Advertisement
CISA Adds 8 Flaws to KEV: Cisco and PaperCut Exploited in the Wild
CISA adds 8 vulnerabilities to its KEV catalog, including PaperCut and Cisco SD-WAN Manager flaws, with federal patching deadlines set for May 2026.
Cisco Webex Services CVE-2024-20419: Manual Patch Guidance
Cisco identifies a critical improper certificate validation flaw in Webex Services. This advisory details the required manual remediation steps for admins.
Cisco Patches Critical RCE and SSO Flaws in ISE and Webex Services
Cisco releases patches for four critical vulnerabilities, including CVE-2026-20184, which allows RCE and user impersonation in Identity Services and Webex.
Cisco FMC Zero-Day Exploited by Interlock Ransomware: March 2026 CVEs
Runtime Rebel analyzes March 2026's significant rise in high-impact CVEs, including a Cisco FMC zero-day actively exploited by Interlock Ransomware.
TeamPCP Supply Chain Campaign: Cisco Source Code Stolen, UNC6780 Activity
Analysis of the TeamPCP supply chain campaign, including the theft of Cisco source code and over 1,000 compromised SaaS environments tracked by Google GTIG as UNC6780.
Claude Mythos Identifies Thousands of Zero-Day Flaws in Major Systems
Anthropic's Project Glasswing uses the Claude Mythos AI model to uncover thousands of zero-day vulnerabilities across infrastructure from AWS, Google, and Cisco.
Cisco IMC and SSM RCE via CVE-2026-20093 — Mitigation Guide
Cisco patches a critical 9.8 CVSS vulnerability in Integrated Management Controller (IMC) allowing unauthenticated remote attackers to gain full system access.
CVE-2024-20359: Cisco IMC Auth Bypass Grants Admin Access
Cisco IMC critical authentication bypass (CVE-2024-20359) allows unauthenticated attackers admin access. Learn about the vulnerability and urgent patch guidance.
Cisco Source Code Stolen: Trivy Supply Chain Attack Leads to Breach
Threat actors breached Cisco's dev environment using credentials from a Trivy supply chain attack, stealing proprietary and customer source code.
CVE-2026-20131: Cisco FMC/SCC Deserialization Vulnerability Under Active Attack
CISA adds CVE-2026-20131, a critical deserialization vulnerability in Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC), to KEV Catalog due…
Interlock Ransomware Targets Cisco Firewalls via CVE-2024-20481
Interlock ransomware operators exploited a critical Cisco ASA vulnerability before public disclosure. Learn how to detect and mitigate these targeted attacks.
CVE-2024-20481: Critical Cisco FMC RCE Exploited in the Wild
CISA mandates federal agencies patch CVE-2024-20481, a 9.8 CVSS RCE vulnerability in Cisco Secure Firewall Management Center, following active exploitation.
CISA KEV Update: CVE-2025-66376 Zimbra and SharePoint Exploits
CISA warns of active exploitation for Zimbra CVE-2025-66376, SharePoint flaws, and Cisco zero-days used in ransomware attacks. Secure your systems now.
CVE-2026-20131: Interlock Ransomware Exploits Cisco FMC — Patch Now
Interlock ransomware actors are exploiting CVE-2026-20131, a critical 10.0 CVSS zero-day in Cisco FMC, to gain unauthenticated root access and deploy malware.
Cisco SD-WAN vManage RCE: Fake PoCs & CVE-2023-20252 Exploitation
Threat intelligence reveals fake PoCs for Cisco SD-WAN vManage CVE-2023-20252. Understand actual RCE risks and critical patching for affected systems.
Cisco IOS XR Software Vulnerabilities: CVE-2024-20320 Patch Guide
Cisco addresses high-severity vulnerabilities in IOS XR Software, including SSH privilege escalation and DoS flaws. Essential mitigation steps for network admins.
CVE-2026-20127: Cisco Catalyst SD-WAN Exploited — Patch Guide
WatchTowr reports widespread exploitation attempts targeting a recent CVE-2026-20127 vulnerability in Cisco Catalyst SD-WAN devices, urging immediate action.
CVE-2026-20122: Cisco Catalyst SD-WAN Manager Exploited in the Wild
Cisco confirms active exploitation of CVE-2026-20122 in Catalyst SD-WAN Manager, allowing authenticated attackers to perform arbitrary file overwrites.
Cisco Catalyst SD-WAN Manager Exploitation: Patch CVE-2024-20437 Now
Cisco confirms active exploitation of two high-severity flaws in Catalyst SD-WAN Manager, involving hardcoded credentials and authentication bypass.
Cisco Catalyst SD-WAN Manager CVE-2023-20252 — Mitigation Guide
Cisco warns of active exploitation targeting Catalyst SD-WAN Manager vulnerabilities CVE-2023-20252 and CVE-2023-20253. Immediate patching is required.
Cisco Secure FMC Root Access & DoS Flaws Patched: Update Now
Cisco addresses two maximum-severity vulnerabilities in Secure Firewall Management Center (FMC) allowing unauthenticated root access and denial of service.
Cisco SD-WAN Zero-Day Under Exploitation for 3 Years
A critical zero-day vulnerability, CVE-2026-20127, in Cisco SD-WAN has been actively exploited by a sophisticated threat actor for three years.
Cisco SD-WAN Zero-Day CVE-2026-20127 Exploited for Admin Access
CVE-2026-20127 is a critical CVSS 10.0 flaw in Cisco SD-WAN controllers exploited since 2023, allowing unauthenticated remote administrative access.
Cisco SD-WAN Exploitation: Critical Authentication Bypass & Escalation
CISA alerts on active global exploitation of Cisco SD-WAN, leveraging CVE-2026-20127 for initial access and CVE-2022-20775 for privilege escalation.