<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>PhllapsNET</title>
    <link>https://www.phllaps.net/</link>
    <description>Recent content on PhllapsNET</description>
    <generator>Hugo</generator>
    <language>en-gb</language>
    <lastBuildDate>Sun, 23 Aug 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://www.phllaps.net/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Auditing a homelab after it breaks: what the documentation got wrong</title>
      <link>https://www.phllaps.net/blog/auditing-a-homelab-after-it-breaks/</link>
      <pubDate>Sun, 23 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/blog/auditing-a-homelab-after-it-breaks/</guid>
      <description>&lt;p&gt;Something in my homelab fell over. I got it back, and then I did the thing I&#xA;would have told anyone else to do first: I went through the machines properly and&#xA;compared what was actually running to what my notes said was running.&lt;/p&gt;&#xA;&lt;p&gt;Six things were wrong. What struck me afterwards was not that there were six — it&#xA;was that all six were wrong in the same direction. Every one of them was a case&#xA;of the documentation faithfully recording what I had &lt;em&gt;intended&lt;/em&gt;, and never being&#xA;corrected when reality went somewhere else.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Contact</title>
      <link>https://www.phllaps.net/contact/</link>
      <pubDate>Sat, 22 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/contact/</guid>
      <description>&lt;h2 id=&#34;email&#34;&gt;Email&lt;/h2&gt;&#xA;&lt;p&gt;&lt;strong&gt;&lt;a href=&#34;mailto:admin@phllaps.net&#34;&gt;admin@phllaps.net&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;That address reaches me directly. I read everything, and I answer most things.&lt;/p&gt;&#xA;&lt;h2 id=&#34;corrections&#34;&gt;Corrections&lt;/h2&gt;&#xA;&lt;p&gt;If a post gets a detail wrong — an affected version, a fixed release, a product&#xA;that is not actually impacted — please say so. Include the post URL and, if you&#xA;have it, the vendor advisory section that contradicts it. Corrections are made in&#xA;place and noted on the post.&lt;/p&gt;&#xA;&lt;p&gt;Getting this right matters more to me than being first, so a correction is a&#xA;favour rather than a complaint.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Methodology</title>
      <link>https://www.phllaps.net/methodology/</link>
      <pubDate>Sat, 22 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/methodology/</guid>
      <description>&lt;p&gt;This page describes how advisories on this site are selected, sourced and&#xA;checked. It exists so you can judge how much weight to put on anything here.&lt;/p&gt;&#xA;&lt;h2 id=&#34;sources&#34;&gt;Sources&lt;/h2&gt;&#xA;&lt;p&gt;Only structured, machine-readable feeds published by the vendor or by CISA are&#xA;used. Nothing on this site comes from scraping a listing page or from&#xA;second-hand reporting.&lt;/p&gt;&#xA;&lt;table&gt;&#xA;  &lt;thead&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;th&gt;Source&lt;/th&gt;&#xA;          &lt;th&gt;What it provides&lt;/th&gt;&#xA;      &lt;/tr&gt;&#xA;  &lt;/thead&gt;&#xA;  &lt;tbody&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;CISA Known Exploited Vulnerabilities catalogue (JSON)&lt;/td&gt;&#xA;          &lt;td&gt;The primary trigger. If CISA says a flaw is being exploited, that is the strongest signal available and it outranks the severity score.&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Cisco PSIRT — per-advisory CSAF JSON&lt;/td&gt;&#xA;          &lt;td&gt;The richest structured data of any vendor: per-CVE CVSS, full product tree, and first-fixed release tables.&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Fortinet PSIRT feed&lt;/td&gt;&#xA;          &lt;td&gt;Discovery, with CVSS in the advisory description.&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Palo Alto Networks feed&lt;/td&gt;&#xA;          &lt;td&gt;Discovery, with CVE identifier and severity in the item title.&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;NVD 2.0 API&lt;/td&gt;&#xA;          &lt;td&gt;Enrichment. Authoritative CVSS base score, vector string and description.&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;  &lt;/tbody&gt;&#xA;&lt;/table&gt;&#xA;&lt;p&gt;Three vendors worth naming explicitly — &lt;strong&gt;Juniper, Ivanti and F5&lt;/strong&gt; — publish no&#xA;usable structured feed. Their advisories are covered here by CVE, through KEV and&#xA;NVD, which catches the case that matters most: confirmed exploitation.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Proxmox on a second-hand workstation</title>
      <link>https://www.phllaps.net/blog/proxmox-on-a-second-hand-workstation/</link>
      <pubDate>Sat, 22 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/blog/proxmox-on-a-second-hand-workstation/</guid>
      <description>&lt;p&gt;The machine running most of my home lab is a Lenovo ThinkStation P700 that cost&#xA;less than a mid-range mini PC. It has a Xeon E5-2699 v3 in it, which is eighteen&#xA;cores of 2014-era server silicon that nobody particularly wants any more, and it&#xA;has been more useful than anything else I have bought for the lab.&lt;/p&gt;&#xA;&lt;p&gt;This isn&amp;rsquo;t a build guide. Proxmox installs itself in about ten minutes and the&#xA;official documentation is good. It&amp;rsquo;s about the three decisions that turned out to&#xA;matter, most of which I got wrong the first time.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Running image and speech generation at home</title>
      <link>https://www.phllaps.net/blog/self-hosted-image-and-speech-generation/</link>
      <pubDate>Sat, 22 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/blog/self-hosted-image-and-speech-generation/</guid>
      <description>&lt;p&gt;I generate images, short video clips and narration at home, on one graphics card.&#xA;Most of what I&amp;rsquo;ve learned isn&amp;rsquo;t about model quality — the models are all&#xA;astonishing and they all get better every few weeks. It&amp;rsquo;s about the boring&#xA;constraints around them: how long things take, how much memory they need, and&#xA;whether you&amp;rsquo;re allowed to use what comes out.&lt;/p&gt;&#xA;&lt;h2 id=&#34;the-gpu-decides-everything-and-it-decides-it-by-vram&#34;&gt;The GPU decides everything, and it decides it by VRAM&lt;/h2&gt;&#xA;&lt;p&gt;The number that determines what you can run is video memory. Not the core count,&#xA;not the generation. A card with 24GB will run things a faster card with 16GB&#xA;simply cannot load.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Selling digital products: what actually has to be true</title>
      <link>https://www.phllaps.net/blog/selling-digital-products-what-actually-has-to-be-true/</link>
      <pubDate>Sat, 22 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/blog/selling-digital-products-what-actually-has-to-be-true/</guid>
      <description>&lt;p&gt;The technical side of selling something digital is genuinely easy now. A payment&#xA;processor, a file, an automated delivery email — an afternoon&amp;rsquo;s work, and the&#xA;platform takes a small cut and handles the tax.&lt;/p&gt;&#xA;&lt;p&gt;That isn&amp;rsquo;t the hard part, and the fact that it&amp;rsquo;s easy is why so much of the advice&#xA;about it is worthless. Anybody can describe how to set up a checkout page. Almost&#xA;nobody wants to talk about the four things that determine whether anyone buys.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Six lessons from automation that runs while you sleep</title>
      <link>https://www.phllaps.net/blog/lessons-from-automating-things-that-run-unattended/</link>
      <pubDate>Sat, 22 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/blog/lessons-from-automating-things-that-run-unattended/</guid>
      <description>&lt;p&gt;Most of what I run at home runs without me. Jobs fire on timers, do work, publish&#xA;results, and tell me only if something interesting happened. That&amp;rsquo;s the point of&#xA;automation and it&amp;rsquo;s also the danger of it, because a job nobody watches can be&#xA;broken for two weeks before anyone notices.&lt;/p&gt;&#xA;&lt;p&gt;These all cost me something. None of them are clever. Most read as obvious and&#xA;weren&amp;rsquo;t obvious until they&amp;rsquo;d happened to me.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Video as code: Remotion, and where an LLM actually helps</title>
      <link>https://www.phllaps.net/blog/video-as-code-remotion-and-an-llm/</link>
      <pubDate>Sat, 22 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/blog/video-as-code-remotion-and-an-llm/</guid>
      <description>&lt;p&gt;Remotion lets you describe a video as React components and render it frame by&#xA;frame to a file. You write a composition, every component is told which frame it&#xA;is on, and a headless browser draws each one in turn.&lt;/p&gt;&#xA;&lt;p&gt;It&amp;rsquo;s a genuinely different way to think about video, and the difference that&#xA;matters isn&amp;rsquo;t that it&amp;rsquo;s programmable. It&amp;rsquo;s that video becomes text in a&#xA;repository — diffable, reviewable, and, which is the part that changes what&amp;rsquo;s&#xA;possible, generatable.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Microsoft Entra ID Deserialization of Untrusted Data Vulnerability</title>
      <link>https://www.phllaps.net/posts/microsoft-entra-id-deserialization-of-untrusted-data-vulnerability/</link>
      <pubDate>Fri, 21 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/microsoft-entra-id-deserialization-of-untrusted-data-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#b91c1c;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&lt;span&gt;SEVERITY: CRITICAL — CVSS 10.0&lt;/span&gt;&lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Microsoft Entra ID formerly known as Azure Active Directory contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network.&lt;/li&gt;&#xA;&lt;li&gt;Highest CVSS: &lt;strong&gt;10.0 (Critical)&lt;/strong&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Listed in CISA KEV&lt;/strong&gt; (2026-08-21) — this is being exploited in the wild.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Check the advisory for fixed releases&lt;/strong&gt; — remediation detail is in the vendor link below.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2026-69836.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-it-is&#34;&gt;What it is&lt;/h2&gt;&#xA;&lt;p&gt;CVE-2026-69836 is a deserialization of untrusted data vulnerability in Microsoft Entra ID (formerly Azure Active Directory). Deserialization flaws of this type typically arise when an application reconstructs objects from attacker-supplied data without adequately validating it first, allowing crafted input to trigger unintended code execution.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability</title>
      <link>https://www.phllaps.net/posts/zimbra-collaboration-suite-zcs-os-command-injection-vulnerability/</link>
      <pubDate>Fri, 21 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/zimbra-collaboration-suite-zcs-os-command-injection-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&lt;span&gt;SEVERITY: HIGH — CVSS 8.9&lt;/span&gt;&lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.&lt;/li&gt;&#xA;&lt;li&gt;Highest CVSS: &lt;strong&gt;8.9 (High)&lt;/strong&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Listed in CISA KEV&lt;/strong&gt; (2026-08-21) — this is being exploited in the wild.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Check the advisory for fixed releases&lt;/strong&gt; — remediation detail is in the vendor link below.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2026-73570.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-it-is&#34;&gt;What it is&lt;/h2&gt;&#xA;&lt;p&gt;CVE-2026-73570 is an OS command injection vulnerability in Zimbra Collaboration Suite (ZCS), reported by Synacor. The flaw sits in how ZCS handles SMTP requests: a specially crafted SMTP request can trigger execution of arbitrary operating system commands, running as the Zimbra user.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TrueConf Server Code Injection Vulnerability</title>
      <link>https://www.phllaps.net/posts/trueconf-server-code-injection-vulnerability/</link>
      <pubDate>Thu, 20 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/trueconf-server-code-injection-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#b91c1c;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&lt;span&gt;SEVERITY: CRITICAL — CVSS 9.0&lt;/span&gt;&lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.&lt;/li&gt;&#xA;&lt;li&gt;Highest CVSS: &lt;strong&gt;9.0 (Critical)&lt;/strong&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Listed in CISA KEV&lt;/strong&gt; (2026-08-20) — this is being exploited in the wild.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Check the advisory for fixed releases&lt;/strong&gt; — remediation detail is in the vendor link below.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2026-72530.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-it-is&#34;&gt;What it is&lt;/h2&gt;&#xA;&lt;p&gt;CVE-2026-72530 is a code injection vulnerability in TrueConf Server. An attacker with network access to port 4307/TCP can submit a specially crafted script that breaks out of the server&amp;rsquo;s isolated execution environment and runs arbitrary code on the underlying host.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TrueConf Server Missing Authentication for Critical Function Vulnerability</title>
      <link>https://www.phllaps.net/posts/trueconf-server-missing-authentication-for-critical-function-vulnerability/</link>
      <pubDate>Thu, 20 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/trueconf-server-missing-authentication-for-critical-function-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#b91c1c;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&lt;span&gt;SEVERITY: CRITICAL — CVSS 9.8&lt;/span&gt;&lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.&lt;/li&gt;&#xA;&lt;li&gt;Highest CVSS: &lt;strong&gt;9.8 (Critical)&lt;/strong&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Listed in CISA KEV&lt;/strong&gt; (2026-08-20) — this is being exploited in the wild.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Check the advisory for fixed releases&lt;/strong&gt; — remediation detail is in the vendor link below.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2026-72529.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-it-is&#34;&gt;What it is&lt;/h2&gt;&#xA;&lt;p&gt;CVE-2026-72529 is a missing authentication for critical function vulnerability in TrueConf Server. A critical function is reachable over the network on port 4307/TCP without any authentication check.&lt;/p&gt;</description>
    </item>
    <item>
      <title>MLflow Server-Side Request Forgery Vulnerability</title>
      <link>https://www.phllaps.net/posts/mlflow-server-side-request-forgery-vulnerability/</link>
      <pubDate>Wed, 19 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/mlflow-server-side-request-forgery-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#b91c1c;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&lt;span&gt;SEVERITY: CRITICAL — CVSS 9.3&lt;/span&gt;&lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;MLflow contains a server-side request forgery vulnerability that can allow attackers to reach internal or cloud metadata services and receive response_status and response_body.&lt;/li&gt;&#xA;&lt;li&gt;Highest CVSS: &lt;strong&gt;9.3 (Critical)&lt;/strong&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Listed in CISA KEV&lt;/strong&gt; (2026-08-19) — this is being exploited in the wild.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Check the advisory for fixed releases&lt;/strong&gt; — remediation detail is in the vendor link below.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2026-64849.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-it-is&#34;&gt;What it is&lt;/h2&gt;&#xA;&lt;p&gt;CVE-2026-64849 is a server-side request forgery (SSRF) vulnerability in MLflow. The CVSS vector indicates the flaw is reachable over the network, requires no authentication and no user interaction, and can be exploited with low attack complexity.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Apple macOS Improper Authentication Vulnerability</title>
      <link>https://www.phllaps.net/posts/apple-macos-improper-authentication-vulnerability/</link>
      <pubDate>Tue, 18 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/apple-macos-improper-authentication-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#b91c1c;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&lt;span&gt;SEVERITY: CRITICAL — CVSS 9.8&lt;/span&gt;&lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials.&lt;/li&gt;&#xA;&lt;li&gt;Highest CVSS: &lt;strong&gt;9.8 (Critical)&lt;/strong&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Listed in CISA KEV&lt;/strong&gt; (2026-08-18) — this is being exploited in the wild.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Check the advisory for fixed releases&lt;/strong&gt; — remediation detail is in the vendor link below.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2026-65400.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-it-is&#34;&gt;What it is&lt;/h2&gt;&#xA;&lt;p&gt;CVE-2026-65400 is an improper authentication flaw in macOS Screen Sharing. The vulnerability allows an attacker on the network to authenticate to Screen Sharing without supplying valid credentials.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Broadcom VMware vCenter Path Traversal Vulnerability</title>
      <link>https://www.phllaps.net/posts/broadcom-vmware-vcenter-path-traversal-vulnerability/</link>
      <pubDate>Tue, 18 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/broadcom-vmware-vcenter-path-traversal-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#b91c1c;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&lt;span&gt;SEVERITY: CRITICAL — CVSS 9.8&lt;/span&gt;&lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code.&lt;/li&gt;&#xA;&lt;li&gt;Highest CVSS: &lt;strong&gt;9.8 (Critical)&lt;/strong&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Listed in CISA KEV&lt;/strong&gt; (2026-08-18) — this is being exploited in the wild.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Check the advisory for fixed releases&lt;/strong&gt; — remediation detail is in the vendor link below.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2026-59310.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-it-is&#34;&gt;What it is&lt;/h2&gt;&#xA;&lt;p&gt;CVE-2026-59310 is a path traversal vulnerability in Broadcom VMware vCenter. It has a CVSS score of 9.8 (Critical), with a vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — meaning it is reachable over the network, requires low attack complexity, needs no privileges and no user interaction, and results in full compromise of confidentiality, integrity and availability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability</title>
      <link>https://www.phllaps.net/posts/microsoft-internet-key-exchange-ike-service-extensions-double-free-vulnerability/</link>
      <pubDate>Tue, 18 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/microsoft-internet-key-exchange-ike-service-extensions-double-free-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#b91c1c;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&lt;span&gt;SEVERITY: CRITICAL — CVSS 9.8&lt;/span&gt;&lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution.&lt;/li&gt;&#xA;&lt;li&gt;Highest CVSS: &lt;strong&gt;9.8 (Critical)&lt;/strong&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Listed in CISA KEV&lt;/strong&gt; (2026-08-18) — this is being exploited in the wild.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Check the advisory for fixed releases&lt;/strong&gt; — remediation detail is in the vendor link below.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2026-33824.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-it-is&#34;&gt;What it is&lt;/h2&gt;&#xA;&lt;p&gt;CVE-2026-33824 is a double free vulnerability in Microsoft&amp;rsquo;s Internet Key Exchange (IKE) Service Extensions. The IKE service handles key negotiation for IPsec, and on Windows this typically runs as part of the IKE/AuthIP IPsec Keying Modules service, which listens on the network to negotiate security associations with peers.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Microsoft SharePoint Weak Authentication Vulnerability</title>
      <link>https://www.phllaps.net/posts/microsoft-sharepoint-weak-authentication-vulnerability/</link>
      <pubDate>Tue, 18 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/microsoft-sharepoint-weak-authentication-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#b91c1c;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&lt;span&gt;SEVERITY: CRITICAL — CVSS 9.1&lt;/span&gt;&lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.&lt;/li&gt;&#xA;&lt;li&gt;Highest CVSS: &lt;strong&gt;9.1 (Critical)&lt;/strong&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Listed in CISA KEV&lt;/strong&gt; (2026-08-18) — this is being exploited in the wild.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Check the advisory for fixed releases&lt;/strong&gt; — remediation detail is in the vendor link below.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2026-55040.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-it-is&#34;&gt;What it is&lt;/h2&gt;&#xA;&lt;p&gt;Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Ray-Project Ray Code Injection Vulnerability</title>
      <link>https://www.phllaps.net/posts/ray-project-ray-code-injection-vulnerability/</link>
