<?xml version="1.0" encoding="utf-8" ?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
  <!-- I2R 9899 -->
  
    
    <title>Cisco Security Advisory</title>
    
  
   
   
    
    
    
    <link>http://sec.cloudapps.cisco.com/security/center/psirtrss20/CiscoSecurityAdvisory.xml</link>
    
    <description>
    	
    </description>
    <language>en-us</language>
    <copyright>
         1992-2010 Cisco Systems, Inc. All rights reserved.
    </copyright>
    <category>Cisco Security Advisory</category> 
    <generator>
    	Cisco Systems, Inc.
    </generator>
    <atom:link href="http://sec.cloudapps.cisco.com/security/center/psirtrss20/CiscoSecurityAdvisory.xml" rel="self" type="application/rss+xml" ></atom:link>
    <ttl>15</ttl>

    
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Catalyst%20SD-WAN%20Controller%20Authentication%20Bypass%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;&lt;strong&gt;May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the &lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa-EHchtZk&#034;&gt;Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability&lt;/a&gt; was disclosed in February 2026. This new advisory is for a new vulnerability in the control connection handshaking. The &lt;a href=&#034;#IOC&#034;&gt;Indicators of Compromise&lt;/a&gt; section of this advisory includes Show Control Connections guidance to help with system checks.&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.&lt;/p&gt;
&lt;p&gt;This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to the affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-&lt;em&gt;root&lt;/em&gt; user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.&lt;/p&gt;

&lt;p&gt;Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Important: &lt;/strong&gt;To preserve possible indicators of compromise, &lt;span class=&#034;more&#034;&gt;customers should issue the &lt;a href=&#034;https://www.cisco.com/c/en/us/support/docs/routers/sd-wan/225842-remediate-catalyst-sd-wan-security.html&#034; target=&#034;_blank&#034; rel=&#034;noopener&#034;&gt;&lt;strong&gt;request admin-tech&lt;/strong&gt;&lt;/a&gt; command from each of the control components in the SD-WAN deployment before upgrading. After the &lt;em&gt;admin-tech&lt;/em&gt; file has been collected,&lt;/span&gt; software should be upgraded at the earliest opportunity.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a id=&#034;u_psirt_publication.u_public_url_link&#034; class=&#034;web web-inline form-control-static&#034; tabindex=&#034;0&#034; href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW&#034; target=&#034;_blank&#034; rel=&#034;noopener&#034; name=&#034;u_psirt_publication.u_public_url_link&#034; aria-hidden=&#034;false&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW&lt;/a&gt;&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Critical
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20182
		    
         </description>
          
		  <pubDate>2026-05-14 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-rpa2-v69WY2SW</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco Catalyst SD-WAN Manager Vulnerabilities</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-mltvnps2-JxpWm7R?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Catalyst%20SD-WAN%20Manager%20Vulnerabilities%26vs_k=1</link>
          
          <description>
			&lt;p&gt;Multiple vulnerabilities in Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow a remote attacker to&amp;nbsp;gain access to sensitive information, elevate privileges, or gain unauthorized access to the application.&lt;/p&gt;
&lt;p&gt;For more information about these vulnerabilities, see the &lt;a href=&#034;#details&#034;&gt;Details&lt;/a&gt; section of this advisory.&lt;/p&gt;
&lt;p&gt;Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.&lt;/p&gt;
&lt;p&gt;Cisco strongly recommends that customers upgrade to the fixed software indicated in this advisory.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-mltvnps2-JxpWm7R&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-mltvnps2-JxpWm7R&lt;/a&gt;&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Critical
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20209,CVE-2026-20210,CVE-2026-20224
		    
         </description>
          
		  <pubDate>2026-05-14 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-mltvnps2-JxpWm7R</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco Crosswork Network Controller and Cisco Network Services Orchestrator Advisory</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nso-dos-7Egqyc?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Crosswork%20Network%20Controller%20and%20Cisco%20Network%20Services%20Orchestrator%20Advisory%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;Following the initial publication of the Security Advisory about a denial of service (DoS) condition in Cisco Crosswork Network Controller and Cisco Network Services Orchestrator (NSO), additional information has been made available to the Cisco Product Security Incident Response Team (PSIRT).&lt;/p&gt;
&lt;p&gt;Upon further analysis, the Cisco PSIRT has reclassified this issue as a customer-configurable, resource management issue rather than a security vulnerability.&lt;/p&gt;

&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nso-dos-7Egqyc&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nso-dos-7Egqyc&lt;/a&gt;&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Informational
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20188
		    
         </description>
          
		  <pubDate>2026-05-14 15:56:13.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nso-dos-7Egqyc</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco Unity Connection Remote Code Execution and Server-Side Request Forgery Vulnerabilities</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-unity-rce-ssrf-hENhuASy?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Unity%20Connection%20Remote%20Code%20Execution%20and%20Server-Side%20Request%20Forgery%20Vulnerabilities%26vs_k=1</link>
          
          <description>
			&lt;p&gt;Multiple vulnerabilities in Cisco Unity Connection could allow a remote attacker to execute arbitrary code on&amp;nbsp;or conduct server-side request forgery (SSRF) attacks through an affected device.&lt;/p&gt;
&lt;p&gt;For more information about these vulnerabilities, see the &lt;a href=&#034;#details&#034;&gt;Details&lt;/a&gt; section of this advisory.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-unity-rce-ssrf-hENhuASy&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-unity-rce-ssrf-hENhuASy&lt;/a&gt;&lt;/p&gt;

			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  High
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20034,CVE-2026-20035
		    
         </description>
          
		  <pubDate>2026-05-06 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-unity-rce-ssrf-hENhuASy</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco Enterprise Chat and Email Lite Agent File Upload Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ece-lite-agent-BCgSN8eb?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Enterprise%20Chat%20and%20Email%20Lite%20Agent%20File%20Upload%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;A vulnerability in the Lite Agent feature of Cisco Enterprise Chat and Email (ECE) could allow an authenticated, remote attacker to conduct browser-based attacks. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of &lt;em&gt;Agent&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;This vulnerability is due to inadequate validation of file contents during file upload operations. An attacker could exploit this vulnerability by uploading a file that contains malicious scripts or HTML code, which the application could make available to other users to access. A successful exploit could allow the attacker to execute the contents of that file in the browser of a user and conduct browser-based attacks.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ece-lite-agent-BCgSN8eb&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ece-lite-agent-BCgSN8eb&lt;/a&gt;&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Medium
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20172
		    
         </description>
          
		  <pubDate>2026-05-06 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ece-lite-agent-BCgSN8eb</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco Identity Services Engine Authentication Bypass Vulnerabilities</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-bypass-uxjRXGpb?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Authentication%20Bypass%20Vulnerabilities%26vs_k=1</link>
          
          <description>
			&lt;p&gt;Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow a remote attacker to bypass authorization mechanisms or examine error messages to gain access to sensitive information on an affected device.&lt;/p&gt;
&lt;p&gt;For more information about these vulnerabilities, see the &lt;a href=&#034;#details&#034;&gt;Details&lt;/a&gt; section of this advisory.&lt;/p&gt;
&lt;p&gt;Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-bypass-uxjRXGpb&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-bypass-uxjRXGpb&lt;/a&gt;&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Medium
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20193,CVE-2026-20195
		    
