[{"identifier":"cisco-sa-notice-LDquvx5d","title":"Cisco Advance Notification for Publication of August 19, 2026, Security Advisories","version":"1.0","firstPublished":"2026-08-12T16:00:00.000+0000","lastPublished":"2026-08-12T16:00:00.000+0000","workflowStatus":null,"id":1,"name":"Cisco Security Advisory","url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-LDquvx5d","severity":"Informational","workarounds":"No","cwe":null,"status":"New","summary":"On August 19, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products:BroadWorksIndustrial Ethernet 1000 Series ","totalCount":62626,"relatedResource":[]},{"identifier":"cisco-sa-fmc-static-cred-BET3Cjh","title":"Cisco Secure Firewall Management Center Software Static Credential Vulnerability","version":"1.5","firstPublished":"2026-07-29T16:00:00.000+0000","lastPublished":"2026-08-11T19:01:08.220+0000","workflowStatus":null,"id":1,"name":"Cisco Security Advisory","url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh","severity":"High","workarounds":"No","cwe":"CWE-259","cve":"CVE-2026-20316","ciscoBugId":"CSCwt95997","status":"Updated","summary":"A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.This vulnerability is due ","totalCount":62626,"relatedResource":[{"type":"Snort","values":[{"name":"66883","url":""}]}]},{"identifier":"cisco-sa-asaftd-vpn-dos-dzv4mQFF","title":"Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability","version":"1.0","firstPublished":"2026-08-11T16:39:00.000+0000","lastPublished":"2026-08-11T16:39:00.000+0000","workflowStatus":null,"id":1,"name":"Cisco Security Advisory","url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF","severity":"High","workarounds":"No","cwe":"CWE-244","cve":"CVE-2026-20349","ciscoBugId":"CSCwv96220","status":"New","summary":"A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of ","totalCount":62626,"relatedResource":[{"type":"Snort","values":[{"name":"46897","url":"https://www.snort.org/"},{"name":"59654","url":"https://www.snort.org/"}]}]},{"identifier":"cisco-sa-clamav-WuuvVd26","title":"ClamAV Vulnerabilities Affecting Cisco Products: August 2026","version":"1.1","firstPublished":"2026-08-07T16:00:00.000+0000","lastPublished":"2026-08-10T16:03:09.970+0000","workflowStatus":null,"id":1,"name":"Cisco Security Advisory","url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-clamav-WuuvVd26","severity":"High","workarounds":"No","cwe":"CWE-120, CWE-121, CWE-125, CWE-190, CWE-415","cve":"CVE-2026-20337,CVE-2026-20338,CVE-2026-20339,CVE-2026-20345,CVE-2026-20346,CVE-2026-20347,CVE-2026-20348","ciscoBugId":"CSCwu34288,CSCwu59475,CSCwu65985,CSCwu78432,CSCwu99410,CSCwv57797","status":"Updated","summary":"Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations. For more information about these vulnerabilities, see the Details section of this advisory.For additional ","totalCount":62626,"relatedResource":[]},{"identifier":"cisco-sa-sdwan-infodis-SPuJBDCe","title":"Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability","version":"1.1","firstPublished":"2026-08-05T16:00:00.000+0000","lastPublished":"2026-08-07T21:26:16.083+0000","workflowStatus":null,"id":1,"name":"Cisco Security Advisory","url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-infodis-SPuJBDCe","severity":"Medium","workarounds":"No","cwe":"CWE-319","cve":"CVE-2026-20294","ciscoBugId":"CSCwu18179","status":"Updated","summary":"A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system.This vulnerability is due to insufficient access control enforcement for specific ","totalCount":62626,"relatedResource":[]},{"identifier":"cisco-sa-notice-L4XfJg8S","title":"Cisco Advance Notification for Publication of August 5, 2026, Security Advisories","version":"1.1","firstPublished":"2026-07-29T16:00:00.000+0000","lastPublished":"2026-08-05T16:01:06.253+0000","workflowStatus":null,"id":1,"name":"Cisco Security Advisory","url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-L4XfJg8S","severity":"Informational","workarounds":"No","cwe":null,"status":"Updated","summary":"On August 5, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories:","totalCount":62626,"relatedResource":[]},{"identifier":"cisco-sa-xe-webui-dos-PtAODAWW","title":"Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerability","version":"1.0","firstPublished":"2026-08-05T16:00:00.000+0000","lastPublished":"2026-08-05T16:00:00.000+0000","workflowStatus":null,"id":1,"name":"Cisco Security Advisory","url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-xe-webui-dos-PtAODAWW","severity":"Medium","workarounds":"No","cwe":"CWE-126","cve":"CVE-2026-20311","ciscoBugId":"CSCwu25287","status":"New","summary":"A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device.This vulnerability is due to insufficient error handling in