      <pubDate>Tue, 18 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/ray-project-ray-code-injection-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#b91c1c;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&lt;span&gt;SEVERITY: CRITICAL — CVSS 9.4&lt;/span&gt;&lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari.&lt;/li&gt;&#xA;&lt;li&gt;Highest CVSS: &lt;strong&gt;9.4 (Critical)&lt;/strong&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Listed in CISA KEV&lt;/strong&gt; (2026-08-18) — this is being exploited in the wild.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Check the advisory for fixed releases&lt;/strong&gt; — remediation detail is in the vendor link below.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2025-62593.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-it-is&#34;&gt;What it is&lt;/h2&gt;&#xA;&lt;p&gt;Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-secure-firewall-adaptive-security-appliance-asa-and-secure-firewall-threat-defense-ftd-heap-inspection-v/</link>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-secure-firewall-adaptive-security-appliance-asa-and-secure-firewall-threat-defense-ftd-heap-inspection-v/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&lt;span&gt;SEVERITY: HIGH — CVSS 8.6&lt;/span&gt;&lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.&lt;/li&gt;&#xA;&lt;li&gt;Highest CVSS: &lt;strong&gt;8.6 (High)&lt;/strong&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Listed in CISA KEV&lt;/strong&gt; (2026-08-11) — this is being exploited in the wild.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Check the advisory for fixed releases&lt;/strong&gt; — remediation detail is in the vendor link below.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2026-20349.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-it-is&#34;&gt;What it is&lt;/h2&gt;&#xA;&lt;p&gt;CVE-2026-20349 is a heap inspection vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD). The flaw sits in the code handling heap memory on affected devices.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Metabase SQL Injection Vulnerability</title>
      <link>https://www.phllaps.net/posts/metabase-sql-injection-vulnerability/</link>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/metabase-sql-injection-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#b91c1c;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&lt;span&gt;SEVERITY: CRITICAL — CVSS 10.0&lt;/span&gt;&lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export…&lt;/li&gt;&#xA;&lt;li&gt;Highest CVSS: &lt;strong&gt;10.0 (Critical)&lt;/strong&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Listed in CISA KEV&lt;/strong&gt; (2026-08-11) — this is being exploited in the wild.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Check the advisory for fixed releases&lt;/strong&gt; — remediation detail is in the vendor link below.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2026-72898.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-it-is&#34;&gt;What it is&lt;/h2&gt;&#xA;&lt;p&gt;CVE-2026-72898 is a SQL injection vulnerability in Metabase. An unauthenticated remote attacker can inject arbitrary SQL into the Metabase application database over the network, with no user interaction required.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability</title>
      <link>https://www.phllaps.net/posts/microsoft-windows-ancillary-function-driver-for-winsock-use-after-free-vulnerability/</link>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/microsoft-windows-ancillary-function-driver-for-winsock-use-after-free-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&lt;span&gt;SEVERITY: HIGH — CVSS 7.0&lt;/span&gt;&lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.&lt;/li&gt;&#xA;&lt;li&gt;Highest CVSS: &lt;strong&gt;7.0 (High)&lt;/strong&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Listed in CISA KEV&lt;/strong&gt; (2026-08-11) — this is being exploited in the wild.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Check the advisory for fixed releases&lt;/strong&gt; — remediation detail is in the vendor link below.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2026-68820.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-it-is&#34;&gt;What it is&lt;/h2&gt;&#xA;&lt;p&gt;CVE-2026-68820 is a use-after-free vulnerability in the Ancillary Function Driver for WinSock (AFD.sys), the kernel-mode driver that underpins Windows socket operations. It sits on the local attack surface, not the network data plane: exploitation requires local access and low-privilege authentication on the target host.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Progress LoadMaster Command Injection Vulnerability</title>
      <link>https://www.phllaps.net/posts/progress-loadmaster-command-injection-vulnerability/</link>
      <pubDate>Fri, 07 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/progress-loadmaster-command-injection-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#b91c1c;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&lt;span&gt;SEVERITY: CRITICAL — CVSS 9.6&lt;/span&gt;&lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.&lt;/li&gt;&#xA;&lt;li&gt;Highest CVSS: &lt;strong&gt;9.6 (Critical)&lt;/strong&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Listed in CISA KEV&lt;/strong&gt; (2026-08-07) — this is being exploited in the wild.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Check the advisory for fixed releases&lt;/strong&gt; — remediation detail is in the vendor link below.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2026-8037.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-it-is&#34;&gt;What it is&lt;/h2&gt;&#xA;&lt;p&gt;CVE-2026-8037 is a command injection vulnerability in Progress LoadMaster, the vendor&amp;rsquo;s load balancer/ADC appliance. The flaw sits in multiple command endpoints where input is not properly sanitised before being passed through to the underlying system.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026</title>
      <link>https://www.phllaps.net/posts/cisco-catalyst-sd-wan-software-security-hardening-release-august-2026/</link>
      <pubDate>Wed, 05 Aug 2026 16:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-catalyst-sd-wan-software-security-hardening-release-august-2026/</guid>
      <description>&lt;div style=&#34;background:#b91c1c;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&lt;span&gt;SEVERITY: CRITICAL — CVSS 9.9&lt;/span&gt;&lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;As part of Cisco&amp;rsquo;s ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To…&lt;/li&gt;&#xA;&lt;li&gt;Highest CVSS: &lt;strong&gt;9.9 (Critical)&lt;/strong&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Fix available&lt;/strong&gt; — see the first fixed release below.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2026-20303, CVE-2026-20304, CVE-2026-20310.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-it-is&#34;&gt;What it is&lt;/h2&gt;&#xA;&lt;p&gt;As part of Cisco&amp;rsquo;s ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco IOS XE Software Security Hardening Release: August 2026</title>
      <link>https://www.phllaps.net/posts/cisco-ios-xe-software-security-hardening-release-august-2026/</link>
      <pubDate>Wed, 05 Aug 2026 16:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-ios-xe-software-security-hardening-release-august-2026/</guid>
      <description>&lt;div style=&#34;background:#b91c1c;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&lt;span&gt;SEVERITY: CRITICAL — CVSS 9.8&lt;/span&gt;&lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;As part of Cisco&amp;rsquo;s ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To…&lt;/li&gt;&#xA;&lt;li&gt;Highest CVSS: &lt;strong&gt;9.8 (Critical)&lt;/strong&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Fix available&lt;/strong&gt; — see the first fixed release below.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2026-20267, CVE-2026-20268, CVE-2026-20269.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-it-is&#34;&gt;What it is&lt;/h2&gt;&#xA;&lt;p&gt;This advisory covers seven CVEs found by Cisco&amp;rsquo;s own IOS XE engineering team during an internal security review, rather than through external reporting. Cisco has grouped the underlying bugs by CWE class and issued one CVE ID per class: CVE-2026-20267 (improper access control, CWE-284), CVE-2026-20268 (memory buffer bounds issues, CWE-119), CVE-2026-20269 (resource lifetime handling, CWE-664), CVE-2026-20270 (incorrect calculation, CWE-682), CVE-2026-20271 (control flow issues such as race conditions or uncontrolled recursion, CWE-691), CVE-2026-20272 (improper neutralisation of special elements, CWE-74, i.e. injection), and CVE-2026-20273 (improper input validation, CWE-20).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-secure-firewall-management-center-software-authentication-bypass-vulnerability/</link>
      <pubDate>Wed, 05 Aug 2026 14:37:42 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-secure-firewall-management-center-software-authentication-bypass-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#b91c1c;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&lt;span&gt;SEVERITY: CRITICAL — CVSS 10.0&lt;/span&gt;&lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time.…&lt;/li&gt;&#xA;&lt;li&gt;Highest CVSS: &lt;strong&gt;10.0 (Critical)&lt;/strong&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Check the advisory for fixed releases&lt;/strong&gt; — remediation detail is in the vendor link below.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2026-20079.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-it-is&#34;&gt;What it is&lt;/h2&gt;&#xA;&lt;p&gt;CVE-2026-20079 is an authentication bypass in the web interface of Cisco Secure Firewall Management Center (FMC) Software. It carries a CVSS score of 10.0 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) — network-exploitable, no privileges, no user interaction, and full impact on confidentiality, integrity and availability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>JetBrains TeamCity Deserialization of Untrusted Data Vulnerability</title>
      <link>https://www.phllaps.net/posts/jetbrains-teamcity-deserialization-of-untrusted-data-vulnerability/</link>
      <pubDate>Wed, 05 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/jetbrains-teamcity-deserialization-of-untrusted-data-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#b91c1c;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&lt;span&gt;SEVERITY: CRITICAL — CVSS 9.8&lt;/span&gt;&lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol.&lt;/li&gt;&#xA;&lt;li&gt;Highest CVSS: &lt;strong&gt;9.8 (Critical)&lt;/strong&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Listed in CISA KEV&lt;/strong&gt; (2026-08-05) — this is being exploited in the wild.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Check the advisory for fixed releases&lt;/strong&gt; — remediation detail is in the vendor link below.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2026-63077.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-it-is&#34;&gt;What it is&lt;/h2&gt;&#xA;&lt;p&gt;CVE-2026-63077 is a deserialisation of untrusted data vulnerability in JetBrains TeamCity. It sits in the agent polling protocol, which handles communication between TeamCity build agents and the server.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Apache Tomcat Missing Encryption of Sensitive Data Vulnerability</title>
      <link>https://www.phllaps.net/posts/apache-tomcat-missing-encryption-of-sensitive-data-vulnerability/</link>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/apache-tomcat-missing-encryption-of-sensitive-data-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&lt;span&gt;SEVERITY: HIGH — CVSS 7.5&lt;/span&gt;&lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.&lt;/li&gt;&#xA;&lt;li&gt;Highest CVSS: &lt;strong&gt;7.5 (High)&lt;/strong&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Listed in CISA KEV&lt;/strong&gt; (2026-08-04) — this is being exploited in the wild.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Check the advisory for fixed releases&lt;/strong&gt; — remediation detail is in the vendor link below.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2026-34486.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-it-is&#34;&gt;What it is&lt;/h2&gt;&#xA;&lt;p&gt;Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IBM Langflow Code Injection Vulnerability</title>
      <link>https://www.phllaps.net/posts/ibm-langflow-code-injection-vulnerability/</link>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/ibm-langflow-code-injection-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#b91c1c;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&lt;span&gt;SEVERITY: CRITICAL — CVSS 9.8&lt;/span&gt;&lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.&lt;/li&gt;&#xA;&lt;li&gt;Highest CVSS: &lt;strong&gt;9.8 (Critical)&lt;/strong&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Listed in CISA KEV&lt;/strong&gt; (2026-08-04) — this is being exploited in the wild.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Check the advisory for fixed releases&lt;/strong&gt; — remediation detail is in the vendor link below.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2026-9198.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-it-is&#34;&gt;What it is&lt;/h2&gt;&#xA;&lt;p&gt;CVE-2026-9198 is a code injection vulnerability in IBM Langflow. It allows an unauthenticated attacker to achieve full remote code execution on a default Langflow deployment.&lt;/p&gt;</description>
    </item>
    <item>
      <title>N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability</title>
      <link>https://www.phllaps.net/posts/n-able-n-central-authentication-bypass-using-an-alternate-path-or-channel-vulnerability-cve-2026-18556/</link>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/n-able-n-central-authentication-bypass-using-an-alternate-path-or-channel-vulnerability-cve-2026-18556/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&lt;span&gt;SEVERITY: HIGH — CVSS 7.4&lt;/span&gt;&lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.&lt;/li&gt;&#xA;&lt;li&gt;Highest CVSS: &lt;strong&gt;7.4 (High)&lt;/strong&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Listed in CISA KEV&lt;/strong&gt; (2026-08-04) — this is being exploited in the wild.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Check the advisory for fixed releases&lt;/strong&gt; — remediation detail is in the vendor link below.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2026-18556.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-it-is&#34;&gt;What it is&lt;/h2&gt;&#xA;&lt;p&gt;CVE-2026-18556 is an authentication bypass in N-able N-central, achieved by reaching the application through an alternate path or channel that skips the normal authentication check. The CVSS vector indicates this is exploitable over the network without authentication or user interaction, though attack complexity is rated high.&lt;/p&gt;</description>
    </item>
    <item>
      <title>N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability</title>
      <link>https://www.phllaps.net/posts/n-able-n-central-authentication-bypass-using-an-alternate-path-or-channel-vulnerability/</link>
      <pubDate>Mon, 03 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/n-able-n-central-authentication-bypass-using-an-alternate-path-or-channel-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&lt;span&gt;SEVERITY: HIGH — CVSS 8.1&lt;/span&gt;&lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.&lt;/li&gt;&#xA;&lt;li&gt;Highest CVSS: &lt;strong&gt;8.1 (High)&lt;/strong&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Listed in CISA KEV&lt;/strong&gt; (2026-08-03) — this is being exploited in the wild.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Check the advisory for fixed releases&lt;/strong&gt; — remediation detail is in the vendor link below.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2026-18577.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-it-is&#34;&gt;What it is&lt;/h2&gt;&#xA;&lt;p&gt;N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Catalyst Center Virtual Appliance Privilege Escalation Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-catalyst-center-virtual-appliance-privilege-escalation-vulnerability/</link>
      <pubDate>Thu, 13 Nov 2025 17:02:05 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-catalyst-center-virtual-appliance-privilege-escalation-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 8.8&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A privilege escalation vulnerability has been identified in the Cisco Catalyst Center Virtual Appliance, allowing authenticated attackers to elevate their privileges to Administrator. The highest CVSS score for this vulnerability is 8.8, categorized as High severity. No workarounds are available, but fixed software releases are provided.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the Cisco Catalyst Center Virtual Appliance could allow an authenticated, remote attacker to elevate their privileges to Administrator on an affected system. This issue arises from insufficient validation of user-supplied input. An attacker with valid credentials for a user account with at least the Observer role could exploit this vulnerability by sending a crafted HTTP request, potentially allowing unauthorized modifications to the system.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Catalyst Center REST API Command Injection Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-catalyst-center-rest-api-command-injection-vulnerability/</link>
      <pubDate>Thu, 13 Nov 2025 17:01:38 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-catalyst-center-rest-api-command-injection-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.3&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A command injection vulnerability has been identified in the Cisco Catalyst Center REST API, allowing authenticated attackers to execute arbitrary commands with root privileges. The highest CVSS score for this vulnerability is 6.3 (Medium). No workarounds are available, but fixed software is provided.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the REST API of Cisco Catalyst Center could allow an authenticated, remote attacker to execute arbitrary commands in a restricted container as the root user. This issue arises from insufficient validation of user-supplied input in REST API request parameters. An attacker must have valid credentials for a user account with at least the role of Observer to exploit this vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Catalyst Center Cross-Site Scripting Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-catalyst-center-cross-site-scripting-vulnerability/</link>
      <pubDate>Thu, 13 Nov 2025 17:01:18 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-catalyst-center-cross-site-scripting-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.1&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A cross-site scripting (XSS) vulnerability has been identified in the web-based management interface of Cisco Catalyst Center. This vulnerability could allow an unauthenticated remote attacker to execute arbitrary script code in the context of the affected interface. Cisco has released fixed software to address this issue, but there are no workarounds available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the Cisco Catalyst Center&amp;rsquo;s web-based management interface allows an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. This is due to insufficient validation of user input, enabling an attacker to exploit the vulnerability by persuading a user to click a crafted link. A successful exploit could lead to the execution of arbitrary script code or access to sensitive browser-based information.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Catalyst Center Privilege Escalation Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-catalyst-center-privilege-escalation-vulnerability/</link>
      <pubDate>Thu, 13 Nov 2025 17:00:54 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-catalyst-center-privilege-escalation-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 4.3&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A privilege escalation vulnerability has been identified in Cisco Catalyst Center, allowing authenticated users to perform actions requiring Administrator privileges. The highest CVSS score is 4.3 (Medium). Users are advised to upgrade to fixed software releases as there are no workarounds available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in Cisco Catalyst Center could enable an authenticated, remote attacker to execute operations that should be restricted to Administrator privileges. This issue arises from improper role-based access control (RBAC). An attacker with valid read-only user credentials could exploit this vulnerability by logging in and modifying certain policy configurations reserved for the Administrator role.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Catalyst Center Virtual Appliance HTTP Open Redirect Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-catalyst-center-virtual-appliance-http-open-redirect-vulnerability/</link>
      <pubDate>Thu, 13 Nov 2025 17:00:28 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-catalyst-center-virtual-appliance-http-open-redirect-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 4.7&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium-severity HTTP open redirect vulnerability has been identified in the Cisco Catalyst Center Virtual Appliance. This flaw could allow unauthenticated attackers to redirect users to malicious web pages. Cisco has released fixed software versions, but there are no workarounds available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the web-based management interface of the Cisco Catalyst Center Virtual Appliance has been discovered. This issue arises from improper input validation of HTTP request parameters, enabling an unauthenticated remote attacker to intercept and modify HTTP requests. If exploited, this could redirect users to malicious web pages, posing a security risk.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Unified Contact Center Express Remote Code Execution Vulnerabilities</title>
      <link>https://www.phllaps.net/posts/cisco-unified-contact-center-express-remote-code-execution-vulnerabilities/</link>
      <pubDate>Wed, 05 Nov 2025 17:02:39 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-unified-contact-center-express-remote-code-execution-vulnerabilities/</guid>
      <description>&lt;div style=&#34;background:#b91c1c;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: CRITICAL — CVSS 9.8&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;Multiple critical vulnerabilities have been identified in Cisco Unified Contact Center Express (Unified CCX) that could allow unauthenticated remote attackers to execute arbitrary commands and bypass authentication. Immediate action is required to mitigate these risks.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;Cisco has disclosed multiple vulnerabilities in the Java Remote Method Invocation (RMI) process of Cisco Unified Contact Center Express. These vulnerabilities could allow an unauthenticated, remote attacker to upload arbitrary files, bypass authentication, execute arbitrary commands, and elevate privileges to root. The vulnerabilities are not dependent on one another, meaning each can be exploited independently.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Identity Services Engine Reflected Cross-Site Scripting and Information Disclosure Vulnerabilities</title>