         </description>
          
		  <pubDate>2026-05-06 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-unauth-bypass-uxjRXGpb</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco Prime Infrastructure Information Disclosure Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-pi-unauth-infodiscl-LFnLgmey?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Prime%20Infrastructure%20Information%20Disclosure%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;A vulnerability in the log file download functionality of Cisco Prime Infrastructure could allow an&amp;nbsp;authenticated, remote attacker to download arbitrary log files from the server.&lt;/p&gt;
&lt;p&gt;This vulnerability is due to insufficient authorization checks on the download service API. An attacker could exploit this vulnerability by submitting a crafted URL request to an affected device. A successful exploit could allow the attacker to download sensitive log files that they would otherwise not have authorization to access.&lt;/p&gt;
&lt;p&gt;To exploit this vulnerability, the attacker must have valid credentials to access the web-based management interface of the affected device.&lt;/p&gt;

&lt;p&gt;Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-pi-unauth-infodiscl-LFnLgmey&#034; target=&#034;_blank&#034; rel=&#034;noopener&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-pi-unauth-infodiscl-LFnLgmey&lt;/a&gt;&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Medium
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20189
		    
         </description>
          
		  <pubDate>2026-05-06 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-pi-unauth-infodiscl-LFnLgmey</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco Slido Insecure Direct Object Reference Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-slido-idor-CpsFmKxN?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Slido%20Insecure%20Direct%20Object%20Reference%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;A vulnerability in the REST API of Cisco Slido could have allowed an authenticated, remote attacker to access the social profile data of other users or affect quiz and poll results. Cisco has addressed this vulnerability in Cisco Slido and no customer action is needed.&lt;/p&gt;
&lt;p&gt;This vulnerability existed because of the presence of an insecure direct object reference. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by sending a crafted request to the vulnerable API endpoint. A successful exploit could have allowed the attacker to view the social profiles of other users or affect quiz and poll results.&lt;/p&gt;

&lt;p&gt;As mentioned, Cisco has addressed this vulnerability in the Slido service, and no customer action is necessary to update on-premises software or devices. There are no workarounds that address this vulnerability.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-slido-idor-CpsFmKxN&#034; target=&#034;_blank&#034; rel=&#034;noopener&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-slido-idor-CpsFmKxN&lt;/a&gt;&lt;/p&gt;

			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Medium
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20219
		    
         </description>
          
		  <pubDate>2026-05-06 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-slido-idor-CpsFmKxN</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco IoT Field Network Director Vulnerabilities</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iot-fnd-dos-n8N26Q4u?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20IoT%20Field%20Network%20Director%20Vulnerabilities%26vs_k=1</link>
          
          <description>
			&lt;p&gt;Multiple vulnerabilities in the web-based management interface of Cisco IoT Field Network Director Software could allow an authenticated, remote attacker to access files, execute commands, and cause denial of service (DoS) conditions on managed routers.&lt;/p&gt;
&lt;p&gt;For more information about these vulnerabilities, see the&amp;nbsp;&lt;a href=&#034;#details&#034;&gt;Details&lt;/a&gt; section of this advisory.&lt;/p&gt;
&lt;p&gt;Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iot-fnd-dos-n8N26Q4u&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iot-fnd-dos-n8N26Q4u&lt;/a&gt;&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  High
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20167,CVE-2026-20168,CVE-2026-20169
		    
         </description>
          
		  <pubDate>2026-05-06 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iot-fnd-dos-n8N26Q4u</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco SG350 and SG350X Series Managed Switches SNMP Denial of Service Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sg350-snmp-dos-GEFZr2Tj?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20SG350%20and%20SG350X%20Series%20Managed%20Switches%20SNMP%20Denial%20of%20Service%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of&amp;nbsp;Cisco 350 Series Managed Switches (SG350) and Cisco 350X Series Stackable Managed Switches (SG350X)&amp;nbsp;firmware could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;This vulnerability is due to improper error handling when parsing response data for a specific SNMP request. An attacker could exploit this vulnerability by sending a specific SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition.&lt;/p&gt;
&lt;p&gt;This vulnerability affects SNMP versions 1, 2c, and 3. To exploit this vulnerability through SNMPv2c or earlier, the attacker must know a valid &lt;em&gt;read-write&lt;/em&gt; or &lt;em&gt;read-only&lt;/em&gt; SNMP community string for the affected system. To exploit this vulnerability through SNMPv3, the attacker must have valid SNMP user credentials for the affected system.&lt;/p&gt;

&lt;p&gt;Cisco has not released and will not release software updates that address this vulnerability because the affected products are past the date for End of Software Maintenance Releases. The Cisco Product Security Incident Response Team (PSIRT) will continue to evaluate and disclose security vulnerabilities that affect these products until the Last Date of Support is reached.&lt;/p&gt;
&lt;p&gt;There are no workarounds that address this vulnerability. However, there is a mitigation.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sg350-snmp-dos-GEFZr2Tj&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sg350-snmp-dos-GEFZr2Tj&lt;/a&gt;&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  High
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20185
		    
         </description>
          
		  <pubDate>2026-05-06 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sg350-snmp-dos-GEFZr2Tj</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xss-42tgsdMG?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Stored%20Cross-Site%20Scripting%20Vulnerabilities%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;These vulnerabilities are due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit these vulnerabilities by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit these vulnerabilities, the attacker must have&amp;nbsp;valid administrative credentials.&lt;/p&gt;

&lt;p&gt;Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xss-42tgsdMG&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xss-42tgsdMG&lt;/a&gt;&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Medium
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2025-20204,CVE-2025-20205
		    
         </description>
          
		  <pubDate>2026-05-05 18:21:38.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xss-42tgsdMG</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Continued Evolution of Persistence Mechanism Against Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-persist-CISAED25-03?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Continued%20Evolution%20of%20Persistence%20Mechanism%20Against%20Cisco%20Secure%20Firewall%20Adaptive%20Security%20Appliance%20and%20Secure%20Firewall%20Threat%20Defense%26vs_k=1</link>
          
          <description>
			&lt;p&gt;On April 23, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an update to &lt;a href=&#034;https://cisa.gov/news-events/directives/v1-ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices&#034;&gt;V1: Emergency Directive (ED) 25-03: Identify and Mitigate Potential Compromise of Cisco Devices&lt;/a&gt; related to Cisco Secure Firewall Adaptive Security Appliance (ASA) and Cisco Secure Firewall Threat Defense (FTD) products.&lt;/p&gt;
&lt;p&gt;According to the update, the ArcaneDoor threat actor has developed a previously unknown persistence mechanism that is preserved across upgrading to the fixed releases that were published in September 2025. This persistence mechanism resides in the Cisco Firepower eXtensible Operating System (FXOS) Software base operating system for Cisco Secure Firewall ASA Software and Cisco Secure FTD Software installations on the affected hardware platforms.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; According to the intelligence Cisco PSIRT has received to date, the initial compromise, begins with the attacker exploiting the following vulnerabilities before customers upgraded to the fixed releases that were made available in September 2025:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CVE-2025-20333:&lt;/strong&gt; &lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-z5xP8EUB&#034;&gt;Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software VPN Web Server Remote Code Execution Vulnerability&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;CVE-2025-20362:&amp;nbsp;&lt;/strong&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-YROOTUW&#034;&gt;Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software VPN Web Server Unauthorized Access Vulnerability&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For more information about the fixed releases that were made available in September 2025, see&amp;nbsp;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/resources/asa_ftd_continued_attacks&#034;&gt;Cisco Event Response: Continued Attacks Against Cisco Firewalls&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-persist-CISAED25-03&#034; rel=&#034;nofollow&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-persist-CISAED25-03&lt;/a&gt;&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Informational
		    