the web-based ","totalCount":62626,"relatedResource":[]},{"identifier":"cisco-sa-webui-dos-qdc7qx3","title":"Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerability","version":"1.0","firstPublished":"2026-08-05T16:00:00.000+0000","lastPublished":"2026-08-05T16:00:00.000+0000","workflowStatus":null,"id":1,"name":"Cisco Security Advisory","url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-webui-dos-qdc7qx3","severity":"Medium","workarounds":"No","cwe":"CWE-269","cve":"CVE-2026-20308","ciscoBugId":"CSCwu19075","status":"New","summary":"A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device.This vulnerability is due to insufficient input validation. An ","totalCount":62626,"relatedResource":[]},{"identifier":"cisco-sa-ts-agent-fw-bypass-MYBTMrev","title":"Cisco Terminal Services Agent Firewall Rules Bypass Vulnerability","version":"1.0","firstPublished":"2026-08-05T16:00:00.000+0000","lastPublished":"2026-08-05T16:00:00.000+0000","workflowStatus":null,"id":1,"name":"Cisco Security Advisory","url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ts-agent-fw-bypass-MYBTMrev","severity":"Medium","workarounds":"No","cwe":"CWE-266","cve":"CVE-2026-20028","ciscoBugId":"CSCws82513","status":"New","summary":"A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker to bypass firewall rules that are associated with the account of the attacker.This vulnerability is due to an incorrect mapping of network connections to user ","totalCount":62626,"relatedResource":[]},{"identifier":"cisco-sa-roomos-infodisc-qBXjfmWm","title":"Cisco RoomOS Logging Subsystem Information Disclosure Vulnerability","version":"1.0","firstPublished":"2026-08-05T16:00:00.000+0000","lastPublished":"2026-08-05T16:00:00.000+0000","workflowStatus":null,"id":1,"name":"Cisco Security Advisory","url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-infodisc-qBXjfmWm","severity":"Medium","workarounds":"No","cwe":"CWE-532","cve":"CVE-2026-20289","ciscoBugId":"CSCwu64817","status":"New","summary":"A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive information.This vulnerability is due to the logging of sensitive information. An attacker could exploit this vulnerability by enabling a ","totalCount":62626,"relatedResource":[]},{"identifier":"cisco-sa-iosxe-snmp-dos-ZAqNm4MD","title":"Cisco IOS XE Software SNMP Denial of Service Vulnerability","version":"1.0","firstPublished":"2026-08-05T16:00:00.000+0000","lastPublished":"2026-08-05T16:00:00.000+0000","workflowStatus":null,"id":1,"name":"Cisco Security Advisory","url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-snmp-dos-ZAqNm4MD","severity":"High","workarounds":"No","cwe":"CWE-772","cve":"CVE-2026-20124","ciscoBugId":"CSCws90638","status":"New","summary":"A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition.This vulnerability is due to improper error ","totalCount":62626,"relatedResource":[]},{"identifier":"cisco-sa-iosxe-bing-MGHrFAkd","title":"Cisco IOS XE Software Blocks Extensible Exchange Protocol Denial of Service Vulnerability","version":"1.0","firstPublished":"2026-08-05T16:00:00.000+0000","lastPublished":"2026-08-05T16:00:00.000+0000","workflowStatus":null,"id":1,"name":"Cisco Security Advisory","url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-iosxe-bing-MGHrFAkd","severity":"High","workarounds":"No","cwe":"CWE-388","cve":"CVE-2026-20263","ciscoBugId":"CSCwu46548","status":"New","summary":"A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.This vulnerability is due to improper handling when parsing a specific ","totalCount":62626,"relatedResource":[]},{"identifier":"cisco-sa-ios-xmcp-thbAr34t","title":"Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerability","version":"1.0","firstPublished":"2026-08-05T16:00:00.000+0000","lastPublished":"2026-08-05T16:00:00.000+0000","workflowStatus":null,"id":1,"name":"Cisco Security Advisory","url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ios-xmcp-thbAr34t","severity":"High","workarounds":"No","cwe":"CWE-606","cve":"CVE-2026-20301","ciscoBugId":"CSCwu20827","status":"New","summary":"A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.This ","totalCount":62626,"relatedResource":[]},{"identifier":"cisco-sa-hardening-sdwan-faLcR3K","title":"Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026","version":"1.0","firstPublished":"2026-08-05T16:00:00.000+0000","lastPublished":"2026-08-05T16:00:00.000+0000","workflowStatus":null,"id":1,"name":"Cisco Security Advisory","url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-sdwan-faLcR3K","severity":"Critical","workarounds":"No","cwe":"CWE-1284, CWE-20, CWE-284, CWE-312, CWE-59","cve":"CVE-2026-20303,CVE-2026-20304,CVE-2026-20310,CVE-2026-20312,CVE-2026-20313","ciscoBugId":"","status":"New","summary":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered ","totalCount":62626,"relatedResource":[{"type":"Snort","values":[{"name":"66899","url":""}]}]},{"identifier":"cisco-sa-hardening-iosxe-V8NMuMZJ","title":"Cisco IOS XE Software Security Hardening Release: August 2026","version":"1.0","firstPublished":"2026-08-05T16:00:00.000+0000","lastPublished":"2026-08-05T16:00:00.000+0000","workflowStatus":null,"id":1,"name":"Cisco Security Advisory","url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxe-V8NMuMZJ","severity":"Critical","workarounds":"No","cwe":"CWE-119, CWE-20, CWE-284, CWE-664, CWE-682, CWE-691, CWE-74","cve":"CVE-2026-20267,CVE-2026-20268,CVE-2026-20269,CVE-2026-20270,CVE-2026-20271,CVE-2026-20272,CVE-2026-20273","ciscoBugId":"","status":"New","summary":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered ","totalCount":62626,"relatedResource":[{"type":"Snort","values":[{"name":"66891-66896","url":""},{"name":"66897-66898","url":""}]}]},{"identifier":"cisco-sa-cimc-xss-7EhBFxBp","title":"Cisco Integrated Management Controller Cross-Site Scripting Vulnerability","version":"1.0","firstPublished":"2026-08-05T16:00:00.000+0000","lastPublished":"2026-08-05T16:00:00.000+0000","workflowStatus":null,"id":1,"name":"Cisco Security Advisory","url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-xss-7EhBFxBp","severity":"Medium","workarounds":"No","cwe":"CWE-79","cve":"CVE-2026-20198","ciscoBugId":"CSCwt96899,CSCwu66661,CSCwu66669","status":"New","summary":"A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface.This vulnerability is due to insufficient validation of ","totalCount":62626,"relatedResource":[{"type":"White Paper","values":[{"name":"Cross-Site Scripting","url":"https://owasp.org/www-community/attacks/xss/"}]}]},{"identifier":"cisco-sa-cimc-arg-inject-upSHdMfU","title":"Cisco Integrated Management Controller Argument Injection Vulnerabilities","version":"1.0","firstPublished":"2026-08-05T16:00:00.000+0000","lastPublished":"2026-08-05T16:00:00.000+0000","workflowStatus":null,"id":1,"name":"Cisco Security Advisory","url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU","severity":"High","workarounds":"No","cwe":"CWE-141, CWE-146","cve":"CVE-2026-20200,CVE-2026-20288","ciscoBugId":"CSCwt16342,CSCwt45063,CSCwu57141,CSCwu57142","status":"New","summary":"Multiple vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to ","totalCount":62626,"relatedResource":[]},{"identifier":"cisco-sa-onprem-fmc-authbypass-5JPp45V2","title":"Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability","version":"2.4","firstPublished":"2026-03-04T16:00:00.000+0000","lastPublished":"2026-08-05T14:37:42.933+0000","workflowStatus":null,"id":1,"name":"Cisco Security Advisory","url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2","severity":"Critical","workarounds":"No","cwe":"CWE-288","erpPubIds":"ERP-75736","cve":"CVE-2026-20079","ciscoBugId":"CSCwr96008,CSCwt95974","status":"Updated","summary":"A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating ","totalCount":62626,"relatedResource":[{"type":"Snort","values":[{"name":"66075-66080","url":"https://www.snort.org/"}]},{"type":"Event Response Page","values":[{"name":"Cisco Event Response: March 2026 Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication","url":"https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75736&typeName=Event Response Page"}]}]},{"identifier":"cisco-sa-sdwan-privesc-4uxFrdzx","title":"Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerability","version":"1.10","firstPublished":"2026-06-04T22:27:00.000+0000","lastPublished":"2026-07-21T16:01:27.067+0000","workflowStatus":null,"id":1,"name":"Cisco Security Advisory","url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-privesc-4uxFrdzx","severity":"High","workarounds":"No","cwe":"CWE-116","cve":"CVE-2026-20245","ciscoBugId":"CSCwu18563","status":"","summary":"A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as ","totalCount":62626,"relatedResource":[]},{"identifier":"cisco-sa-ise-xss-42tgsdMG","title":"Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities","version":"1.3","firstPublished":"2025-02-05T16:00:00.000+0000","lastPublished":"2026-07-20T15:47:15.003+0000","workflowStatus":null,"id":1,"name":"Cisco Security Advisory","url":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xss-42tgsdMG","severity":"Medium","workarounds":"No","cwe":"CWE-79","cve":"CVE-2025-20204,CVE-2025-20205","ciscoBugId":"CSCwm38652","status":"","summary":"Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) guest portals could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities are due to ","totalCount":62626,"relatedResource":[{"type":"White Paper","values":[{"name":"Cross-Site Scripting","url":"https://owasp.org/www-community/attacks/xss/"}]}]}]