Tag

#Cisco

28 stories taggedCisco · page 2 of 2.

Photoreal news-editorial style, 16:9 framing, edge-to-edge composition
Vulnerabilities

Cisco Phone System Flaw Now Being Actively Exploited — Patch Immediately

A security hole in Cisco's business phone software is being used in real attacks. Millions of offices run this software. The fix has existed since June.

3 min read
Vulnerabilities

Cisco Catalyst SD-WAN Bug Hit as Zero-Day Months Before Disclosure

Mandiant says an unidentified actor exploited CVE-2026-20245 for at least two months before Cisco's public advisory, gaining root on affected appliances.

2 min read
Vulnerabilities

Cisco Unified CM SSRF Flaw Hits Active Exploitation Three Weeks After Patch Drop

A file-write chain rooted in CVE-2026-20230 is now being probed in the wild. PoC was already public when Cisco shipped the fix.

2 min read
Vulnerabilities

Cisco Unified CM Bug Under Active Exploit After PoC Drops Root File-Write Chain

CVE-2026-20230 (CVSS 8.6) lets unauthenticated attackers smuggle crafted HTTP requests into Unified CM. Cisco's PSIRT confirms in-the-wild attempts following public PoC release.

2 min read
Identity & Access

Cisco Acquires WideField Security to Wire Identity Intelligence Into Splunk's Agentic SOC

The deal adds credential, session, and blast-radius visibility to Splunk's autonomous detection pipeline — filling a gap that pure log-correlation has always struggled with.

2 min read
Vulnerabilities

Cisco's SD-WAN Manager Has a Write-to-Root Problem — and Attackers Found It First

CVE-2026-20262 lets an authenticated attacker overwrite arbitrary files on Cisco Catalyst SD-WAN Manager, with a clear path to root. No workaround exists. Exploitation is already underway.

2 min read
Vulnerabilities

Cisco Patches Catalyst SD-WAN Manager Bug Already Seeing In-the-Wild Abuse

CVE-2026-20262 lets an authenticated remote user write files on the appliance. Cisco confirms exploitation. Severity is rated medium, but the access it enables is not.

2 min read
Policy & Regulation

CISA Triggers Federal Patch Clock on Cisco, Chrome and Arista Bugs Under KEV

Three vulnerabilities added to the Known Exploited Vulnerabilities catalog activate BOD 22-01 remediation deadlines for civilian agencies.

2 min read
Vulnerabilities

Cisco SD-WAN Manager Has an Unpatched Privilege-Escalation Flaw Under Active Exploitation

A command-injection bug in Catalyst SD-WAN Manager is already being used in the wild. No patch exists yet — and a known espionage group may be involved.

2 min read
Vulnerabilities

Cisco SD-WAN Manager Bug Under Active Exploit, No Fix Yet

CVE-2026-20245 affects on-prem and FedRAMP deployments. Cisco confirms exploitation in the wild while customers wait on a patch.

2 min read
Vulnerabilities

Public PoC Lands for Cisco Unified CM Root-Write Bug CVE-2026-20230

An unauthenticated SSRF in Cisco Unified Communications Manager opens a path to root. Cisco's PSIRT hasn't observed in-the-wild use — yet.

2 min read
Vulnerabilities

Cisco Secure Workload Flaw Demands Immediate Attention

Cisco Secure Workload vulnerability allows attackers admin-level access; patch now.

2 min read
Vulnerabilities

Cisco's Secure Workload Earns a Perfect 10, in the Wrong Sense

An unauthenticated REST API flaw rated CVSS 10.0 lets remote attackers help themselves to sensitive data. Cisco has issued fixes.

2 min read
© 2026 Threat Vectr