		    
         </description>
          
		  <pubDate>2026-04-30 18:57:23.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-persist-CISAED25-03</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco Identity Services Engine Remote Code Execution and Path Traversal Vulnerabilities</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-traversal-8bYndVrZ?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Remote%20Code%20Execution%20and%20Path%20Traversal%20Vulnerabilities%26vs_k=1</link>
          
          <description>
			&lt;p&gt;Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to achieve remote code execution or conduct path traversal attacks on an affected device. To exploit these vulnerabilities, the attacker must have valid administrative credentials.&lt;/p&gt;
&lt;p&gt;For more information about these vulnerabilities, see the&amp;nbsp;&lt;a href=&#034;#details&#034;&gt;Details&lt;/a&gt; section of this advisory.&lt;/p&gt;
&lt;p&gt;Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-traversal-8bYndVrZ&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-traversal-8bYndVrZ&lt;/a&gt;&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Critical
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20147,CVE-2026-20148
		    
         </description>
          
		  <pubDate>2026-04-28 14:33:18.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-traversal-8bYndVrZ</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco ACI Multi-Site CloudSec Encryption Information Disclosure Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-aci-cloudsec-enc-Vs5Wn2sX?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20ACI%20Multi-Site%20CloudSec%20Encryption%20Information%20Disclosure%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;A vulnerability in the Cisco ACI Multi-Site CloudSec encryption feature of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, remote attacker to read or modify intersite encrypted traffic.&lt;/p&gt;
&lt;p&gt;This vulnerability is due to an issue with the implementation of the ciphers that are used by the CloudSec encryption feature on affected switches. An attacker with an on-path position between the ACI sites could exploit this vulnerability by intercepting intersite encrypted traffic and using cryptanalytic techniques to break the encryption. A successful exploit could allow the attacker to read or modify the traffic that is transmitted between the sites.&lt;/p&gt;
&lt;p&gt;Cisco has deprecated and removed the ACI Multi-Site CloudSec encryption feature that is affected by this vulnerability. There are no workarounds that address this vulnerability.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-aci-cloudsec-enc-Vs5Wn2sX&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-aci-cloudsec-enc-Vs5Wn2sX&lt;/a&gt;&lt;/p&gt;

			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  High
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2023-20185
		    
         </description>
          
		  <pubDate>2026-04-24 13:05:36.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-aci-cloudsec-enc-Vs5Wn2sX</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco Integrated Management Controller Cross-Site Scripting Vulnerabilities</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-xss-A2tkgVAB?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Integrated%20Management%20Controller%20Cross-Site%20Scripting%20Vulnerabilities%26vs_k=1</link>
          
          <description>
			&lt;p&gt;Multiple vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.&lt;/p&gt;
&lt;p&gt;For more information about these vulnerabilities, see the &lt;a href=&#034;#details&#034;&gt;Details&lt;/a&gt; section of this advisory.&lt;/p&gt;
&lt;p&gt;Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-xss-A2tkgVAB&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-xss-A2tkgVAB&lt;/a&gt;&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Medium
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20085,CVE-2026-20087,CVE-2026-20088,CVE-2026-20089,CVE-2026-20090
		    
         </description>
          
		  <pubDate>2026-04-22 18:05:52.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-xss-A2tkgVAB</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco Integrated Management Controller Command Injection and Remote Code Execution Vulnerabilities</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-cmd-inj-3hKN3bVt?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Integrated%20Management%20Controller%20Command%20Injection%20and%20Remote%20Code%20Execution%20Vulnerabilities%26vs_k=1</link>
          
          <description>
			&lt;p&gt;Multiple vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to execute arbitrary code or commands on the underlying operating system of an affected system and elevate privileges to&amp;nbsp;&lt;em&gt;root&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;For more information about these vulnerabilities, see the&amp;nbsp;&lt;a href=&#034;#details&#034;&gt;Details&lt;/a&gt; section of this advisory.&lt;/p&gt;
&lt;p&gt;Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-cmd-inj-3hKN3bVt&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-cmd-inj-3hKN3bVt&lt;/a&gt;&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  High
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20094,CVE-2026-20095,CVE-2026-20096,CVE-2026-20097
		    
         </description>
          
		  <pubDate>2026-04-22 18:01:40.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-cmd-inj-3hKN3bVt</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco Catalyst SD-WAN Vulnerabilities</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Catalyst%20SD-WAN%20Vulnerabilities%26vs_k=1</link>
          
          <description>
			&lt;p&gt;Multiple vulnerabilities in Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an attacker to access an affected system, elevate privileges to&amp;nbsp;&lt;em&gt;root,&lt;/em&gt; gain access to sensitive information, and overwrite arbitrary files.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;For more information about these vulnerabilities, see the &lt;a href=&#034;#details&#034;&gt;Details&lt;/a&gt; section of this advisory.&lt;/p&gt;
&lt;p&gt;Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.&lt;/p&gt;
&lt;p&gt;Cisco strongly recommends that customers upgrade to the fixed software indicated in this advisory.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v&lt;/a&gt;&lt;/p&gt;

			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Critical
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20122,CVE-2026-20126,CVE-2026-20128,CVE-2026-20129,CVE-2026-20133
		    
         </description>
          
		  <pubDate>2026-04-22 15:10:56.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-authbp-qwCX8D4v</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco Webex Services Certificate Validation Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-cui-cert-8jSZYhWL?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Webex%20Services%20Certificate%20Validation%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;A vulnerability in the integration of single sign-on (SSO) with Control Hub in Cisco Webex Services could have allowed an unauthenticated, remote attacker to impersonate any user within the service.&lt;/p&gt;
&lt;p&gt;This vulnerability existed because of improper certificate validation. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by connecting to a service endpoint and supplying a crafted token. A successful exploit could have allowed the attacker to gain unauthorized access to legitimate Cisco Webex services.&lt;/p&gt;

&lt;p&gt;Cisco has addressed this vulnerability in the Cisco Webex service. However, customer action is necessary for affected organizations that are using trust anchors with their SSO integration.&lt;/p&gt;
&lt;p&gt;There are no workarounds that address this vulnerability.&lt;/p&gt;
&lt;p&gt;To avoid service interruption, customers who are using trust anchors with their SSO integration should upload a new identity provider (IdP) SAML certificate to Control Hub. For more information, see &lt;a href=&#034;https://help.webex.com/en-us/article/nstvmyo/Manage-single-sign-on-integration-in-Control-Hub#Cisco_Task_in_List_GUI.dita_07fbdc21-41a0-482f-99dc-b8c17adbd087&#034;&gt;Manage single sign-on integration in Control Hub&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-cui-cert-8jSZYhWL&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-cui-cert-8jSZYhWL&lt;/a&gt;&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Critical
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20184
		    