      <link>https://www.phllaps.net/posts/cisco-identity-services-engine-reflected-cross-site-scripting-and-information-disclosure-vulnerabilities/</link>
      <pubDate>Wed, 05 Nov 2025 17:01:54 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-identity-services-engine-reflected-cross-site-scripting-and-information-disclosure-vulnerabilities/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 5.4&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;Multiple vulnerabilities have been identified in the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). These vulnerabilities could allow an authenticated, remote attacker to disclose sensitive information or conduct reflected cross-site scripting (XSS) attacks. Cisco has released software updates to address these issues, but no workarounds are available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;Cisco has disclosed multiple vulnerabilities in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). These vulnerabilities stem from insufficient validation of user-supplied input and improper data protection mechanisms in the web-based management interface. Attackers with authenticated access could exploit these vulnerabilities to execute arbitrary scripts or access sensitive information.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Identity Services Engine RADIUS Suppression Denial of Service Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-identity-services-engine-radius-suppression-denial-of-service-vulnerability/</link>
      <pubDate>Wed, 05 Nov 2025 17:01:04 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-identity-services-engine-radius-suppression-denial-of-service-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 8.6&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in Cisco Identity Services Engine (ISE) could allow unauthenticated attackers to cause a denial of service (DoS) by exploiting a logic error in RADIUS request processing. Affected versions include 3.4.0 and its patches. Cisco recommends upgrading to fixed software or disabling a specific setting as a workaround.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability has been identified in the RADIUS setting &amp;ldquo;Reject RADIUS requests from clients with repeated failures&amp;rdquo; in Cisco Identity Services Engine (ISE). This flaw allows an unauthenticated remote attacker to send crafted RADIUS access requests that can cause Cisco ISE to restart unexpectedly, leading to a denial of service (DoS) condition.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Multiple Cisco Contact Center Products Vulnerabilities</title>
      <link>https://www.phllaps.net/posts/multiple-cisco-contact-center-products-vulnerabilities/</link>
      <pubDate>Wed, 05 Nov 2025 17:00:35 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/multiple-cisco-contact-center-products-vulnerabilities/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.5&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;Multiple vulnerabilities have been identified in Cisco Contact Center products, allowing authenticated attackers to potentially disclose sensitive information, execute arbitrary commands, and elevate privileges. The highest CVSS score is 6.5, indicating a medium risk. Users are advised to upgrade to fixed software releases as there are no available workarounds.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;Cisco has disclosed multiple vulnerabilities affecting its Contact Center products, including Cisco Unified Contact Center Express (Unified CCX), Cisco Unified Contact Center Enterprise (Unified CCE), Cisco Packaged Contact Center Enterprise (Packaged CCE), and Cisco Unified Intelligence Center (CUIC). These vulnerabilities can be exploited by authenticated remote attackers to disclose sensitive information, upload and execute arbitrary files, and elevate privileges to root. Successful exploitation requires valid user credentials.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco BroadWorks CommPilot Application Software Cross-Site Scripting Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-broadworks-commpilot-application-software-cross-site-scripting-vulnerability/</link>
      <pubDate>Tue, 21 Oct 2025 16:00:30 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-broadworks-commpilot-application-software-cross-site-scripting-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 4.8&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A cross-site scripting (XSS) vulnerability has been identified in the Cisco BroadWorks CommPilot Application Software, which could allow an authenticated attacker to execute arbitrary scripts. The highest CVSS score is 4.8, categorized as Medium severity. No workarounds are available, and users are advised to upgrade to fixed software versions.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software has been discovered. This flaw allows an authenticated remote attacker to conduct cross-site scripting (XSS) attacks by injecting malicious code into specific pages of the interface. Successful exploitation could enable the attacker to execute arbitrary script code or access sensitive browser-based information. To exploit this vulnerability, the attacker must possess valid administrative credentials.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-telepresence-collaboration-endpoint-and-roomos-software-information-disclosure-vulnerability/</link>
      <pubDate>Wed, 15 Oct 2025 17:01:23 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-telepresence-collaboration-endpoint-and-roomos-software-information-disclosure-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 4.9&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium-severity information disclosure vulnerability has been identified in Cisco TelePresence Collaboration Endpoint and RoomOS Software. An authenticated attacker could exploit this vulnerability to view sensitive information in clear text. Cisco has released fixed software, and there are no workarounds available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS Software allows an authenticated, remote attacker to view sensitive information in clear text on affected systems. This issue arises when SIP media component logging is enabled, which can lead to the exposure of unencrypted credentials stored in audit logs. An attacker with valid administrative credentials could exploit this vulnerability to access confidential information, potentially including personally identifiable information (PII).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Multiple Cisco Products Snort 3 MIME Denial of Service Vulnerabilities</title>
      <link>https://www.phllaps.net/posts/multiple-cisco-products-snort-3-mime-denial-of-service-vulnerabilities/</link>
      <pubDate>Wed, 15 Oct 2025 17:00:59 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/multiple-cisco-products-snort-3-mime-denial-of-service-vulnerabilities/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.5&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;Multiple Cisco products are affected by vulnerabilities in the Snort 3 MIME Decoder that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to leak sensitive information or restart, leading to a denial of service. Cisco has released software updates to address these vulnerabilities, but no workarounds are available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;Cisco has identified vulnerabilities in the HTTP Multipurpose Internet Mail Extensions (MIME) Decoder within Snort 3, which could be exploited by an unauthenticated remote attacker. These vulnerabilities may lead to the disclosure of sensitive information or cause the Snort 3 Detection Engine to restart unexpectedly, resulting in a denial of service (DoS) condition.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Vulnerabilities</title>
      <link>https://www.phllaps.net/posts/cisco-desk-phone-9800-series-ip-phone-7800-and-8800-series-and-video-phone-8875-with-sip-software-vulnerabilities/</link>
      <pubDate>Wed, 15 Oct 2025 17:00:30 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-desk-phone-9800-series-ip-phone-7800-and-8800-series-and-video-phone-8875-with-sip-software-vulnerabilities/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 7.5&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;Cisco has identified multiple vulnerabilities in the Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 that could allow unauthenticated remote attackers to cause denial of service (DoS) conditions or conduct cross-site scripting (XSS) attacks. The highest CVSS score is 7.5, indicating a high severity risk. Software updates are available to address these vulnerabilities, and there are no workarounds.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Unified Communications Manager Stored Cross-Site Scripting Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-unified-communications-manager-stored-cross-site-scripting-vulnerability/</link>
      <pubDate>Wed, 01 Oct 2025 17:00:23 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-unified-communications-manager-stored-cross-site-scripting-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 4.8&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A stored cross-site scripting (XSS) vulnerability has been identified in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME). This vulnerability allows an authenticated remote attacker to execute arbitrary script code, potentially accessing sensitive information. Cisco has released fixed software updates, but no workarounds are available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated attacker to conduct a cross-site scripting (XSS) attack. This occurs because the interface fails to properly validate user input, enabling the injection of malicious code. Successful exploitation could lead to the execution of arbitrary scripts in the context of the affected interface, compromising sensitive, browser-based information.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Cyber Vision Center Stored Cross-Site Scripting Vulnerabilities</title>
      <link>https://www.phllaps.net/posts/cisco-cyber-vision-center-stored-cross-site-scripting-vulnerabilities/</link>
      <pubDate>Wed, 01 Oct 2025 16:00:31 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-cyber-vision-center-stored-cross-site-scripting-vulnerabilities/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 5.4&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;Cisco Cyber Vision Center has multiple stored cross-site scripting (XSS) vulnerabilities that could allow authenticated remote attackers to execute arbitrary scripts. The highest CVSS score for these vulnerabilities is 5.4, categorized as Medium severity. There are no workarounds available, and users are advised to upgrade to fixed software releases.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;Multiple vulnerabilities have been identified in the web-based management interface of Cisco Cyber Vision Center. These vulnerabilities arise from insufficient validation of user-supplied input, enabling authenticated attackers to conduct XSS attacks. Successful exploitation could allow attackers to execute arbitrary scripts or access sensitive browser-based information. Specifically, exploitation of CVE-2025-20356 requires administrative access to the Sensor Explorer page, while CVE-2025-20357 requires access to the Reports page.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco IOS XE Software Web Authentication Reflected Cross-Site Scripting Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-ios-xe-software-web-authentication-reflected-cross-site-scripting-vulnerability/</link>
      <pubDate>Fri, 26 Sep 2025 17:00:25 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-ios-xe-software-web-authentication-reflected-cross-site-scripting-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.1&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A reflected cross-site scripting (XSS) vulnerability has been identified in the Web Authentication feature of Cisco IOS XE Software. This issue could allow an unauthenticated remote attacker to execute malicious scripts on affected devices. Cisco has released updates to address this vulnerability, but there are no workarounds available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the Web Authentication feature of Cisco IOS XE Software allows an unauthenticated remote attacker to conduct a reflected cross-site scripting (XSS) attack. This vulnerability arises from improper sanitization of user-supplied input. An attacker could exploit this by persuading a user to click a malicious link, potentially allowing the attacker to steal user cookies from the affected device.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software VPN Web Server Remote Code Execution Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-secure-firewall-adaptive-security-appliance-software-and-secure-firewall-threat-defense-software-vpn-web-server-remote-code-execution-vulnerability/</link>
      <pubDate>Thu, 25 Sep 2025 17:01:17 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-secure-firewall-adaptive-security-appliance-software-and-secure-firewall-threat-defense-software-vpn-web-server-remote-code-execution-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#b91c1c;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: CRITICAL — CVSS 9.9&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A critical remote code execution vulnerability has been identified in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software. This flaw allows authenticated attackers to execute arbitrary code on affected devices. Immediate software updates are recommended, as there are no workarounds available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability (CVE-2025-20333) has been discovered in the VPN web server of Cisco Secure Firewall ASA and FTD Software. This issue arises from improper validation of user-supplied input in HTTP(S) requests. An attacker with valid VPN credentials could exploit this vulnerability by sending crafted HTTP requests, potentially leading to arbitrary code execution as root. This could result in a complete compromise of the affected device.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, IOS Software, IOS XE Software, and IOS XR Software Web Services Remote Code Execution Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-secure-firewall-adaptive-security-appliance-software-secure-firewall-threat-defense-software-ios-software-ios-xe-software-and-ios-xr-software-web-services-remote-code-execution-vulnerability/</link>
      <pubDate>Thu, 25 Sep 2025 17:00:54 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-secure-firewall-adaptive-security-appliance-software-secure-firewall-threat-defense-software-ios-software-ios-xe-software-and-ios-xr-software-web-services-remote-code-execution-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#b91c1c;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: CRITICAL — CVSS 9.0&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A critical vulnerability has been identified in the web services of Cisco Secure Firewall ASA, Secure Firewall FTD, IOS, IOS XE, and IOS XR Software. This flaw could allow unauthenticated or authenticated remote attackers to execute arbitrary code on affected devices. Cisco has released fixed software to address this issue, and there are no workarounds available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the web services of Cisco Secure Firewall ASA and FTD Software allows unauthenticated remote attackers to execute arbitrary code on affected devices. For IOS, IOS XE, and IOS XR Software, the vulnerability can be exploited by authenticated remote attackers with low user privileges. This vulnerability arises from improper validation of user-supplied input in HTTP requests, potentially leading to complete device compromise.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Secure Firewall Adaptive Security Appliance Software and Secure Firewall Threat Defense Software VPN Web Server Unauthorized Access Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-secure-firewall-adaptive-security-appliance-software-and-secure-firewall-threat-defense-software-vpn-web-server-unauthorized-access-vulnerability/</link>
      <pubDate>Thu, 25 Sep 2025 17:00:26 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-secure-firewall-adaptive-security-appliance-software-and-secure-firewall-threat-defense-software-vpn-web-server-unauthorized-access-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.5&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium-severity vulnerability has been identified in the VPN web server of Cisco Secure Firewall ASA and FTD Software, allowing unauthenticated remote access to restricted URLs. No workarounds are available, and users are strongly advised to upgrade to fixed software releases.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated remote attacker to access restricted URL endpoints without authentication. This issue arises from improper validation of user-supplied input in HTTP(S) requests. An attacker could exploit this vulnerability by sending crafted HTTP requests to a targeted web server, potentially gaining access to restricted URLs.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Wireless Access Point Software Device Analytics Action Frame Injection Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-wireless-access-point-software-device-analytics-action-frame-injection-vulnerability/</link>
      <pubDate>Wed, 24 Sep 2025 17:05:49 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-wireless-access-point-software-device-analytics-action-frame-injection-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 4.3&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium-severity vulnerability has been identified in Cisco Wireless Access Point Software related to Device Analytics action frame processing. An unauthenticated adjacent attacker could exploit this vulnerability to inject arbitrary information into wireless 802.11 action frames. Cisco has released fixed software, but no workarounds are available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the Device Analytics action frame processing of Cisco Wireless Access Point Software allows an unauthenticated, adjacent attacker to inject wireless 802.11 action frames with arbitrary information. This issue arises from insufficient verification checks of incoming 802.11 action frames. Successful exploitation could modify the Device Analytics data of valid wireless clients connected to the same wireless controller.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Access Point Software Intermittent IPv6 Gateway Change Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-access-point-software-intermittent-ipv6-gateway-change-vulnerability/</link>
      <pubDate>Wed, 24 Sep 2025 17:05:28 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-access-point-software-intermittent-ipv6-gateway-change-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 4.3&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium-severity vulnerability has been identified in Cisco Access Point Software that could allow an unauthenticated, adjacent attacker to modify the IPv6 gateway on affected devices. There are no workarounds available, and users are advised to upgrade to fixed software releases.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the IPv6 Router Advertisement (RA) packet processing of Cisco Access Point Software could allow an unauthenticated, adjacent attacker to change the IPv6 gateway on affected devices. This vulnerability arises from a logic error in processing IPv6 RA packets received from wireless clients. An attacker could exploit this by associating with a wireless network and sending crafted IPv6 RA packets, potentially leading to intermittent packet loss for associated wireless clients.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco IOS XE Software for Catalyst 9000 Series Switches Denial of Service Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-ios-xe-software-for-catalyst-9000-series-switches-denial-of-service-vulnerability/</link>
      <pubDate>Wed, 24 Sep 2025 17:05:04 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-ios-xe-software-for-catalyst-9000-series-switches-denial-of-service-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 7.4&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A denial of service vulnerability has been identified in Cisco IOS XE Software for Catalyst 9000 Series Switches. An unauthenticated, adjacent attacker can exploit this vulnerability by sending crafted Ethernet frames, causing an egress port to drop all outbound traffic. The highest CVSS score is 7.4 (High). Cisco has released fixed software, but no workarounds are available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability exists in the handling of certain Ethernet frames within Cisco IOS XE Software for Catalyst 9000 Series Switches. This flaw allows an unauthenticated, adjacent attacker to send crafted Ethernet frames, which can block an egress port, resulting in a denial of service (DoS) condition. Once exploited, the affected port will drop all outbound traffic, severely impacting network operations.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco IOS XE Software on Cisco Catalyst 9500X and 9600X Series Switches Virtual Interface Access Control List Bypass Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-ios-xe-software-on-cisco-catalyst-9500x-and-9600x-series-switches-virtual-interface-access-control-list-bypass-vulnerability/</link>
