cisco Secure Firewall - High Volume of Intrusion Events Per Host

This analytic detects internal systems generating an unusually high volume of intrusion detections within a 30-minute window using Cisco Secure Firewall Threat Defense logs, identifying hosts triggering more than 15 Snort-based signatures, which may indicate suspicious activity like malware execution, command-and-control communication, vulnerability scanning, or lateral movement.

exploited Secure Firewall Threat Defense +3 network intrusion_detection anomaly_detection
2r 3t
critical advisory

Multiple Vulnerabilities in Cisco Products Allow for Remote Code Execution

Multiple vulnerabilities in Cisco ASA, Secure Firewall Threat Defense, IOS, IOS XE, and IOS XR allow a remote attacker to bypass authentication and execute arbitrary code with administrator privileges.

ASA +4 cisco vulnerability rce authentication-bypass
2r 4t 3c
high advisory

Outbound SMB Traffic Detection

This analytic detects outbound SMB connections from internal hosts to external servers, potentially indicating lateral movement and credential theft attempts.

Secure Firewall Threat Defense +4 network smb lateral-movement privilege-escalation
2r 1t