         </description>
          
		  <pubDate>2026-04-16 18:52:15.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webex-cui-cert-8jSZYhWL</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco Secure Web Appliance Authentication Bypass Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wsa-auth-bypass-6YZkTQhd?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Web%20Appliance%20Authentication%20Bypass%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;A vulnerability in the authentication service feature of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass authentication policy requirements.&lt;/p&gt;
&lt;p&gt;This vulnerability is due to improper validation of user-supplied authentication input in HTTP requests. An attacker could exploit this vulnerability by sending HTTP requests that contain specific authentication requests to an affected device. A successful exploit could allow the attacker to bypass policy enforcement on the device. There is no direct impact to the Cisco Secure Web Appliance. However, as a result of exploiting this vulnerability, an attacker could send HTTP requests that should be restricted through the device.&lt;/p&gt;

&lt;p&gt;Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wsa-auth-bypass-6YZkTQhd&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wsa-auth-bypass-6YZkTQhd&lt;/a&gt;&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Medium
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20152
		    
         </description>
          
		  <pubDate>2026-04-16 13:14:04.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wsa-auth-bypass-6YZkTQhd</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco Identity Services Engine Remote Code Execution Vulnerabilities</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-4fverepv?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Remote%20Code%20Execution%20Vulnerabilities%26vs_k=1</link>
          
          <description>
			&lt;p&gt;Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit these vulnerabilities, the attacker must have at least Read Only Admin credentials.&lt;/p&gt;
&lt;p&gt;These vulnerabilities are due to insufficient validation of user-supplied input. An attacker could exploit these vulnerabilities by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to&amp;nbsp;&lt;em&gt;root&lt;/em&gt;. In single-node Cisco ISE deployments, successful exploitation of these vulnerabilities could cause the affected ISE node to become unavailable, resulting in a denial of service (DoS) condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored.&lt;/p&gt;
&lt;p&gt;Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-4fverepv&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-4fverepv&lt;/a&gt;&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Critical
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20180,CVE-2026-20186
		    
         </description>
          
		  <pubDate>2026-04-15 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-4fverepv</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco Identity Services Engine Authenticated Privilege Escalation Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-cmd-inj-5WSJcYJB?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Authenticated%20Privilege%20Escalation%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;A vulnerability in the&amp;nbsp;CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, local attacker with administrative privileges to perform a command injection attack on the underlying operating system and elevate privileges to &lt;em&gt;root&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;This vulnerability is due to insufficient validation of user supplied input. An attacker could exploit this vulnerability by providing crafted input to a specific CLI command. A successful exploit could allow the attacker to elevate their privileges to &lt;em&gt;root &lt;/em&gt;on the underlying operating system.&lt;/p&gt;

&lt;p&gt;Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-cmd-inj-5WSJcYJB&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-cmd-inj-5WSJcYJB&lt;/a&gt;&lt;/p&gt;

			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Medium
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20136
		    
         </description>
          
		  <pubDate>2026-04-15 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-cmd-inj-5WSJcYJB</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco Identity Services Engine Multiple Cross-Site Scripting Vulnerabilities</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-isexss-BS8ctE7U?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Multiple%20Cross-Site%20Scripting%20Vulnerabilities%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative&amp;nbsp;&lt;em&gt;write &lt;/em&gt;privileges to conduct a stored cross-site scripting (XSS) attack or a reflected XSS attack against a user of the web-based management interface of an affected device.&lt;/p&gt;
&lt;p&gt;These vulnerabilities are due to insufficient sanitization of user-supplied data that is stored in the web page. An attacker could exploit these vulnerabilities by convincing a user of the interface to click a specific link or view an affected web page. The injected script code may be executed in the context of the web-based management interface or allow the attacker to access sensitive browser-based information.&lt;/p&gt;

&lt;p&gt;Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-isexss-BS8ctE7U&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-isexss-BS8ctE7U&lt;/a&gt;&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Medium
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20132
		    
         </description>
          
		  <pubDate>2026-04-15 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-isexss-BS8ctE7U</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco ThousandEyes Enterprise Agent Arbitrary File Overwrite Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-te-agentfilewrite-tqUw3SMU?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20ThousandEyes%20Enterprise%20Agent%20Arbitrary%20File%20Overwrite%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent could allow an authenticated, local attacker with low privileges to overwrite arbitrary files on the local system of an affected device.&lt;/p&gt;
&lt;p&gt;This vulnerability is due to improper access controls on files that are on the local file system&amp;nbsp;of an affected device. An attacker could exploit this vulnerability by placing a symbolic link in a specific location on the local file system. A successful exploit could allow the attacker to bypass file system permissions and overwrite arbitrary files on the affected device.&lt;/p&gt;

&lt;p&gt;Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-te-agentfilewrite-tqUw3SMU&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-te-agentfilewrite-tqUw3SMU&lt;/a&gt;&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Medium
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20161
		    
         </description>
          
		  <pubDate>2026-04-15 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-te-agentfilewrite-tqUw3SMU</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco Unity Connection Arbitrary File Download Vulnerabilities</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-unity-file-download-RmKEVWPx?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Unity%20Connection%20Arbitrary%20File%20Download%20Vulnerabilities%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker&amp;nbsp;to download arbitrary files from an affected system. To exploit these vulnerabilities, the attacker must have valid administrative credentials.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;These vulnerabilities are due to improper sanitization of user input to the web-based management interface. An attacker could exploit these vulnerabilities by sending a crafted HTTPS request. A successful exploit could allow the attacker to download arbitrary files from an affected system.&lt;/p&gt;

&lt;p&gt;Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-unity-file-download-RmKEVWPx&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-unity-file-download-RmKEVWPx&lt;/a&gt;&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Medium
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20078,CVE-2026-20081
		    
         </description>
          
		  <pubDate>2026-04-15 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-unity-file-download-RmKEVWPx</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco Unity Connection Cross-Site Scripting, Open Redirect, and SQL Injection Vulnerabilities</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-unity-vulns-n2EJSbbw?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Unity%20Connection%20Cross-Site%20Scripting,%20Open%20Redirect,%20and%20SQL%20Injection%20Vulnerabilities%26vs_k=1</link>
          
          <description>
			&lt;p&gt;Multiple vulnerabilities in Cisco Unity Connection could allow a remote attacker to conduct a cross-site scripting (XSS) attack, an open redirect attack, and an SQL injection attack.&lt;/p&gt;
&lt;p&gt;For more information about these vulnerabilities, see the &lt;a href=&#034;#details&#034;&gt;Details&lt;/a&gt; section of this advisory.&lt;/p&gt;
&lt;p&gt;Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-unity-vulns-n2EJSbbw&#034; target=&#034;_blank&#034; rel=&#034;noopener&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-unity-vulns-n2EJSbbw&lt;/a&gt;&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Medium
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20059,CVE-2026-20060,CVE-2026-20061
		    