      <pubDate>Wed, 24 Sep 2025 17:04:46 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-ios-xe-software-on-cisco-catalyst-9500x-and-9600x-series-switches-virtual-interface-access-control-list-bypass-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 5.3&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A Medium severity vulnerability has been identified in Cisco IOS XE Software affecting Catalyst 9500X and 9600X Series Switches. An unauthenticated remote attacker could exploit this vulnerability to bypass configured access control lists (ACLs) on affected devices. Cisco has released software updates to address this issue, and there are workarounds available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the access control list (ACL) programming of Cisco IOS XE Software allows an unauthenticated, remote attacker to bypass a configured ACL on affected devices. This occurs when an attacker floods traffic from an unlearned MAC address on a switch virtual interface (SVI) with an egress ACL applied. If the MAC address table is full or flushed, the attacker could successfully bypass the egress ACL.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco SD-WAN vEdge Software Access Control List Bypass Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-sd-wan-vedge-software-access-control-list-bypass-vulnerability/</link>
      <pubDate>Wed, 24 Sep 2025 17:04:26 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-sd-wan-vedge-software-access-control-list-bypass-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 5.8&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in Cisco SD-WAN vEdge Software could allow unauthenticated remote attackers to bypass access control lists (ACLs) on affected devices. This vulnerability has a medium severity rating (CVSS 5.8). Cisco has released fixed software and workarounds are available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability has been identified in the access control list (ACL) processing of IPv4 packets within Cisco SD-WAN vEdge Software. This flaw allows an unauthenticated remote attacker to bypass configured ACLs due to improper enforcement of the implicit deny rule at the end of an ACL. By exploiting this vulnerability, attackers can send unauthorized traffic to an affected device&amp;rsquo;s interface, potentially compromising network security.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco IOS and IOS XE Software CLI Denial of Service Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-ios-and-ios-xe-software-cli-denial-of-service-vulnerability/</link>
      <pubDate>Wed, 24 Sep 2025 17:04:08 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-ios-and-ios-xe-software-cli-denial-of-service-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.5&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium-severity vulnerability has been identified in the CLI of Cisco IOS and IOS XE Software, allowing an authenticated local attacker to cause a denial of service (DoS) by exploiting a buffer overflow. No workarounds are available, and Cisco recommends upgrading to fixed software releases.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the CLI of Cisco IOS and IOS XE Software could allow an authenticated, local attacker to cause an affected device to unexpectedly reload, resulting in a denial of service (DoS) condition. This issue arises from a buffer overflow that can be exploited using crafted commands at the CLI prompt. While proof-of-concept exploit code is available, there have been no reports of malicious exploitation.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco IOS Software Industrial Ethernet Switch Device Manager Denial of Service Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-ios-software-industrial-ethernet-switch-device-manager-denial-of-service-vulnerability/</link>
      <pubDate>Wed, 24 Sep 2025 17:03:49 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-ios-software-industrial-ethernet-switch-device-manager-denial-of-service-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 7.7&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A denial of service (DoS) vulnerability has been identified in the web UI of Cisco IOS Software for Industrial Ethernet Switches. An authenticated remote attacker with low privileges can exploit this vulnerability by sending a specially crafted URL, potentially causing the device to reload and become unavailable. Cisco has released software updates to address this issue, but there are no workarounds available.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco IOS and IOS XE Software TACACS&#43; Authentication Bypass Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-ios-and-ios-xe-software-tacacs-authentication-bypass-vulnerability/</link>
      <pubDate>Wed, 24 Sep 2025 17:03:28 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-ios-and-ios-xe-software-tacacs-authentication-bypass-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 8.1&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in Cisco IOS and IOS XE Software could allow unauthenticated remote attackers to bypass TACACS+ authentication or view sensitive data. The highest CVSS score is 8.1, classified as High severity. Cisco has released fixes and workarounds are available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability has been identified in the TACACS+ protocol implementation within Cisco IOS and IOS XE Software. This issue arises because the software does not properly verify if the required TACACS+ shared secret is configured. As a result, an attacker could exploit this vulnerability to intercept unencrypted TACACS+ messages or impersonate the TACACS+ server, potentially allowing unauthorized access to sensitive information or bypassing authentication altogether.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco IOS XE Software HTTP API Command Injection Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-ios-xe-software-http-api-command-injection-vulnerability/</link>
      <pubDate>Wed, 24 Sep 2025 17:03:08 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-ios-xe-software-http-api-command-injection-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 8.8&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A command injection vulnerability has been identified in the HTTP API subsystem of Cisco IOS XE Software. This flaw could allow an attacker to execute commands with root privileges, posing a significant security risk. Users are advised to upgrade to fixed software as there are no workarounds available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;Cisco has disclosed a vulnerability in the HTTP API subsystem of Cisco IOS XE Software that could allow a remote attacker to inject commands that execute with root privileges. This vulnerability arises from insufficient input validation. An attacker with administrative privileges could exploit this by authenticating to an affected system and making an API call with crafted input. Alternatively, an unauthenticated attacker could trick a legitimate user with administrative privileges into clicking a malicious link. Successful exploitation could lead to arbitrary command execution as the root user.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco IOS XE Software CLI Argument Injection Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-ios-xe-software-cli-argument-injection-vulnerability/</link>
      <pubDate>Wed, 24 Sep 2025 17:02:50 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-ios-xe-software-cli-argument-injection-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.0&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium-severity vulnerability has been identified in Cisco IOS XE Software that allows authenticated local attackers with administrative privileges to execute arbitrary commands on the underlying operating system. No workarounds are available, and users are advised to upgrade to fixed software as soon as possible.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the Command-Line Interface (CLI) of Cisco IOS XE Software could allow an authenticated local attacker with administrative privileges to execute arbitrary commands as root on the affected device&amp;rsquo;s operating system. This issue arises from insufficient validation of user arguments passed to specific CLI commands. An attacker could exploit this by logging in with valid administrative credentials and using crafted commands.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco IOS XE Software Network-Based Application Recognition Denial of Service Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-ios-xe-software-network-based-application-recognition-denial-of-service-vulnerability/</link>
      <pubDate>Wed, 24 Sep 2025 17:02:32 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-ios-xe-software-network-based-application-recognition-denial-of-service-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 8.6&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A high-severity vulnerability has been identified in the Network-Based Application Recognition (NBAR) feature of Cisco IOS XE Software. This flaw could allow unauthenticated remote attackers to cause affected devices to reload, resulting in a denial of service (DoS) condition. Cisco has released fixed software, but there are no workarounds available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the NBAR feature of Cisco IOS XE Software allows unauthenticated, remote attackers to exploit improperly handled malformed Control and Provisioning of Wireless Access Points (CAPWAP) packets. By sending these malformed packets, an attacker can cause the affected device to unexpectedly reload, leading to a denial of service (DoS).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco IOS XE Software Secure Boot Bypass Vulnerabilities</title>
      <link>https://www.phllaps.net/posts/cisco-ios-xe-software-secure-boot-bypass-vulnerabilities/</link>
      <pubDate>Wed, 24 Sep 2025 17:02:05 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-ios-xe-software-secure-boot-bypass-vulnerabilities/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.7&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;Multiple vulnerabilities in Cisco IOS XE Software could allow an authenticated local attacker or an unauthenticated attacker with physical access to execute persistent code at boot time, compromising device security. Cisco has released fixed software, and no workarounds are available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;Cisco has identified multiple vulnerabilities in its IOS XE Software that could allow an attacker to bypass secure boot mechanisms. These vulnerabilities stem from improper validation of software packages, enabling an attacker to place a crafted file on an affected device. This could lead to the execution of persistent code on the operating system, effectively breaking the chain of trust.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-ios-and-ios-xe-software-snmp-denial-of-service-and-remote-code-execution-vulnerability/</link>
      <pubDate>Wed, 24 Sep 2025 17:01:38 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-ios-and-ios-xe-software-snmp-denial-of-service-and-remote-code-execution-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 7.7&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the SNMP subsystem of Cisco IOS and IOS XE Software could allow authenticated attackers to cause a denial of service (DoS) or execute arbitrary code. This affects devices with SNMP enabled. Immediate action is required to patch or mitigate this vulnerability.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability has been identified in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software. This vulnerability allows an authenticated remote attacker to cause a denial of service (DoS) condition or execute code as the root user on affected devices. The exploitation requires valid SNMP credentials, either through SNMPv2c read-only community strings or SNMPv3 user credentials. This vulnerability is due to a stack overflow condition in the SNMP subsystem.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco IOS XE Software Simple Network Management Protocol Denial of Service Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-ios-xe-software-simple-network-management-protocol-denial-of-service-vulnerability/</link>
      <pubDate>Wed, 24 Sep 2025 17:01:16 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-ios-xe-software-simple-network-management-protocol-denial-of-service-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 7.7&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A denial of service (DoS) vulnerability has been identified in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software. An authenticated remote attacker can exploit this vulnerability to cause affected devices to reload unexpectedly. The highest CVSS score for this vulnerability is 7.7, categorized as High severity. Cisco has released software updates to address this issue, but there are no workarounds available.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco IOS XE Software Web UI Reflected Cross-Site Scripting Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-ios-xe-software-web-ui-reflected-cross-site-scripting-vulnerability/</link>
      <pubDate>Wed, 24 Sep 2025 17:00:53 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-ios-xe-software-web-ui-reflected-cross-site-scripting-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.1&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A reflected cross-site scripting (XSS) vulnerability has been identified in the web UI of Cisco IOS XE Software. This flaw could allow unauthenticated remote attackers to execute malicious scripts on affected devices. Cisco has released software updates to address this issue, but no workarounds are available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the web UI of Cisco IOS XE Software has been discovered, allowing unauthenticated remote attackers to conduct reflected cross-site scripting (XSS) attacks. This vulnerability arises from improper sanitization of user-supplied input, enabling attackers to trick users into clicking malicious links. A successful exploit could allow attackers to steal user cookies from affected devices.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco IOS XE Software for Catalyst 9800 Series Wireless Controller for Cloud Unauthenticated Access to Certificate Enrollment Service Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-ios-xe-software-for-catalyst-9800-series-wireless-controller-for-cloud-unauthenticated-access-to-certificate-enrollment-service-vulnerability/</link>
      <pubDate>Wed, 24 Sep 2025 17:00:34 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-ios-xe-software-for-catalyst-9800-series-wireless-controller-for-cloud-unauthenticated-access-to-certificate-enrollment-service-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 5.3&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium-severity vulnerability has been identified in the Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers for Cloud. This flaw allows unauthenticated remote attackers to access the public-key infrastructure (PKI) server, potentially enabling unauthorized device enrollment. Workarounds are available, and Cisco has recommended software updates to fully mitigate the risk.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the Day One setup process of Cisco IOS XE Software for Catalyst 9800 Series Wireless Controllers for Cloud could allow an unauthenticated, remote attacker to access the PKI server running on affected devices. This issue arises due to incomplete cleanup after the Day One setup process. An attacker could exploit this vulnerability by sending Simple Certificate Enrollment Protocol (SCEP) requests, potentially allowing them to request a certificate and join an attacker-controlled device to the virtual wireless controller.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco IOS XE SD-WAN Software Packet Filtering Bypass Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-ios-xe-sd-wan-software-packet-filtering-bypass-vulnerability/</link>
      <pubDate>Mon, 22 Sep 2025 15:00:44 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-ios-xe-sd-wan-software-packet-filtering-bypass-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 5.3&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium-severity vulnerability has been identified in Cisco IOS XE SD-WAN Software that allows unauthenticated remote attackers to bypass Layer 3 and Layer 4 traffic filters. This could lead to unauthorized access to network resources. Users are advised to implement workarounds or upgrade to fixed software versions as soon as possible.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the packet filtering features of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to bypass Layer 3 and Layer 4 traffic filters. This issue arises from improper traffic filtering conditions on affected devices. By sending a crafted packet, an attacker could exploit this vulnerability to inject malicious packets into the network. Proof-of-concept exploit code is available, although there are no known instances of malicious exploitation at this time.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco IOS XR ARP Broadcast Storm Denial of Service Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-ios-xr-arp-broadcast-storm-denial-of-service-vulnerability/</link>
      <pubDate>Wed, 10 Sep 2025 17:01:18 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-ios-xr-arp-broadcast-storm-denial-of-service-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 7.4&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A denial of service (DoS) vulnerability has been identified in the ARP implementation of Cisco IOS XR Software. An unauthenticated, adjacent attacker can exploit this vulnerability by sending excessive ARP traffic to the management interface, potentially leading to degraded performance or complete unresponsiveness of the device. Cisco has released software updates to address this issue, but no workarounds are available.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco IOS XR Software Image Verification Bypass Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-ios-xr-software-image-verification-bypass-vulnerability/</link>
      <pubDate>Wed, 10 Sep 2025 17:00:58 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-ios-xr-software-image-verification-bypass-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.0&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium severity vulnerability has been identified in Cisco IOS XR Software that allows an authenticated local attacker to bypass image signature verification, potentially leading to the installation of unsigned software. No workarounds are available, and users are advised to update to fixed software versions.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the installation process of Cisco IOS XR Software could allow an authenticated, local attacker with root-system privileges to bypass the software image signature verification. This flaw arises from incomplete validation of files during the installation of an .iso file. An attacker could exploit this by modifying the .iso image and installing it on the device, leading to the activation of unsigned software.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco IOS XR Software Management Interface ACL Bypass Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-ios-xr-software-management-interface-acl-bypass-vulnerability/</link>
      <pubDate>Wed, 10 Sep 2025 17:00:38 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-ios-xr-software-management-interface-acl-bypass-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 5.3&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium-severity vulnerability in Cisco IOS XR Software allows unauthenticated remote attackers to bypass access control lists (ACLs) on the management interface for SSH, NetConf, and gRPC features. Users are advised to upgrade to fixed software releases or implement workarounds.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability was identified in the management interface ACL processing feature of Cisco IOS XR Software. This flaw allows unauthenticated remote attackers to bypass configured ACLs, potentially leading to unauthorized access to management features like SSH, NetConf, and gRPC. The issue arises because management interface ACLs are not enforced on certain Linux-handled features within the Packet I/O infrastructure.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Evolved Programmable Network Manager Arbitrary File Upload Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-evolved-programmable-network-manager-arbitrary-file-upload-vulnerability/</link>
      <pubDate>Wed, 03 Sep 2025 17:02:23 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-evolved-programmable-network-manager-arbitrary-file-upload-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 4.3&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium-severity vulnerability has been identified in the Cisco Evolved Programmable Network Manager (EPNM) that allows authenticated attackers to upload arbitrary files. There are no workarounds available, and affected users should migrate to fixed software releases.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the web-based management interface of Cisco EPNM could allow an authenticated, remote attacker to upload arbitrary files. This issue arises from improper validation of uploaded files, enabling an attacker with valid Config Managers credentials to exploit the vulnerability by sending a crafted file upload request to a specific API endpoint.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Information Disclosure Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-evolved-programmable-network-manager-and-cisco-prime-infrastructure-information-disclosure-vulnerability/</link>
      <pubDate>Wed, 03 Sep 2025 17:02:07 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-evolved-programmable-network-manager-and-cisco-prime-infrastructure-information-disclosure-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 4.3&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium-severity information disclosure vulnerability has been identified in Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure. This flaw allows authenticated, low-privileged users to access sensitive configuration information. Software updates are available to mitigate this risk, but there are no workarounds.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability exists in the web-based management interface of Cisco EPNM and Cisco Prime Infrastructure. This issue arises from improper validation of requests to API endpoints. An authenticated attacker with low privileges could exploit this vulnerability to view sensitive configuration information that should be restricted.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Stored Cross-Site Scripting Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-evolved-programmable-network-manager-and-cisco-prime-infrastructure-stored-cross-site-scripting-vulnerability/</link>