         </description>
          
		  <pubDate>2026-04-15 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-unity-vulns-n2EJSbbw</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco Webex Contact Center Cross-Site Scripting Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webexcc-xss-WEX5nUnA?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Webex%20Contact%20Center%20Cross-Site%20Scripting%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;A vulnerability in the Desktop Agent functionality of Cisco Webex Contact Center could have allowed an unauthenticated, remote attacker to conduct cross-site scripting attacks. Cisco has addressed this vulnerability in the Cisco Webex Contact Center service, and no customer action is needed.&lt;/p&gt;
&lt;p&gt;This vulnerability existed because HTML and script content was not properly handled. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by persuading a user to follow a malicious link. A successful exploit could have allowed the attacker to steal sensitive information from the browser, including authentication and session information.&lt;/p&gt;

&lt;p&gt;As mentioned, Cisco has addressed this vulnerability in the Cisco Webex Contact Center service, and no customer action is necessary to update on-premises software or devices. There are no workarounds that address this vulnerability.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webexcc-xss-WEX5nUnA&#034; rel=&#034;nofollow&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webexcc-xss-WEX5nUnA&lt;/a&gt;&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Medium
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20170
		    
         </description>
          
		  <pubDate>2026-04-15 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webexcc-xss-WEX5nUnA</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco IOS XE Software Denial of Service Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-mntc-dos-LZweQcyq?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20IOS%20XE%20Software%20Denial%20of%20Service%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device.&lt;/p&gt;
&lt;p&gt;This vulnerability exists because incorrect privileges are associated with the&amp;nbsp;&lt;strong&gt;start maintenance&lt;/strong&gt; command. An attacker could exploit this vulnerability by accessing the management CLI of the affected device as a low-privileged user and using the&amp;nbsp;&lt;strong&gt;start maintenance&lt;/strong&gt; command. A successful exploit could allow the attacker to put the device in maintenance mode, which shuts down interfaces, resulting in a denial of service (DoS) condition. In case of exploitation, a device administrator can connect to the CLI and use the &lt;strong&gt;stop maintenance&lt;/strong&gt; command to restore operations.&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-mntc-dos-LZweQcyq&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-mntc-dos-LZweQcyq&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This advisory is part of the March 2026 release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see &lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75297&#034;&gt;Cisco Event Response: March 2026 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication&lt;/a&gt;.&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Medium
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20110
		    
         </description>
          
		  <pubDate>2026-04-02 19:43:54.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-mntc-dos-LZweQcyq</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco Smart Software Manager On-Prem Arbitrary Command Execution Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ssm-cli-execution-cHUcWuNr?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Smart%20Software%20Manager%20On-Prem%20Arbitrary%20Command%20Execution%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host.&lt;/p&gt;
&lt;p&gt;This vulnerability is due to the unintentional exposure of an&amp;nbsp;internal service. An attacker could exploit this vulnerability by sending a crafted request to the API of the exposed service. A successful exploit could allow the attacker to execute commands on the underlying operating system with &lt;em&gt;root&lt;/em&gt;-level privileges.&lt;/p&gt;

&lt;p&gt;Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ssm-cli-execution-cHUcWuNr&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ssm-cli-execution-cHUcWuNr&lt;/a&gt;&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Critical
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20160
		    
         </description>
          
		  <pubDate>2026-04-01 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ssm-cli-execution-cHUcWuNr</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco Nexus Dashboard Configuration Backup REST API Unauthorized Access Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nd-cbid-5YqkOSHu?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Nexus%20Dashboard%20Configuration%20Backup%20REST%20API%20Unauthorized%20Access%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encryption password and access to Full or Config-only backup files to access sensitive information.&lt;/p&gt;
&lt;p&gt;This vulnerability exists because authentication details are included in the encrypted backup files. An attacker with a valid backup file and encryption password from an affected device could decrypt the backup file. The attacker could then use the authentication details in the backup file to access internal-only APIs on the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the &lt;em&gt;root&lt;/em&gt; user.&lt;/p&gt;

&lt;p&gt;Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nd-cbid-5YqkOSHu&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nd-cbid-5YqkOSHu&lt;/a&gt;&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Medium
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20042
		    
         </description>
          
		  <pubDate>2026-04-01 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nd-cbid-5YqkOSHu</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco Nexus Dashboard and Nexus Dashboard Insights Server-Side Request Forgery Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nd-ssrf-NAen4O7r?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Nexus%20Dashboard%20and%20Nexus%20Dashboard%20Insights%20Server-Side%20Request%20Forgery%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;A vulnerability in Cisco Nexus Dashboard and Cisco Nexus Dashboard Insights could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device.&lt;/p&gt;
&lt;p&gt;This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by persuading an authenticated user of the device management interface to click a crafted link. A successful exploit could allow the attacker to send arbitrary network requests that are sourced from the affected device to an attacker-controlled server. The attacker could then execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.&lt;/p&gt;

&lt;p&gt;Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nd-ssrf-NAen4O7r&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nd-ssrf-NAen4O7r&lt;/a&gt;&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Medium
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20041
		    
         </description>
          
		  <pubDate>2026-04-01 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nd-ssrf-NAen4O7r</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco Nexus Dashboard Insights Arbitrary File Write Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndi-afw-rJuRC5dZ?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Nexus%20Dashboard%20Insights%20Arbitrary%20File%20Write%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;A vulnerability in the Metadata update feature of Cisco Nexus Dashboard Insights could allow an authenticated, remote attacker to write arbitrary files to an affected system.&lt;/p&gt;
&lt;p&gt;This vulnerability is due to insufficient validation of the metadata update file. An attacker could exploit this vulnerability by crafting a metadata update file and manually uploading it to an affected device. A successful exploit could allow the attacker to write arbitrary files to the underlying operating system as the&amp;nbsp;&lt;em&gt;root&lt;/em&gt; user. To exploit this vulnerability, the attacker must have valid administrative credentials.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; Manual uploading of metadata files is typical for Air-Gap environments but not for Cisco Intersight Cloud connected devices. However, the manual upload option exists for both deployments.&lt;/p&gt;

&lt;p&gt;Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndi-afw-rJuRC5dZ&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndi-afw-rJuRC5dZ&lt;/a&gt;&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Medium
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20174
		    
         </description>
          
		  <pubDate>2026-04-01 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndi-afw-rJuRC5dZ</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco Integrated Management Controller Authentication Bypass Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-auth-bypass-AgG2BxTn?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Integrated%20Management%20Controller%20Authentication%20Bypass%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as&amp;nbsp;&lt;em&gt;Admin&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;This vulnerability is due to incorrect handling of password change requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to bypass authentication, alter the passwords of any user on the system, including an&amp;nbsp;&lt;em&gt;Admin&lt;/em&gt; user, and gain access to the system as that user.&lt;/p&gt;

&lt;p&gt;Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-auth-bypass-AgG2BxTn&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-auth-bypass-AgG2BxTn&lt;/a&gt;&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Critical
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20093
		    
         </description>
          
		  <pubDate>2026-04-01 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-auth-bypass-AgG2BxTn</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco Smart Software Manager On-Prem Privilege Escalation Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cssm-priv-esc-xRAnOuO8?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Smart%20Software%20Manager%20On-Prem%20Privilege%20Escalation%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;A vulnerability in the web interface of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges on an affected system.&lt;/p&gt;
&lt;p&gt;This vulnerability is due to the improper transmission of sensitive user information. An attacker could exploit this vulnerability by sending a crafted message to an affected Cisco SSM On-Prem host and retrieving session credentials from subsequent status messages. A successful exploit could allow the attacker to elevate privileges on the affected system from low to administrative.&lt;/p&gt;
&lt;p&gt;To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of System User.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; This vulnerability exposes information only about users who logged in to the Cisco SSM On-Prem host using the web interface and who are currently logged in. SSH sessions are not affected.&lt;/p&gt;

&lt;p&gt;Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cssm-priv-esc-xRAnOuO8&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cssm-priv-esc-xRAnOuO8&lt;/a&gt;&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  High
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20151
		    
         </description>
          
		  <pubDate>2026-04-01 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cssm-priv-esc-xRAnOuO8</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco Evolved Programmable Network Manager Improper Authorization Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-epnm-improp-auth-mUwFWUU3?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Evolved%20Programmable%20Network%20Manager%20Improper%20Authorization%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker with low privileges to access sensitive information that they are not authorized to access.&lt;/p&gt;
&lt;p&gt;This vulnerability is due to improper authorization checks on a REST API endpoint of an affected device.&amp;nbsp;An attacker could exploit this vulnerability by querying the affected endpoint. A successful exploit could allow the attacker to view session information of active Cisco EPNM users, including users with administrative privileges, which could result in the affected device being compromised.&lt;/p&gt;

&lt;p&gt;Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-epnm-improp-auth-mUwFWUU3&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-epnm-improp-auth-mUwFWUU3&lt;/a&gt;&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  High
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20155
		    
         </description>
          
		  <pubDate>2026-04-01 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-epnm-improp-auth-mUwFWUU3</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco Nexus Dashboard Fabric Controller Arbitrary Command Execution Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndfc-cmdinj-UvYZrKfr?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Nexus%20Dashboard%20Fabric%20Controller%20Arbitrary%20Command%20Execution%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;div&gt;A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to perform a command injection attack against an affected device.&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;This vulnerability is due to improper user authorization and insufficient validation of command arguments. An attacker could exploit this vulnerability by submitting crafted commands to an affected REST API endpoint or through the web UI. A successful exploit could allow the attacker to execute arbitrary commands on the CLI of a Cisco NDFC-managed device with &lt;em&gt;network-admin &lt;/em&gt;privileges.&lt;/div&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;&lt;strong&gt;Note:&lt;/strong&gt; This vulnerability does not affect Cisco NDFC when it is configured for storage area network (SAN) controller deployment.&lt;/div&gt;

&lt;p&gt;Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a id=&#034;u_psirt_publication.u_public_url_link&#034; class=&#034;web web-inline form-control-static&#034; href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndfc-cmdinj-UvYZrKfr&#034; target=&#034;gsft_link&#034; name=&#034;u_psirt_publication.u_public_url_link&#034; aria-hidden=&#034;&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndfc-cmdinj-UvYZrKfr&lt;/a&gt;&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Critical
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2024-20432
		    
         </description>
          
		  <pubDate>2026-03-31 18:47:53.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ndfc-cmdinj-UvYZrKfr</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco IOS XE Software Lobby Ambassador Privilege Escalation Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-lobby-privesc-KwxBqJy?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20IOS%20XE%20Software%20Lobby%20Ambassador%20Privilege%20Escalation%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;A vulnerability in the Lobby Ambassador web-based management API of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate their privileges and access management APIs that would not normally be available for Lobby Ambassador users.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;This vulnerability exists because parameters that are received by an API endpoint are not sufficiently validated. An attacker could exploit this vulnerability by authenticating as a Lobby Ambassador user and sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to create a new user with privilege level 1 access to the web-based management API. The attacker would then be able to access the device with these new credentials and privileges.&lt;/p&gt;

&lt;p&gt;Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-lobby-privesc-KwxBqJy&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-lobby-privesc-KwxBqJy&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This advisory is part of the March 2026 release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see &lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75297&#034;&gt;Cisco Event Response: March 2026 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication&lt;/a&gt;.&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Medium
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20114
		    
         </description>
          
		  <pubDate>2026-03-25 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-lobby-privesc-KwxBqJy</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco IOx Application Hosting Environment Carriage Return Line Feed Injection Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iox-crlf-NvgKTKJZ?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20IOx%20Application%20Hosting%20Environment%20Carriage%20Return%20Line%20Feed%20Injection%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a carriage return line feed (CRLF) injection attack against a user.&lt;/p&gt;
&lt;p&gt;This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by sending crafted packets to an affected device. A successful exploit could allow the attacker to arbitrarily inject log entries, manipulate the structure of log files, or obscure legitimate log events.&lt;/p&gt;

&lt;p&gt;Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iox-crlf-NvgKTKJZ&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iox-crlf-NvgKTKJZ&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This advisory is part of the March 2026 release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see &lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75297&#034;&gt;Cisco Event Response: March 2026 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication&lt;/a&gt;.&lt;/p&gt;

			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Medium
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20113
		    
         </description>
          
		  <pubDate>2026-03-25 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iox-crlf-NvgKTKJZ</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco IOx Application Hosting Environment  Stored Cross-Site Scripting Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iox-xss-LpGkzwtJ?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20IOx%20Application%20Hosting%20Environment%20%20Stored%20Cross-Site%20Scripting%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device.&lt;/p&gt;
&lt;p&gt;This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. To exploit this vulnerability, the attacker must have valid administrative credentials.&lt;/p&gt;

&lt;p&gt;Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iox-xss-LpGkzwtJ&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iox-xss-LpGkzwtJ&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This advisory is part of the March 2026 release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see &lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75297&#034;&gt;Cisco Event Response: March 2026 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication&lt;/a&gt;.&lt;/p&gt;

			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Medium
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20112
		    
         </description>
          
		  <pubDate>2026-03-25 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iox-xss-LpGkzwtJ</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco IOS XE Software for Catalyst 9000 Series Switches DHCP Snooping Denial of Service Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bootp-WuBhNBxA?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20IOS%20XE%20Software%20for%20Catalyst%209000%20Series%20Switches%20DHCP%20Snooping%20Denial%20of%20Service%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause BOOTP packets to be forwarded between VLANs, resulting in a denial of service (DoS) condition.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;This vulnerability is due to improper handling of BOOTP packets on Cisco Catalyst 9000 Series Switches. An attacker could exploit this vulnerability by sending BOOTP request packets to an affected device. A successful exploit could allow an attacker to forward BOOTP packets from one VLAN to another, resulting in BOOTP VLAN leakage and potentially leading to high CPU utilization. This makes the device unreachable (either through console or remote management) and unable to forward traffic, resulting in a DoS condition.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; This vulnerability can be exploited with either unicast or broadcast BOOTP packets.&lt;/p&gt;
&lt;p&gt;Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability.&lt;/p&gt;