      <pubDate>Wed, 03 Sep 2025 17:01:50 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-evolved-programmable-network-manager-and-cisco-prime-infrastructure-stored-cross-site-scripting-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 4.8&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A stored cross-site scripting (XSS) vulnerability has been identified in Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure. This vulnerability allows an authenticated attacker to execute arbitrary scripts in the context of the affected interface. Users are advised to upgrade to fixed software versions as there are no workarounds available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the web-based management interface of Cisco EPNM and Cisco Prime Infrastructure could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack. This occurs because the interface fails to properly validate user-supplied input. An attacker with valid administrative credentials could exploit this vulnerability by inserting malicious code into specific data fields, potentially executing arbitrary script code or accessing sensitive browser-based information.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Unified Communications Manager IM &amp;amp; Presence Service Cross-Site Scripting Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-unified-communications-manager-im-amp-presence-service-cross-site-scripting-vulnerability/</link>
      <pubDate>Wed, 03 Sep 2025 17:01:28 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-unified-communications-manager-im-amp-presence-service-cross-site-scripting-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.1&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A cross-site scripting (XSS) vulnerability has been identified in the web-based management interface of Cisco Unified Communications Manager IM &amp;amp; Presence Service. This flaw could allow an unauthenticated remote attacker to execute arbitrary script code, potentially compromising sensitive information. Cisco has released fixed software versions, and there are no workarounds available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM &amp;amp; Presence Service (Unified CM IM&amp;amp;P) was discovered. This vulnerability arises from improper validation of user-supplied input, enabling an attacker to conduct a cross-site scripting (XSS) attack. By persuading a user to click on a malicious link, an attacker could execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Webex Meetings URL Redirection Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-webex-meetings-url-redirection-vulnerability/</link>
      <pubDate>Wed, 03 Sep 2025 17:00:52 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-webex-meetings-url-redirection-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 4.3&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium-severity vulnerability in Cisco Webex Meetings could allow an unauthenticated attacker to redirect users to untrusted websites. Cisco has addressed this issue, and no action is required from users.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in Cisco Webex Meetings was discovered, which could allow an unauthenticated, remote attacker to redirect a targeted user to an untrusted website. This issue arose due to insufficient validation of URLs included in meeting-join links. If exploited, this could facilitate phishing attacks by misleading users into believing they were interacting with a trusted Webex environment.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Webex Meetings Cross-Site Scripting Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-webex-meetings-cross-site-scripting-vulnerability/</link>
      <pubDate>Wed, 03 Sep 2025 17:00:38 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-webex-meetings-cross-site-scripting-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 5.4&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium-severity cross-site scripting (XSS) vulnerability has been identified in Cisco Webex Meetings, allowing authenticated attackers to exploit the user profile component. Cisco has addressed this issue, and no user action is required.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the user profile component of Cisco Webex Meetings could have allowed an authenticated, remote attacker with low privileges to conduct a cross-site scripting (XSS) attack against a user of the web-based interface. This vulnerability arose due to insufficient validation of user-supplied input. An attacker could exploit this by persuading a user to click a crafted link, potentially leading to an XSS attack.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Unified Communications Manager Cross-Site Request Forgery Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-unified-communications-manager-cross-site-request-forgery-vulnerability/</link>
      <pubDate>Wed, 03 Sep 2025 17:00:24 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-unified-communications-manager-cross-site-request-forgery-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 4.3&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium-severity Cross-Site Request Forgery (CSRF) vulnerability has been identified in Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (SME). An unauthenticated attacker could exploit this vulnerability by tricking a user into clicking a malicious link, potentially allowing the attacker to perform actions with the user&amp;rsquo;s privileges. There are no workarounds available, and affected users should upgrade to fixed software versions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Nexus Dashboard Path Traversal Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-nexus-dashboard-path-traversal-vulnerability/</link>
      <pubDate>Wed, 27 Aug 2025 17:03:44 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-nexus-dashboard-path-traversal-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.5&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium-severity path traversal vulnerability has been identified in Cisco Nexus Dashboard, allowing authenticated remote attackers to gain root privileges. No workarounds are available, and users are advised to upgrade to fixed software releases.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the backup restore functionality of Cisco Nexus Dashboard could allow an authenticated, remote attacker to conduct a path traversal attack. This issue arises from insufficient validation of backup file contents. An attacker with valid Administrator credentials could exploit this vulnerability by restoring a crafted backup file, potentially gaining root privileges on the affected device.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Nexus Dashboard and Nexus Dashboard Fabric Controller Unauthorized REST API Vulnerabilities</title>
      <link>https://www.phllaps.net/posts/cisco-nexus-dashboard-and-nexus-dashboard-fabric-controller-unauthorized-rest-api-vulnerabilities/</link>
      <pubDate>Wed, 27 Aug 2025 17:03:28 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-nexus-dashboard-and-nexus-dashboard-fabric-controller-unauthorized-rest-api-vulnerabilities/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 5.4&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;Cisco Nexus Dashboard and Nexus Dashboard Fabric Controller have vulnerabilities in their REST API that could allow low-privileged authenticated attackers to access sensitive information or modify files. The highest CVSS score is 5.4 (Medium severity). No workarounds are available, and updates are necessary to mitigate the risks.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;Multiple vulnerabilities have been identified in the REST API endpoints of Cisco Nexus Dashboard and Cisco Nexus Dashboard Fabric Controller (NDFC). These vulnerabilities arise from missing authorization controls, enabling low-privileged authenticated attackers to potentially view sensitive information or perform limited administrative functions, such as uploading images or accessing configuration details. Exploitation requires sending crafted API requests to affected endpoints.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco NX-OS Software Command Injection Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-nx-os-software-command-injection-vulnerability/</link>
      <pubDate>Wed, 27 Aug 2025 17:03:12 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-nx-os-software-command-injection-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 4.4&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A command injection vulnerability has been identified in Cisco NX-OS Software that could allow an authenticated local attacker to execute arbitrary commands on the underlying operating system. This vulnerability has a CVSS score of 4.4, indicating a Medium severity level. Cisco has released software updates to address this issue, but there are no workarounds available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the command-line interface (CLI) of Cisco NX-OS Software allows an authenticated, local attacker to perform a command injection attack on the operating system of affected devices. This vulnerability arises from insufficient validation of user-supplied input. If exploited, an attacker with valid user credentials could read and write files on the underlying operating system with the privileges of a non-root user account.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco NX-OS Software Sensitive Log Information Disclosure Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-nx-os-software-sensitive-log-information-disclosure-vulnerability/</link>
      <pubDate>Wed, 27 Aug 2025 17:02:44 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-nx-os-software-sensitive-log-information-disclosure-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 5.5&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium severity vulnerability has been identified in Cisco NX-OS Software that could allow an authenticated, local attacker to access sensitive log information. No workarounds are available, and Cisco has released fixed software to address this issue.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the logging feature of Cisco NX-OS Software affects several Cisco Nexus and UCS devices. This vulnerability arises from improper logging of sensitive information, which could allow an authenticated local attacker to access sensitive data, including stored credentials, by exploiting the log files on the device&amp;rsquo;s file system.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Nexus 3000 and 9000 Series Switches Protocol Independent Multicast Version 6 Denial of Service Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-nexus-3000-and-9000-series-switches-protocol-independent-multicast-version-6-denial-of-service-vulnerability/</link>
      <pubDate>Wed, 27 Aug 2025 17:02:21 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-nexus-3000-and-9000-series-switches-protocol-independent-multicast-version-6-denial-of-service-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 5.0&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium-severity vulnerability has been identified in the Protocol Independent Multicast Version 6 (PIM6) feature of Cisco Nexus 3000 and 9000 Series Switches. This flaw could allow an authenticated, low-privileged remote attacker to trigger a denial of service (DoS) condition. No workarounds are available, but Cisco has released software updates to address the issue.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the PIM6 feature of Cisco Nexus 3000 and 9000 Series Switches in standalone NX-OS mode could allow an authenticated, low-privileged remote attacker to crash the PIM6 process. This is due to improper processing of PIM6 ephemeral data queries. An attacker can exploit this vulnerability by sending a crafted ephemeral query through various methods, including NX-API REST, NETCONF, RESTConf, gRPC, or Model Driven Telemetry. Successful exploitation can lead to a DoS condition, causing potential adjacency flaps.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Integrated Management Controller Virtual Keyboard Video Monitor Stored Cross-Site Scripting Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-integrated-management-controller-virtual-keyboard-video-monitor-stored-cross-site-scripting-vulnerability/</link>
      <pubDate>Wed, 27 Aug 2025 17:01:57 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-integrated-management-controller-virtual-keyboard-video-monitor-stored-cross-site-scripting-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 5.4&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A stored cross-site scripting (XSS) vulnerability has been identified in the Cisco Integrated Management Controller&amp;rsquo;s Virtual Keyboard Video Monitor (vKVM). This medium-severity issue allows authenticated attackers to execute arbitrary scripts in the context of the affected interface. Cisco has released software updates to address this vulnerability, but no workarounds are available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the vKVM connection handling of Cisco&amp;rsquo;s Integrated Management Controller (IMC) could allow an authenticated, remote attacker with low privileges to conduct a stored XSS attack. This vulnerability arises from insufficient validation of user-supplied input in the web-based management interface. An attacker could exploit this by injecting malicious code into specific data fields, potentially executing arbitrary script code or accessing sensitive browser-based information.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco UCS Manager Software Command Injection Vulnerabilities</title>
      <link>https://www.phllaps.net/posts/cisco-ucs-manager-software-command-injection-vulnerabilities/</link>
      <pubDate>Wed, 27 Aug 2025 17:01:33 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-ucs-manager-software-command-injection-vulnerabilities/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.5&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;Multiple command injection vulnerabilities have been identified in Cisco UCS Manager Software, allowing authenticated attackers with administrative privileges to execute arbitrary commands on affected systems. The highest CVSS score for these vulnerabilities is 6.5, indicating a Medium severity level. Software updates are available to address these issues, but no workarounds exist.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;Cisco has disclosed multiple vulnerabilities in the CLI and web-based management interface of Cisco UCS Manager Software. These vulnerabilities could allow an authenticated attacker with administrative privileges to perform command injection attacks, potentially leading to root-level access on the affected systems. The vulnerabilities stem from insufficient input validation of command arguments supplied by users.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Integrated Management Controller Virtual Keyboard Video Monitor Open Redirect Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-integrated-management-controller-virtual-keyboard-video-monitor-open-redirect-vulnerability/</link>
      <pubDate>Wed, 27 Aug 2025 17:01:11 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-integrated-management-controller-virtual-keyboard-video-monitor-open-redirect-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 7.1&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A high-severity vulnerability has been identified in the Cisco Integrated Management Controller (IMC) Virtual Keyboard Video Monitor (vKVM). This vulnerability allows unauthenticated remote attackers to redirect users to malicious websites, potentially capturing sensitive information. Cisco has released software updates to address this issue, and there are no workarounds available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the vKVM connection handling of Cisco IMC could allow an unauthenticated, remote attacker to redirect a user to a malicious website. This vulnerability arises from insufficient verification of vKVM endpoints. Attackers can exploit this by persuading users to click on crafted links, leading to potential credential capture.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco UCS Manager Software Stored Cross-Site Scripting Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-ucs-manager-software-stored-cross-site-scripting-vulnerability/</link>
      <pubDate>Wed, 27 Aug 2025 17:00:47 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-ucs-manager-software-stored-cross-site-scripting-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 5.4&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A stored cross-site scripting (XSS) vulnerability has been identified in Cisco UCS Manager Software, allowing authenticated attackers to inject malicious scripts. This could lead to unauthorized access to sensitive information. The highest CVSS score is 5.4, indicating a medium severity risk. No workarounds are available, but Cisco has released fixed software versions.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the web-based management interface of Cisco UCS Manager Software allows an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack. This vulnerability arises from insufficient validation of user-supplied input, enabling attackers to inject malicious data into specific pages. Successful exploitation could allow attackers to execute arbitrary scripts or access sensitive browser-based information. To exploit this vulnerability, the attacker must hold an Administrator or AAA Administrator role.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Nexus 3000 and 9000 Series Switches Intermediate System-to-Intermediate System Denial of Service Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-nexus-3000-and-9000-series-switches-intermediate-system-to-intermediate-system-denial-of-service-vulnerability/</link>
      <pubDate>Wed, 27 Aug 2025 17:00:26 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-nexus-3000-and-9000-series-switches-intermediate-system-to-intermediate-system-denial-of-service-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 7.4&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A high-severity vulnerability has been identified in the Intermediate System-to-Intermediate System (IS-IS) feature of Cisco Nexus 3000 and 9000 Series Switches. This vulnerability could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) by sending a crafted IS-IS packet, leading to an unexpected device reload. Cisco has released software updates to address this issue, but no workarounds are available.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Sensitive Information Disclosure Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-evolved-programmable-network-manager-and-cisco-prime-infrastructure-sensitive-information-disclosure-vulnerability/</link>
      <pubDate>Wed, 20 Aug 2025 17:01:11 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-evolved-programmable-network-manager-and-cisco-prime-infrastructure-sensitive-information-disclosure-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.5&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium-severity vulnerability has been identified in Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure, allowing authenticated low-privileged attackers to access sensitive files. No workarounds are available, and software updates are necessary to mitigate the risk.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability exists in the web-based management interface of Cisco EPNM and Cisco Prime Infrastructure due to insufficient input validation for specific HTTP requests. An authenticated, low-privileged remote attacker could exploit this vulnerability to retrieve arbitrary files from the underlying file system of affected devices.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Duo Authentication Proxy Information Disclosure Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-duo-authentication-proxy-information-disclosure-vulnerability/</link>
      <pubDate>Wed, 20 Aug 2025 17:00:50 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-duo-authentication-proxy-information-disclosure-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 4.9&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium-severity information disclosure vulnerability has been identified in the Cisco Duo Authentication Proxy. This flaw allows authenticated, high-privileged remote attackers to view sensitive information in system log files. There are no workarounds available, and users are advised to upgrade to fixed software versions.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the debug logging function of the Cisco Duo Authentication Proxy could allow an authenticated, high-privileged remote attacker to access sensitive information that is inadequately masked in system log files. This could lead to unauthorized disclosure of sensitive data, which should remain restricted. Cisco has released software updates to address this vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Identity Services Engine Arbitrary File Upload Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-identity-services-engine-arbitrary-file-upload-vulnerability/</link>
      <pubDate>Wed, 20 Aug 2025 17:00:28 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-identity-services-engine-arbitrary-file-upload-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 4.9&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium-severity vulnerability has been identified in the Cisco Identity Services Engine (ISE) that allows authenticated attackers with administrative privileges to upload arbitrary files. No workarounds are available, and software updates have been released to address this issue.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the GUI of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative privileges to upload files to an affected device. This vulnerability arises from improper validation of the file copy function, enabling attackers to exploit it by sending a crafted file upload through the Cisco ISE GUI. A successful exploit could lead to arbitrary file uploads on the affected system.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-ios-and-ios-xe-software-smart-install-remote-code-execution-vulnerability/</link>
      <pubDate>Wed, 20 Aug 2025 15:00:23 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-ios-and-ios-xe-software-smart-install-remote-code-execution-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#b91c1c;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: CRITICAL — CVSS 9.8&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A critical vulnerability in the Smart Install feature of Cisco IOS and IOS XE Software allows unauthenticated remote attackers to execute arbitrary code or trigger a denial of service on affected devices. Immediate action is required to mitigate risks.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;Cisco has identified a vulnerability in the Smart Install feature of its IOS and IOS XE Software. This flaw allows an unauthenticated remote attacker to send crafted messages to devices, potentially leading to a buffer overflow. Successful exploitation can result in device reloads, arbitrary code execution, or an indefinite loop causing a watchdog crash. Cisco has observed ongoing exploitation attempts and strongly recommends upgrading to fixed software releases.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Web Services Denial of Service Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-secure-firewall-adaptive-security-appliance-and-secure-firewall-threat-defense-software-web-services-denial-of-service-vulnerability/</link>
      <pubDate>Thu, 14 Aug 2025 17:06:34 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-secure-firewall-adaptive-security-appliance-and-secure-firewall-threat-defense-software-web-services-denial-of-service-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 8.6&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A buffer overflow vulnerability has been identified in the web services interface of Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Software. This vulnerability allows unauthenticated remote attackers to cause a denial of service (DoS) condition. Cisco has released software updates to address this issue, and there are no workarounds available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the web services interface of Cisco Secure Firewall ASA and FTD Software could allow an unauthenticated, remote attacker to exploit a buffer overflow condition. This occurs due to insufficient boundary checks for specific data provided to the web services interface. An attacker could send a crafted HTTP request to the affected system, leading to a system reload and resulting in a denial of service (DoS).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Access Control Rules Bypass Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-secure-firewall-adaptive-security-appliance-and-secure-firewall-threat-defense-software-access-control-rules-bypass-vulnerability/</link>
      <pubDate>Thu, 14 Aug 2025 17:06:12 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-secure-firewall-adaptive-security-appliance-and-secure-firewall-threat-defense-software-access-control-rules-bypass-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 5.3&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium severity vulnerability has been identified in Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Software, allowing unauthenticated remote attackers to bypass access control rules for loopback interfaces. No workarounds are available, and software updates are necessary to mitigate the risk.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;Cisco has disclosed a vulnerability in the access control rules implementation for loopback interfaces in its Secure Firewall ASA and FTD Software. This flaw could enable an unauthenticated remote attacker to send traffic that should be blocked to a loopback interface, effectively bypassing configured access control rules. The vulnerability arises from improper enforcement of these rules, posing a potential risk to network security.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco IOS, IOS XE, Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerabilities</title>
      <link>https://www.phllaps.net/posts/cisco-ios-ios-xe-secure-firewall-adaptive-security-appliance-and-secure-firewall-threat-defense-software-ikev2-denial-of-service-vulnerabilities/</link>
      <pubDate>Thu, 14 Aug 2025 17:05:50 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-ios-ios-xe-secure-firewall-adaptive-security-appliance-and-secure-firewall-threat-defense-software-ikev2-denial-of-service-vulnerabilities/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 8.6&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;Cisco has identified multiple high-severity vulnerabilities in the IKEv2 feature of Cisco IOS, IOS XE, Secure Firewall ASA, and Secure Firewall FTD software that could allow unauthenticated remote attackers to trigger denial of service (DoS) conditions. Software updates are available to address these vulnerabilities.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;Cisco has released an advisory detailing several vulnerabilities in the Internet Key Exchange Version 2 (IKEv2) feature across various Cisco software platforms. These vulnerabilities can be exploited by unauthenticated remote attackers to cause devices to reload or trigger memory leaks, leading to a denial of service condition.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Authenticated Command Injection Vulnerabilities</title>
      <link>https://www.phllaps.net/posts/cisco-secure-firewall-adaptive-security-appliance-and-secure-firewall-threat-defense-software-authenticated-command-injection-vulnerabilities/</link>
      <pubDate>Thu, 14 Aug 2025 17:05:30 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-secure-firewall-adaptive-security-appliance-and-secure-firewall-threat-defense-software-authenticated-command-injection-vulnerabilities/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.0&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;Cisco has identified multiple authenticated command injection vulnerabilities in the Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Software. These vulnerabilities could allow an authenticated local attacker to execute arbitrary commands on the underlying operating system with root-level privileges. The highest CVSS score is 6.0, indicating a medium severity risk. Software updates are available to address these vulnerabilities, but there are no workarounds.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software DHCP Denial of Service Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-secure-firewall-adaptive-security-appliance-and-secure-firewall-threat-defense-software-dhcp-denial-of-service-vulnerability/</link>
      <pubDate>Thu, 14 Aug 2025 17:05:11 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-secure-firewall-adaptive-security-appliance-and-secure-firewall-threat-defense-software-dhcp-denial-of-service-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 4.3&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium-severity vulnerability has been identified in the DHCP client functionality of Cisco Secure Firewall ASA and FTD Software. This flaw could allow an unauthenticated adjacent attacker to exhaust device memory, leading to a Denial of Service (DoS) condition. Cisco has released software updates to mitigate this risk, but no workarounds are available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the DHCP client functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software has been discovered. This issue arises from improper validation of incoming DHCP packets, allowing an attacker to send crafted DHCPv4 packets to the device. If exploited, the attacker could exhaust the device&amp;rsquo;s available memory, resulting in service unavailability and requiring a manual reboot to restore functionality.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software VPN Web Server Denial of Service Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-secure-firewall-adaptive-security-appliance-and-secure-firewall-threat-defense-software-vpn-web-server-denial-of-service-vulnerability/</link>
      <pubDate>Thu, 14 Aug 2025 17:04:50 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-secure-firewall-adaptive-security-appliance-and-secure-firewall-threat-defense-software-vpn-web-server-denial-of-service-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 8.5&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A high-severity vulnerability has been identified in the Remote Access SSL VPN service of Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Software. This flaw could allow an authenticated attacker to create or delete files on the underlying operating system, potentially leading to a denial of service (DoS) condition. Cisco has released software updates to address this issue, and there are no available workarounds.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Network Address Translation DNS Inspection Denial of Service Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-secure-firewall-adaptive-security-appliance-and-secure-firewall-threat-defense-software-network-address-translation-dns-inspection-denial-of-service-vulnerability/</link>
      <pubDate>Thu, 14 Aug 2025 17:04:30 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-secure-firewall-adaptive-security-appliance-and-secure-firewall-threat-defense-software-network-address-translation-dns-inspection-denial-of-service-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 8.6&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A high-severity vulnerability has been identified in Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Software, specifically affecting the Network Address Translation (NAT) DNS inspection feature. An unauthenticated remote attacker could exploit this vulnerability to cause a denial of service (DoS) condition by sending crafted DNS packets. Cisco has released software updates to address this issue, but no workarounds are available.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL/TLS Certificate Denial of Service Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-secure-firewall-adaptive-security-appliance-and-secure-firewall-threat-defense-software-ssl-tls-certificate-denial-of-service-vulnerability/</link>
      <pubDate>Thu, 14 Aug 2025 17:04:09 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-secure-firewall-adaptive-security-appliance-and-secure-firewall-threat-defense-software-ssl-tls-certificate-denial-of-service-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 8.6&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A high-severity vulnerability in Cisco Secure Firewall ASA and FTD Software could allow unauthenticated remote attackers to trigger a denial of service (DoS) by sending a crafted SSL/TLS certificate. Immediate action is required to patch affected systems.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;Cisco has identified a vulnerability in the certificate processing of its Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software. This flaw allows an unauthenticated remote attacker to send a specially crafted SSL/TLS certificate to an affected device, potentially causing it to reload unexpectedly and resulting in a denial of service (DoS) condition.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerabilities</title>
      <link>https://www.phllaps.net/posts/cisco-secure-firewall-adaptive-security-appliance-and-secure-firewall-threat-defense-software-remote-access-ssl-vpn-denial-of-service-vulnerabilities/</link>
      <pubDate>Thu, 14 Aug 2025 17:03:54 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-secure-firewall-adaptive-security-appliance-and-secure-firewall-threat-defense-software-remote-access-ssl-vpn-denial-of-service-vulnerabilities/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 8.6&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;Multiple vulnerabilities have been identified in Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Software, allowing unauthenticated remote attackers to cause denial of service (DoS) conditions. Cisco has released software updates to address these vulnerabilities, but there are no workarounds available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;Cisco has disclosed vulnerabilities in the management and VPN web servers of its Secure Firewall ASA and FTD Software. These vulnerabilities stem from improper validation of user-supplied input, enabling attackers to send crafted HTTP requests that could lead to the device becoming unresponsive or unexpectedly reloading, resulting in a denial of service (DoS) condition.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access VPN Web Server Denial of Service Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-secure-firewall-adaptive-security-appliance-and-secure-firewall-threat-defense-software-remote-access-vpn-web-server-denial-of-service-vulnerability/</link>
      <pubDate>Thu, 14 Aug 2025 17:03:38 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-secure-firewall-adaptive-security-appliance-and-secure-firewall-threat-defense-software-remote-access-vpn-web-server-denial-of-service-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 7.7&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A denial of service (DoS) vulnerability has been identified in the Remote Access SSL VPN service for Cisco Secure Firewall ASA and FTD Software. This flaw could allow an authenticated attacker to cause the device to reload unexpectedly. Cisco has released updates to address this issue, but no workarounds are available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software has been discovered. This vulnerability arises from incomplete error checking when parsing an HTTP header field value. An authenticated attacker could exploit this by sending a crafted HTTP request, leading to an unexpected device reload and resulting in a denial of service (DoS) condition.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Secure Firewall Management Center Software Authorization Bypass Vulnerabilities</title>
      <link>https://www.phllaps.net/posts/cisco-secure-firewall-management-center-software-authorization-bypass-vulnerabilities/</link>
      <pubDate>Thu, 14 Aug 2025 17:03:20 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-secure-firewall-management-center-software-authorization-bypass-vulnerabilities/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.5&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;Multiple vulnerabilities have been identified in the Cisco Secure Firewall Management Center (FMC) Software that could allow authenticated, low-privileged remote attackers to access unauthorized files. The highest CVSS score for these vulnerabilities is 6.5, indicating a medium level of risk. Software updates are available to address these issues, but there are no workarounds.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;Cisco has disclosed multiple vulnerabilities in the web-based management interface of the Cisco Secure Firewall Management Center (FMC) Software. These vulnerabilities could allow an authenticated, low-privileged remote attacker to access files they are not authorized to view, including troubleshoot files and generated reports from different domains managed on the same FMC instance. The vulnerabilities stem from missing authorization checks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Secure Firewall Management Center Software Command Injection Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-secure-firewall-management-center-software-command-injection-vulnerability/</link>
      <pubDate>Thu, 14 Aug 2025 17:03:04 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-secure-firewall-management-center-software-command-injection-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 4.9&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A command injection vulnerability has been identified in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software. This flaw allows authenticated attackers with Administrator-level privileges to execute arbitrary commands on the underlying operating system. The highest CVSS score for this vulnerability is 4.9, classified as Medium severity. No workarounds are available, and software updates have been released to address the issue.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Secure Firewall Management Center and Secure Firewall Threat Defense Software Command Injection Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-secure-firewall-management-center-and-secure-firewall-threat-defense-software-command-injection-vulnerability/</link>
      <pubDate>Thu, 14 Aug 2025 17:02:50 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-secure-firewall-management-center-and-secure-firewall-threat-defense-software-command-injection-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.0&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A command injection vulnerability has been identified in Cisco Secure Firewall Management Center (FMC) and Secure Firewall Threat Defense (FTD) Software. This medium-severity issue allows authenticated local attackers to execute arbitrary commands on the underlying operating system. Cisco has released software updates to address this vulnerability, but no workarounds are available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the command-line interface (CLI) of Cisco Secure Firewall Management Center (FMC) and Secure Firewall Threat Defense (FTD) Software has been discovered. This flaw arises from improper input validation for specific CLI commands, enabling an authenticated local attacker to inject operating system commands. If exploited, the attacker could escape the restricted command prompt and execute arbitrary commands as root on the underlying operating system. Successful exploitation requires valid Administrator credentials.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Secure Firewall Management Center Software HTML Injection Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-secure-firewall-management-center-software-html-injection-vulnerability/</link>
      <pubDate>Thu, 14 Aug 2025 17:02:33 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-secure-firewall-management-center-software-html-injection-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 8.5&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A high-severity HTML injection vulnerability has been identified in the Cisco Secure Firewall Management Center (FMC) Software. This flaw allows authenticated remote attackers to inject arbitrary HTML content into device-generated documents, potentially leading to sensitive information exposure. Cisco has released updates to address this issue, but there are no workarounds available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center Software could allow an authenticated, remote attacker to inject arbitrary HTML content into a device-generated document. This vulnerability arises from improper validation of user-supplied data. An attacker with valid credentials (at least Security Analyst role) could exploit this vulnerability to alter document layouts, read arbitrary files from the underlying operating system, and conduct server-side request forgery (SSRF) attacks.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Secure Firewall Management Center Software RADIUS Remote Code Execution Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-secure-firewall-management-center-software-radius-remote-code-execution-vulnerability/</link>
      <pubDate>Thu, 14 Aug 2025 17:02:15 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-secure-firewall-management-center-software-radius-remote-code-execution-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#b91c1c;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: CRITICAL — CVSS 10.0&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A critical vulnerability has been identified in the Cisco Secure Firewall Management Center (FMC) Software that allows unauthenticated remote code execution via the RADIUS subsystem. This vulnerability has a CVSS score of 10.0, indicating a severe risk. Immediate action is required to patch affected systems.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the RADIUS subsystem of Cisco Secure FMC Software could allow an unauthenticated, remote attacker to execute arbitrary shell commands on the device. This issue arises from improper handling of user input during the authentication phase. Exploitation requires that RADIUS authentication is configured for the web-based management interface, SSH management, or both.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Secure Firewall Management Center Software XPATH Injection Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-secure-firewall-management-center-software-xpath-injection-vulnerability/</link>
      <pubDate>Thu, 14 Aug 2025 17:01:57 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-secure-firewall-management-center-software-xpath-injection-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 4.9&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium-severity XPATH injection vulnerability has been identified in the Cisco Secure Firewall Management Center (FMC) Software, allowing authenticated attackers to retrieve sensitive information. There are no workarounds available, and users are advised to apply the necessary software updates.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software has been discovered. This vulnerability arises from insufficient input validation, enabling an authenticated remote attacker to send crafted requests to the management interface. Successful exploitation could lead to the retrieval of sensitive information from the affected device. Importantly, the attacker must possess valid administrative credentials to exploit this vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Secure Firewall Management Center Software Cross-Site Scripting Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-secure-firewall-management-center-software-cross-site-scripting-vulnerability/</link>