&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bootp-WuBhNBxA&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bootp-WuBhNBxA&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This advisory is part of the March 2026 release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see &lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75297&#034;&gt;Cisco Event Response: March 2026 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication&lt;/a&gt;.&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  High
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20084
		    
         </description>
          
		  <pubDate>2026-03-25 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bootp-WuBhNBxA</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco IOS Software and IOS XE Software Release 3E HTTP Server Denial of Service Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-http-dos-sbv8XRpL?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20IOS%20Software%20and%20IOS%20XE%20Software%20Release%203E%20HTTP%20Server%20Denial%20of%20Service%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release 3E could allow an authenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.&lt;/p&gt;
&lt;p&gt;This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending malformed HTTP requests to an affected device. A successful exploit could allow the attacker to cause a watchdog timer to expire and the device to reload, resulting in a DoS condition. To exploit this vulnerability, the attacker must have a valid user account.&lt;/p&gt;

&lt;p&gt;Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-http-dos-sbv8XRpL&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-http-dos-sbv8XRpL&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;This advisory is part of the March 2026 release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see &lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75297&#034;&gt;Cisco Event Response: March 2026 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication&lt;/a&gt;.&lt;/p&gt;

			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  High
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20125
		    
         </description>
          
		  <pubDate>2026-03-25 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-http-dos-sbv8XRpL</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco IOS, IOS XE, Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ftd-ios-dos-kPEpQGGK?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20IOS,%20IOS%20XE,%20Secure%20Firewall%20Adaptive%20Security%20Appliance,%20and%20Secure%20Firewall%20Threat%20Defense%20Software%20IKEv2%20Denial%20of%20Service%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak, resulting in a denial of service (DoS) condition on an affected device.&lt;/p&gt;
&lt;p&gt;This vulnerability is due to improper parsing of IKEv2 packets. An attacker could exploit this vulnerability by sending crafted IKEv2 packets to an affected device. A successful exploit of Cisco IOS Software and IOS XE Software could allow the attacker to cause the affected device to reload, resulting in a DoS condition. A successful exploit of Cisco Secure Firewall ASA Software and Secure FTD Software could allow the attacker to partially exhaust system memory, resulting in system instability, such as the inability to establish new IKEv2 VPN sessions. A manual reboot of the device is required to recover from this condition.&lt;/p&gt;

&lt;p&gt;Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ftd-ios-dos-kPEpQGGK&#034; target=&#034;_blank&#034; rel=&#034;noopener&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ftd-ios-dos-kPEpQGGK&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This advisory is part of the March 2026 release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see &lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75297&#034;&gt;Cisco Event Response: March 2026 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication&lt;/a&gt;.&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  High
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20012
		    
         </description>
          
		  <pubDate>2026-03-25 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ftd-ios-dos-kPEpQGGK</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco Catalyst SD-WAN Manager Cross-Site Scripting Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanage-xss-ZqkhP9W9?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Catalyst%20SD-WAN%20Manager%20Cross-Site%20Scripting%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device.&lt;/p&gt;
&lt;p&gt;This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of the web-based management interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.&lt;/p&gt;

&lt;p&gt;Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanage-xss-ZqkhP9W9&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanage-xss-ZqkhP9W9&lt;/a&gt;&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Medium
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20108
		    
         </description>
          
		  <pubDate>2026-03-25 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-vmanage-xss-ZqkhP9W9</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco IOS XE Wireless Controller Software for the Catalyst CW9800 Family CAPWAP Denial of Service Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wlc-dos-hnX5KGOm?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20IOS%20XE%20Wireless%20Controller%20Software%20for%20the%20Catalyst%20CW9800%20Family%20CAPWAP%20Denial%20of%20Service%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) packets of Cisco IOS XE Wireless Controller Software for the Catalyst CW9800 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.&lt;/p&gt;
&lt;p&gt;This vulnerability is due to improper handling of a malformed CAPWAP packet. An attacker could exploit this vulnerability by sending a malformed CAPWAP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to reload unexpectedly, resulting in a DoS condition.&lt;/p&gt;

&lt;p&gt;Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wlc-dos-hnX5KGOm&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wlc-dos-hnX5KGOm&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;This advisory is part of the March 2026 release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see&amp;nbsp;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75297&#034;&gt;Cisco Event Response: March 2026 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication&lt;/a&gt;.&lt;/p&gt;

			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  High
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20086
		    
         </description>
          
		  <pubDate>2026-03-25 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-wlc-dos-hnX5KGOm</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco IOS XE Software for Cisco Catalyst and Rugged Series Switches Secure Boot Bypass Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-xe-secureboot-bypass-B6uYxYSZ?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20IOS%20XE%20Software%20for%20Cisco%20Catalyst%20and%20Rugged%20Series%20Switches%20Secure%20Boot%20Bypass%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;A vulnerability in the bootloader of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches, Cisco Catalyst ESS9300 Embedded Series Switches, Cisco Catalyst IE9310 and IE9320 Rugged Series Switches, and Cisco IE3500 and IE3505 Rugged Series Switches could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to an affected device to execute arbitrary code at boot time and break the chain of trust.&lt;/p&gt;
&lt;p&gt;This vulnerability is due to insufficient validation of software at boot time. An attacker could exploit this vulnerability by manipulating the loaded binaries on an affected device to bypass some of the integrity checks that are performed during the boot process. A successful exploit could allow the attacker to execute code that bypasses&amp;nbsp;the requirement to run Cisco-signed images.&lt;/p&gt;
&lt;p&gt;Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates because this vulnerability allows an attacker to bypass a major security feature of a device.&lt;/p&gt;

&lt;p&gt;Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-xe-secureboot-bypass-B6uYxYSZ&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-xe-secureboot-bypass-B6uYxYSZ&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This advisory is part of the March 2026 release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see &lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75297&#034;&gt;Cisco Event Response: March 2026 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication&lt;/a&gt;.&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  High
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20104
		    
         </description>
          
		  <pubDate>2026-03-25 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-xe-secureboot-bypass-B6uYxYSZ</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco IOS XE Software TLS Memory Exhaustion Denial of Service Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-tls-dos-TVgLDEZL?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20IOS%20XE%20Software%20TLS%20Memory%20Exhaustion%20Denial%20of%20Service%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;A vulnerability in the TLS library of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to exhaust the available memory of an affected device.&lt;/p&gt;
&lt;p&gt;This vulnerability is due to improper management of memory resources during TLS connection setup. An attacker could exploit this vulnerability by repeatedly triggering the conditions that cause the memory increase. This could be done in a variety of ways, such as by repeatedly attempting Extensible Authentication Protocol (EAP) authentication when local EAP is enabled on an affected device or by using a machine-in-the-middle attack and resetting TLS connections between the affected device and other devices. A successful exploit could allow the attacker to exhaust the available memory on an affected device, resulting in an unexpected reload and a denial of service (DoS) condition.&lt;/p&gt;

&lt;p&gt;Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-tls-dos-TVgLDEZL&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-tls-dos-TVgLDEZL&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This advisory is part of the March 2026 release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see &lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75297&#034;&gt;Cisco Event Response: March 2026 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication&lt;/a&gt;.&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  High
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20004
		    
         </description>
          
		  <pubDate>2026-03-25 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-tls-dos-TVgLDEZL</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco IOS XE Software Secure Channel for Meraki Information Disclosure Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe_infodis-6J847uEB?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20IOS%20XE%20Software%20Secure%20Channel%20for%20Meraki%20Information%20Disclosure%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;A vulnerability in Cisco IOS XE Software for Cisco Meraki&amp;nbsp;could allow a remote, unauthenticated attacker to view confidential device information.&lt;/p&gt;
&lt;p&gt;This vulnerability is due to a device configuration upload being performed over an insecure tunnel. An attacker could exploit this vulnerability by conducting an on-path attack between the affected device and the Cisco Meraki Dashboard. A successful exploit could allow the attacker to view sensitive device configuration information.&lt;/p&gt;

&lt;p&gt;Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe_infodis-6J847uEB&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe_infodis-6J847uEB&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This advisory is part of the March 2026 release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see &lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75297&#034;&gt;Cisco Event Response: March 2026 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication&lt;/a&gt;.&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Medium
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20115
		    
         </description>
          
		  <pubDate>2026-03-25 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe_infodis-6J847uEB</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco IOS XE Software Secure Copy Protocol Server Denial of Service Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-scp-dos-duAdXtCg?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20IOS%20XE%20Software%20Secure%20Copy%20Protocol%20Server%20Denial%20of%20Service%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;A vulnerability in the Secure Copy Protocol (SCP) server feature of Cisco IOS XE Software could allow an authenticated, local attacker with low privileges to cause a denial of service (DoS) condition on an affected device.&lt;/p&gt;
&lt;p&gt;This vulnerability is due to improper handling of a malformed SCP request. An attacker could exploit this vulnerability by issuing a crafted command through SSH. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition.&lt;/p&gt;

&lt;p&gt;Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-scp-dos-duAdXtCg&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-scp-dos-duAdXtCg&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This advisory is part of the March 2026 release of the Cisco IOS and IOS XE Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see &lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75297&#034;&gt;Cisco Event Response: March 2026 Semiannual Cisco IOS and IOS XE Software Security Advisory Bundled Publication&lt;/a&gt;.&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Medium
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20083
		    
         </description>
          
		  <pubDate>2026-03-25 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-scp-dos-duAdXtCg</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Secure%20Firewall%20Management%20Center%20Software%20Remote%20Code%20Execution%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as &lt;em&gt;root&lt;/em&gt;&amp;nbsp;on an affected device.&lt;/p&gt;
&lt;p&gt;This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to &lt;em&gt;root&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Note: &lt;/strong&gt;If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.&lt;/p&gt;

&lt;p&gt;Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This advisory is part of the March 2026 release of the Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see&amp;nbsp;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75736&#034;&gt;Cisco Event Response: March 2026 Semiannual Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication&lt;/a&gt;.&lt;/p&gt;
			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  Critical
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20131
		    
         </description>
          
		  <pubDate>2026-03-25 14:21:24.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-rce-NKhnULJh</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco IOS XR Egress Packet Network Interface Aligner Interrupt Denial of Service Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-xrncs-epni-int-dos-TWMffUsN?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20IOS%20XR%20Egress%20Packet%20Network%20Interface%20Aligner%20Interrupt%20Denial%20of%20Service%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;A vulnerability in the handling of an Egress Packet Network Interface (EPNI) Aligner interrupt in Cisco IOS XR Software for Cisco Network Convergence System (NCS) 5500 Series with NC57 line cards and Cisco NCS 5700 Routers and Cisco IOS XR Software for Third Party Software could allow an unauthenticated, remote attacker to cause the network processing unit (NPU) and ASIC to stop processing, preventing traffic from traversing the interface.&lt;/p&gt;
&lt;p&gt;This vulnerability is due to the corruption of packets in specific cases when an EPNI Aligner interrupt is triggered while an affected device is experiencing heavy transit traffic. An attacker could exploit this vulnerability by sending a continuous flow of crafted packets to an interface of the affected device. A successful exploit could allow the attacker to cause persistent, heavy packet loss, resulting in a denial of service (DoS) condition.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; If active exploitation of this vulnerability is suspected, contact the Cisco Technical Assistance Center (TAC) or your contracted maintenance provider.&lt;/p&gt;
&lt;p&gt;Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. This change was made because the affected device operates within a critical network segment where compromise could lead to significant disruption or exposure, thereby elevating the overall risk beyond the base technical severity.&lt;/p&gt;

&lt;p&gt;Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-xrncs-epni-int-dos-TWMffUsN&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-xrncs-epni-int-dos-TWMffUsN&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;This advisory is part of the March 2026 release of the Cisco IOS XR Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see &lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75772&#034;&gt;Cisco Event Response: March 2026 Semiannual Cisco IOS XR Software Security Advisory Bundled Publication&lt;/a&gt;.&lt;/p&gt;

			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  High
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20118
		    
         </description>
          
		  <pubDate>2026-03-11 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-xrncs-epni-int-dos-TWMffUsN</guid>
      </item>
    
	
    
	  <item>
	  <!-- I2R 9899 -->
          <title>Cisco IOS XR Software Multi-Instance Intermediate System-to-Intermediate System Denial of Service Vulnerability</title>
          
           
            
             
			
		            
		 
          <link>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-isis-dos-kDMxpSzK?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20IOS%20XR%20Software%20Multi-Instance%20Intermediate%20System-to-Intermediate%20System%20Denial%20of%20Service%20Vulnerability%26vs_k=1</link>
          
          <description>
			
&lt;p&gt;A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) multi-instance routing feature of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the IS-IS process to restart unexpectedly.&lt;/p&gt;
&lt;p&gt;This vulnerability is due to insufficient input validation of ingress IS-IS packets. An attacker could exploit this vulnerability by sending crafted IS-IS packets to an affected device after forming an adjacency. A successful exploit could allow the attacker to cause the IS-IS process to restart unexpectedly, resulting in a temporary loss of connectivity to advertised networks and a denial of service (DoS) condition.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; The IS-IS protocol is a routing protocol. To exploit this vulnerability, an attacker must be Layer 2-adjacent to the affected device and must have formed an adjacency.&amp;nbsp;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&lt;/p&gt;
&lt;p&gt;This advisory is available at the following link:&lt;br&gt;&lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-isis-dos-kDMxpSzK&#034;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-isis-dos-kDMxpSzK&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;This advisory is part of the March 2026 release of the Cisco IOS XR Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see &lt;a href=&#034;https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75772&#034;&gt;Cisco Event Response: March 2026 Semiannual Cisco IOS XR Software Security Advisory Bundled Publication&lt;/a&gt;.&lt;/p&gt;

			      
		           &amp;lt;br/&amp;gt;Security Impact Rating:  High
		    
		    
		        &amp;lt;br/&amp;gt;CVE: CVE-2026-20074
		    
         </description>
          
		  <pubDate>2026-03-11 16:00:00.0</pubDate>                   
          <guid>https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-isis-dos-kDMxpSzK</guid>
      </item>
    
	
  </channel>
</rss> 