      <pubDate>Thu, 14 Aug 2025 17:01:43 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-secure-firewall-management-center-software-cross-site-scripting-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.1&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium severity cross-site scripting (XSS) vulnerability has been identified in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software. This flaw could allow unauthenticated remote attackers to execute arbitrary scripts in the context of the interface. There are no workarounds available, but Cisco has released software updates to address this issue.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;Cisco has reported a vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software. This vulnerability arises from insufficient validation of user-supplied input, allowing attackers to execute arbitrary script code or access sensitive browser-based information through crafted input.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Firepower 2100 Series IPv6 over IPsec Denial of Service Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-secure-firewall-adaptive-security-appliance-and-secure-firewall-threat-defense-software-for-firepower-2100-series-ipv6-over-ipsec-denial-of-service-vulnerability/</link>
      <pubDate>Thu, 14 Aug 2025 17:01:22 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-secure-firewall-adaptive-security-appliance-and-secure-firewall-threat-defense-software-for-firepower-2100-series-ipv6-over-ipsec-denial-of-service-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 8.6&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A denial of service (DoS) vulnerability has been identified in the Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Software for the Firepower 2100 Series. This vulnerability allows unauthenticated remote attackers to cause a device reload by sending specially crafted IPv6 packets over an IPsec VPN connection. Cisco has released software updates to address this issue, but there are no workarounds available.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Secure Firewall Threat Defense Software Snort 3 Denial of Service Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-secure-firewall-threat-defense-software-snort-3-denial-of-service-vulnerability/</link>
      <pubDate>Thu, 14 Aug 2025 17:01:05 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-secure-firewall-threat-defense-software-snort-3-denial-of-service-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 8.6&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A high-severity denial of service (DoS) vulnerability has been identified in the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense Software. An unauthenticated remote attacker can exploit this issue, leading to potential service disruptions. Cisco has released software updates to address this vulnerability, but no workarounds are available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the packet inspection functionality of the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service condition on affected devices. This issue arises from incorrect processing of traffic being inspected, which can lead to an infinite loop during traffic inspection. Although the system watchdog will automatically restart the Snort process, the vulnerability poses a significant risk of service interruption.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Secure Firewall Threat Defense Software Geolocation Remote Access VPN Bypass Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-secure-firewall-threat-defense-software-geolocation-remote-access-vpn-bypass-vulnerability/</link>
      <pubDate>Thu, 14 Aug 2025 17:00:43 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-secure-firewall-threat-defense-software-geolocation-remote-access-vpn-bypass-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 5.8&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium-severity vulnerability has been identified in the Geolocation-Based Remote Access VPN feature of Cisco Secure Firewall Threat Defense Software. This flaw allows unauthenticated attackers to bypass security policies, potentially granting unauthorized access to restricted networks. No workarounds are available, and software updates are necessary to mitigate the risk.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in Cisco Secure Firewall Threat Defense (FTD) Software&amp;rsquo;s Geolocation-Based Remote Access (RA) VPN feature could enable an unauthenticated, remote attacker to bypass configured policies that control HTTP connections based on geographical location. This issue arises from incomplete URL parsing, allowing attackers to exploit it by sending crafted HTTP connections. Successful exploitation could lead to unauthorized access to networks that should otherwise be protected.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Firepower 3100 and 4200 Series TLS 1.3 Cipher Denial of Service Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-secure-firewall-adaptive-security-appliance-and-secure-firewall-threat-defense-software-for-firepower-3100-and-4200-series-tls-1-3-cipher-denial-of-service-vulnerability/</link>
      <pubDate>Thu, 14 Aug 2025 17:00:24 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-secure-firewall-adaptive-security-appliance-and-secure-firewall-threat-defense-software-for-firepower-3100-and-4200-series-tls-1-3-cipher-denial-of-service-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 7.7&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the TLS 1.3 implementation for Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Software on Firepower 3100 and 4200 Series devices could allow an authenticated remote attacker to cause a denial of service (DoS) condition. This affects the device&amp;rsquo;s ability to accept new SSL/TLS or VPN requests. Cisco has released software updates to address this issue, and there are workarounds available.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Catalyst Center Unauthenticated API Access Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-catalyst-center-unauthenticated-api-access-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 18:46:51 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-catalyst-center-unauthenticated-api-access-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 7.3&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A high-severity vulnerability has been identified in the Cisco Catalyst Center, allowing unauthenticated remote attackers to read and modify proxy configuration settings via an unprotected API endpoint. This could disrupt internet traffic or allow interception of outbound traffic. Users are advised to upgrade to fixed software version 2.3.7.9 or later.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the management API of Cisco Catalyst Center (formerly Cisco DNA Center) has been discovered. This issue stems from a lack of authentication on an API endpoint, enabling unauthenticated remote attackers to send requests that could read or modify the outgoing proxy configuration. Such exploitation could disrupt internet traffic or allow attackers to intercept outbound traffic.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Webex Meeting Client Join Certificate Validation Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-webex-meeting-client-join-certificate-validation-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 18:23:29 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-webex-meeting-client-join-certificate-validation-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 5.4&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium-severity vulnerability in the Cisco Webex Meeting Client could allow an unauthenticated attacker on a local network to join meetings as another user. Cisco has addressed this issue, and no user action is required.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability was identified in the meeting-join functionality of Cisco Webex Meetings. This flaw could permit an unauthenticated, network-proximate attacker to impersonate a legitimate user during the meeting-join process. The vulnerability arises from issues with client certificate validation, allowing an attacker to intercept and complete a meeting-join flow if they are positioned on a local or adjacent network. Cisco has confirmed that there is no known malicious exploitation of this vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities</title>
      <link>https://www.phllaps.net/posts/cisco-identity-services-engine-stored-cross-site-scripting-vulnerabilities/</link>
      <pubDate>Sat, 09 Aug 2025 18:22:05 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-identity-services-engine-stored-cross-site-scripting-vulnerabilities/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 5.4&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;Multiple stored cross-site scripting (XSS) vulnerabilities have been identified in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). These vulnerabilities could allow authenticated attackers to modify configurations or execute malicious scripts. Software updates are available to address these issues, but no workarounds exist.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;Cisco has disclosed multiple vulnerabilities in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). These vulnerabilities could allow an authenticated, remote attacker to conduct stored XSS attacks or modify device configurations. The vulnerabilities stem from insufficient validation of user input and lack of server-side validation of administrator permissions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Catalyst Center Insufficient Access Control Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-catalyst-center-insufficient-access-control-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:35:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-catalyst-center-insufficient-access-control-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 4.7&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium-severity vulnerability has been identified in Cisco Catalyst Center, allowing authenticated remote attackers to read and modify data due to insufficient access control on HTTP requests. No workarounds are available, and affected users are advised to upgrade to fixed software versions.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;Cisco has disclosed a vulnerability in the Cisco Catalyst Center, formerly known as Cisco DNA Center. This flaw stems from insufficient enforcement of access control on HTTP requests, enabling an authenticated remote attacker to exploit the vulnerability by sending a crafted HTTP request. A successful exploit could allow attackers to read and modify data managed by an internal service on the affected device.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Catalyst SD-WAN Manager Arbitrary File Creation Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-catalyst-sd-wan-manager-arbitrary-file-creation-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:35:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-catalyst-sd-wan-manager-arbitrary-file-creation-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.5&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;Cisco published a security advisory. See the Fixed software table below for the version you should upgrade to.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the application data endpoints of Cisco Catalyst SD-WAN Manager, formerly Cisco SD-WAN vManage, could allow an authenticated, remote attacker to write arbitrary files to an affected system.&lt;/p&gt;&#xA;&lt;p&gt;This vulnerability is due to improper validation of requests to APIs. An attacker could exploit this vulnerability by sending malicious requests to an API within the affected system. A successful exploit could allow the attacker to conduct directory traversal attacks and write files to an arbitrary location on the affected system.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Catalyst SD-WAN Manager Arbitrary File Overwrite Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-catalyst-sd-wan-manager-arbitrary-file-overwrite-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:35:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-catalyst-sd-wan-manager-arbitrary-file-overwrite-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 5.5&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium-severity vulnerability has been identified in the Cisco Catalyst SD-WAN Manager, allowing authenticated local attackers to overwrite arbitrary files on the device. Immediate software updates are recommended as there are no workarounds available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the command-line interface (CLI) of the Cisco Catalyst SD-WAN Manager (formerly Cisco SD-WAN vManage) could allow an authenticated local attacker to overwrite arbitrary files on the local file system of an affected device. This vulnerability arises from improper access controls on files in the local file system. An attacker with valid read-only credentials can exploit this by executing crafted commands, potentially gaining root user privileges.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Catalyst SD-WAN Manager Certificate Validation Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-catalyst-sd-wan-manager-certificate-validation-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:35:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-catalyst-sd-wan-manager-certificate-validation-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 5.9&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the Cisco Catalyst SD-WAN Manager could allow an unauthenticated remote attacker to access sensitive information due to improper certificate validation. Cisco has released updates to address this issue, but there are no workarounds available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability has been identified in the certificate validation processing of Cisco Catalyst SD-WAN Manager, previously known as Cisco SD-WAN vManage. This flaw could enable an unauthenticated remote attacker to exploit improper validation of certificates used by the Smart Licensing feature. By intercepting traffic sent over the Internet, an attacker could potentially gain access to sensitive information, including device credentials for connecting to Cisco cloud services.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Duo Self-Service Portal Command Injection Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-duo-self-service-portal-command-injection-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:35:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-duo-self-service-portal-command-injection-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 5.4&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A command injection vulnerability has been identified in the Cisco Duo Self-Service Portal, allowing unauthenticated remote attackers to inject arbitrary commands into emails sent by the service. Cisco has addressed this issue, and no customer action is necessary.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the self-service portal of Cisco Duo could allow an unauthenticated, remote attacker to inject arbitrary commands into emails sent by the service. This is due to insufficient input validation. A successful exploit could enable attackers to send emails containing malicious content to unsuspecting users.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Identity Services Engine RADIUS Denial of Service Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-identity-services-engine-radius-denial-of-service-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:35:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-identity-services-engine-radius-denial-of-service-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 8.6&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the Cisco Identity Services Engine (ISE) related to RADIUS message processing could allow an unauthenticated attacker to trigger a denial of service (DoS) condition. Cisco has released software updates to address this issue, but there are no workarounds available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;Cisco has identified a vulnerability in the RADIUS message processing feature of Cisco Identity Services Engine (ISE). This flaw allows an unauthenticated, remote attacker to send specific authentication requests that can cause the Cisco ISE to reload, leading to a denial of service (DoS) condition. The vulnerability is attributed to improper handling of certain RADIUS requests.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches Secure Boot Bypass Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-ios-software-for-cisco-catalyst-2960x-2960xr-2960cx-and-3560cx-series-switches-secure-boot-bypass-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:35:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-ios-software-for-cisco-catalyst-2960x-2960xr-2960cx-and-3560cx-series-switches-secure-boot-bypass-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.8&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium-severity vulnerability has been identified in Cisco IOS Software for Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches. This vulnerability allows an attacker to bypass secure boot protections, potentially executing arbitrary code at boot time. Cisco has released software updates to address this issue, and no workarounds are available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in Cisco IOS Software affects Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches. This flaw allows an authenticated local attacker with privilege level 15 or an unauthenticated attacker with physical access to execute persistent code during the boot process, effectively breaking the device&amp;rsquo;s chain of trust. The vulnerability arises from missing signature verification for certain files loaded during boot. Cisco has raised the Security Impact Rating (SIR) from Medium to High due to the potential severity of this issue.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco IOS Software Industrial Ethernet Switch Device Manager Privilege Escalation Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-ios-software-industrial-ethernet-switch-device-manager-privilege-escalation-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:35:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-ios-software-industrial-ethernet-switch-device-manager-privilege-escalation-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 8.3&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A privilege escalation vulnerability has been identified in the Cisco IOS Software Industrial Ethernet Switch Device Manager. This issue could allow authenticated remote attackers to elevate their privileges. The vulnerability has a CVSS score of 8.3 (High severity). Cisco has released software updates to address this vulnerability, and there are no workarounds available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the Cisco Industrial Ethernet Switch Device Manager (DM) of Cisco IOS Software allows an authenticated remote attacker to elevate privileges due to insufficient validation of authorizations for authenticated users. By sending a crafted HTTP request to an affected device, an attacker with valid credentials for a user account with privilege level 5 or higher could exploit this vulnerability to gain privilege level 15.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco IOS XE Software Bootstrap Arbitrary File Write Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-ios-xe-software-bootstrap-arbitrary-file-write-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:35:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-ios-xe-software-bootstrap-arbitrary-file-write-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.0&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium severity vulnerability has been identified in the Cisco IOS XE Software Bootstrap that allows an authenticated local attacker to write arbitrary files to an affected system. Cisco has released software updates to address this issue, but no workarounds are available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the bootstrap loading of Cisco IOS XE Software could allow an authenticated, local attacker to write arbitrary files to an affected system. This issue arises from insufficient input validation of the bootstrap file used when a device is deployed in SD-WAN mode or configured for SD-Routing. An attacker could exploit this by modifying a bootstrap file generated by Cisco Catalyst SD-WAN Manager and loading it into the device flash, leading to potential arbitrary file writes to the operating system.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco IOS XE Software for Cisco ASR 903 Aggregation Services Routers ARP Denial of Service Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-ios-xe-software-for-cisco-asr-903-aggregation-services-routers-arp-denial-of-service-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:35:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-ios-xe-software-for-cisco-asr-903-aggregation-services-routers-arp-denial-of-service-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 7.4&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A high-severity vulnerability has been identified in Cisco IOS XE Software for ASR 903 Aggregation Services Routers, allowing unauthenticated adjacent attackers to trigger a denial of service (DoS) condition. Cisco has released software updates to address this issue, but there are no workarounds available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the Cisco Express Forwarding functionality of Cisco IOS XE Software for Cisco ASR 903 Aggregation Services Routers with Route Switch Processor 3 (RSP3C) could allow an unauthenticated adjacent attacker to exploit the system. This vulnerability arises from improper memory management when processing Address Resolution Protocol (ARP) messages. By sending crafted ARP messages at a high rate, an attacker could exhaust system resources, leading to a reload of the active route switch processor (RSP). If there is no redundant RSP, the router will reload.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco IOS XE Wireless Controller Software Cisco Discovery Protocol Denial of Service Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-ios-xe-wireless-controller-software-cisco-discovery-protocol-denial-of-service-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:35:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-ios-xe-wireless-controller-software-cisco-discovery-protocol-denial-of-service-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 7.4&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A high-severity vulnerability has been identified in Cisco IOS XE Wireless Controller Software, allowing unauthenticated adjacent attackers to cause a denial of service (DoS) condition. Cisco has released software updates to address this issue, and there are no workarounds available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the Cisco IOS XE Wireless Controller Software could enable an unauthenticated, adjacent attacker to exploit insufficient input validation of Cisco Discovery Protocol (CDP) neighbor reports. By sending a crafted CDP packet to an affected access point (AP), an attacker could trigger an unexpected reload of the wireless controller managing the AP, resulting in a DoS condition that disrupts the wireless network.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco IOS XE Wireless Controller Software Unauthorized User Deletion Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-ios-xe-wireless-controller-software-unauthorized-user-deletion-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:35:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-ios-xe-wireless-controller-software-unauthorized-user-deletion-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.5&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the Cisco IOS XE Wireless Controller Software allows authenticated remote attackers to delete user accounts, including those with administrative privileges. This issue arises from insufficient access control in the lobby ambassador web interface. No workarounds are available, but Cisco has released software updates to address the vulnerability.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;Cisco has identified a vulnerability in the lobby ambassador web interface of its IOS XE Wireless Controller Software. This flaw enables authenticated attackers to remove arbitrary user accounts from affected devices by exploiting insufficient access control. The vulnerability can only be exploited if the attacker has obtained credentials for a lobby ambassador account, which is not configured by default.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Meraki MX and Z Series Teleworker Gateway AnyConnect VPN Denial of Service Vulnerabilities</title>
      <link>https://www.phllaps.net/posts/cisco-meraki-mx-and-z-series-teleworker-gateway-anyconnect-vpn-denial-of-service-vulnerabilities/</link>
      <pubDate>Sat, 09 Aug 2025 15:35:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-meraki-mx-and-z-series-teleworker-gateway-anyconnect-vpn-denial-of-service-vulnerabilities/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 8.6&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;Cisco Meraki MX and Z Series Teleworker Gateway devices are affected by multiple denial of service (DoS) vulnerabilities in the AnyConnect VPN server. These vulnerabilities could allow an unauthenticated attacker to disrupt VPN services. Cisco has released software updates to address these issues, and there are no workarounds available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;Multiple vulnerabilities have been identified in the Cisco AnyConnect VPN server of Cisco Meraki MX and Z Series Teleworker Gateway devices. An unauthenticated, remote attacker could exploit these vulnerabilities to cause a denial of service (DoS) condition, resulting in the failure of established SSL VPN connections and preventing new connections from being established.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Meraki MX and Z Series Teleworker Gateway AnyConnect VPN Session Takeover and Denial of Service Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-meraki-mx-and-z-series-teleworker-gateway-anyconnect-vpn-session-takeover-and-denial-of-service-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:35:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-meraki-mx-and-z-series-teleworker-gateway-anyconnect-vpn-session-takeover-and-denial-of-service-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 5.8&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability has been identified in the Cisco AnyConnect VPN server of Cisco Meraki MX and Z Series Teleworker Gateway devices. This flaw could allow an unauthenticated remote attacker to hijack VPN sessions or cause denial of service (DoS) conditions for users. Cisco has released software updates to address this issue, and no workarounds are available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the Cisco AnyConnect VPN server could enable an unauthenticated remote attacker to hijack an AnyConnect VPN session or induce a denial of service (DoS) condition for users of the service. This vulnerability stems from weak entropy during the VPN authentication process and a race condition within the same process. Attackers can exploit this flaw by guessing an authentication handler and sending crafted HTTPS requests to the affected device.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Nexus Dashboard Fabric Controller SSH Host Key Validation Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-nexus-dashboard-fabric-controller-ssh-host-key-validation-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:35:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-nexus-dashboard-fabric-controller-ssh-host-key-validation-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 8.7&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A high-severity vulnerability has been identified in the SSH implementation of Cisco Nexus Dashboard Fabric Controller (NDFC), allowing unauthenticated remote attackers to impersonate managed devices due to insufficient SSH host key validation. Cisco has released software updates to address this issue, with no workarounds available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the SSH implementation of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to impersonate Cisco NDFC-managed devices. This vulnerability arises from insufficient SSH host key validation, enabling attackers to perform machine-in-the-middle attacks on SSH connections. A successful exploit could lead to traffic interception and user credential capture.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Secure Network Analytics Manager API Authorization Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-secure-network-analytics-manager-api-authorization-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:35:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-secure-network-analytics-manager-api-authorization-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.5&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium-severity vulnerability has been identified in the Cisco Secure Network Analytics Manager API, which could allow authenticated low-privileged users to generate fraudulent findings. Cisco has released updates to address this issue, but no workarounds are available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the API subsystem of Cisco Secure Network Analytics Manager and Cisco Secure Network Analytics Virtual Manager could allow an authenticated, remote attacker with low privileges to create fraudulent findings. This vulnerability arises from insufficient authorization enforcement on a specific API. An attacker could exploit this by authenticating as a low-privileged user and making crafted API calls, potentially obfuscating legitimate findings in analytics reports or generating false alarms and alerts.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Secure Network Analytics Manager Privilege Escalation Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-secure-network-analytics-manager-privilege-escalation-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:35:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-secure-network-analytics-manager-privilege-escalation-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.5&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A privilege escalation vulnerability has been identified in Cisco Secure Network Analytics Manager and Cisco Secure Network Analytics Virtual Manager. This flaw allows authenticated attackers with valid administrative credentials to execute arbitrary commands as root on the underlying operating system. Cisco has released software updates to address this issue, but no workarounds are available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the web-based management interface of Cisco Secure Network Analytics Manager and Cisco Secure Network Analytics Virtual Manager was discovered. This vulnerability stems from insufficient input validation in specific fields, allowing an authenticated attacker to send crafted input and execute arbitrary commands with root privileges on the underlying operating system.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Unified Communications Products Command Injection Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-unified-communications-products-command-injection-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:35:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-unified-communications-products-command-injection-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.0&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A command injection vulnerability has been identified in multiple Cisco Unified Communications products. This flaw allows an authenticated local attacker to execute arbitrary commands on the underlying operating system as the root user. Cisco has released software updates to address this issue, and there are no workarounds available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the Command Line Interface (CLI) of several Cisco Unified Communications products could allow an authenticated, local attacker to execute arbitrary commands on the affected device&amp;rsquo;s operating system as the root user. This vulnerability stems from improper validation of user-supplied command arguments. To exploit this vulnerability, the attacker must possess valid administrative credentials.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Unified Communications Products Privilege Escalation Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-unified-communications-products-privilege-escalation-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:35:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-unified-communications-products-privilege-escalation-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 5.1&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A privilege escalation vulnerability has been identified in multiple Cisco Unified Communications and Contact Center Solutions products. An authenticated local attacker could exploit this vulnerability to gain root access on affected devices. Cisco has released software updates to address this issue, but there are no workarounds available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in various Cisco Unified Communications and Contact Center Solutions products could allow an authenticated, local attacker to elevate their privileges to root on an affected device. This vulnerability arises from excessive permissions assigned to system commands, enabling an attacker to execute crafted commands on the underlying operating system. To exploit this vulnerability, administrative access to the ESXi hypervisor is required.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Unified Contact Center Enterprise Cloud Connect Insufficient Access Control Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-unified-contact-center-enterprise-cloud-connect-insufficient-access-control-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:35:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-unified-contact-center-enterprise-cloud-connect-insufficient-access-control-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.5&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium-severity vulnerability has been identified in the Cloud Connect component of Cisco Unified Contact Center Enterprise (CCE). This flaw could allow unauthenticated, remote attackers to read and modify data on affected devices. Cisco has released software updates to address this issue, but there are no workarounds available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the Cloud Connect component of Cisco Unified Contact Center Enterprise (CCE) has been discovered. This issue arises from insufficient access controls, enabling unauthenticated remote attackers to send crafted TCP data to a specific port on affected devices. If successfully exploited, attackers could read or modify data on these devices.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Unified Intelligence Center Privilege Escalation Vulnerabilities</title>
      <link>https://www.phllaps.net/posts/cisco-unified-intelligence-center-privilege-escalation-vulnerabilities/</link>
      <pubDate>Sat, 09 Aug 2025 15:35:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-unified-intelligence-center-privilege-escalation-vulnerabilities/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 7.1&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;Multiple privilege escalation vulnerabilities have been identified in Cisco Unified Intelligence Center, allowing authenticated remote attackers to elevate their privileges. Cisco has released software updates to address these vulnerabilities, and there are no workarounds available.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;Cisco has disclosed vulnerabilities in the Cisco Unified Intelligence Center that could allow authenticated remote attackers to perform privilege escalation attacks. These vulnerabilities arise from insufficient validation of user-supplied parameters in API or HTTP requests, potentially enabling attackers to access or modify data beyond their intended access level.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Unified Intelligent Contact Management Enterprise Cross-Site Scripting Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-unified-intelligent-contact-management-enterprise-cross-site-scripting-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:35:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-unified-intelligent-contact-management-enterprise-cross-site-scripting-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.1&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A cross-site scripting (XSS) vulnerability has been identified in the web-based management interface of Cisco Unified Intelligent Contact Management Enterprise. This could allow an unauthenticated attacker to execute arbitrary script code. No workarounds are available, and software updates are forthcoming.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;Cisco has disclosed a vulnerability in the web-based management interface of Cisco Unified Intelligent Contact Management Enterprise. This vulnerability arises from insufficient user input validation, enabling an attacker to potentially execute arbitrary script code within the context of the affected interface. The attacker would need to persuade a user to click on a crafted link to exploit this vulnerability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Webex Meetings Services HTTP Cache Poisoning Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-webex-meetings-services-http-cache-poisoning-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:35:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-webex-meetings-services-http-cache-poisoning-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 4.3&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;A medium-severity HTTP cache poisoning vulnerability has been identified in Cisco Webex Meetings Services. No user action is required as Cisco has addressed the issue in the cloud-based service.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the client join services of Cisco Webex Meetings could allow an unauthenticated, remote attacker to manipulate cached HTTP responses. This issue arises from improper handling of malicious HTTP requests, potentially leading to incorrect HTTP responses being returned to clients. Fortunately, Cisco has already resolved this vulnerability, and no customer action is necessary to update on-premises software or devices.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Webex Services Cross-Site Scripting Vulnerabilities</title>
      <link>https://www.phllaps.net/posts/cisco-webex-services-cross-site-scripting-vulnerabilities/</link>
      <pubDate>Sat, 09 Aug 2025 15:35:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-webex-services-cross-site-scripting-vulnerabilities/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.1&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;Cisco has identified multiple cross-site scripting (XSS) vulnerabilities in Cisco Webex Services that could allow an unauthenticated remote attacker to exploit users. The vulnerabilities have been addressed, and no user action is required for updates.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;Multiple vulnerabilities in Cisco Webex could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. These vulnerabilities arise from improper filtering of user-supplied input. An attacker could exploit these vulnerabilities by persuading a user to follow a malicious link, which could lead to a successful XSS attack against the targeted user.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco ThousandEyes Endpoint Agent for Windows Arbitrary File Delete Vulnerabilities</title>
      <link>https://www.phllaps.net/posts/cisco-thousandeyes-endpoint-agent-for-windows-arbitrary-file-delete-vulnerabilities/</link>
      <pubDate>Sat, 09 Aug 2025 15:27:01 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-thousandeyes-endpoint-agent-for-windows-arbitrary-file-delete-vulnerabilities/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 5.3&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Multiple vulnerabilities in the update process of Cisco ThousandEyes Endpoint Agent for Windows could allow an authenticated, local attacker to delete arbitrary files on an affected device. These vulnerabilities are due to improper access controls on files that are in the local file system. An attacker could exploit these vulnerabilities by using a symbolic link to perform an agent upgrade…&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;No fixed release listed&lt;/strong&gt; yet; apply mitigations and monitor.&lt;/li&gt;&#xA;&lt;li&gt;Workarounds are documented in the advisory.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2025-20259.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;Multiple vulnerabilities in the update process of Cisco ThousandEyes Endpoint Agent for Windows could allow an authenticated, local attacker to delete arbitrary files on an affected device.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Unified Contact Center Express Editor Remote Code Execution Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-unified-contact-center-express-editor-remote-code-execution-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:25:56 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-unified-contact-center-express-editor-remote-code-execution-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 5.3&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;A vulnerability in the file opening process of Cisco Unified Contact Center Express (Unified CCX) Editor could allow an unauthenticated attacker to execute arbitrary code on an affected device. This vulnerability is due to insecure deserialization of Java objects by the affected software. An attacker could exploit this vulnerability by persuading an authenticated, local user to open a crafted .aef…&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;No fixed release listed&lt;/strong&gt; yet; apply mitigations and monitor.&lt;/li&gt;&#xA;&lt;li&gt;Workarounds are documented in the advisory.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2025-20275.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the file opening process of Cisco Unified Contact Center Express (Unified CCX) Editor could allow an unauthenticated attacker to execute arbitrary code on an affected device.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Unified Contact Center Express Vulnerabilities</title>
      <link>https://www.phllaps.net/posts/cisco-unified-contact-center-express-vulnerabilities/</link>
      <pubDate>Sat, 09 Aug 2025 15:25:01 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-unified-contact-center-express-vulnerabilities/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 4.8&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an authenticated, remote attacker to perform a stored cross-site scripting (XSS) attack or execute arbitrary code on an affected device. To exploit these vulnerabilities, the attacker must have valid administrative credentials. For more information about these vulnerabilities, see the Details [&amp;quot;#details&amp;quot;] section of…&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;No fixed release listed&lt;/strong&gt; yet; apply mitigations and monitor.&lt;/li&gt;&#xA;&lt;li&gt;Workarounds are documented in the advisory.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2025-20276, CVE-2025-20277, CVE-2025-20279.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;The vulnerabilities are not dependent on one another. Exploitation of one of the vulnerabilities is not required to exploit another vulnerability. In addition, a software release that is affected by one of the vulnerabilities may not be affected by the other vulnerabilities.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Integrated Management Controller Privilege Escalation Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-integrated-management-controller-privilege-escalation-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:23:48 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-integrated-management-controller-privilege-escalation-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 8.8&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;A vulnerability in the SSH connection handling of Cisco Integrated Management Controller (IMC) for Cisco UCS B-Series, UCS C-Series, UCS S-Series, and UCS X-Series Servers could allow an authenticated, remote attacker to access internal services with elevated privileges. This vulnerability is due to insufficient restrictions on access to internal services. An attacker with a valid user account could exploit this…&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;No fixed release listed&lt;/strong&gt; yet; apply mitigations and monitor.&lt;/li&gt;&#xA;&lt;li&gt;Workarounds are documented in the advisory.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2025-20261.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the SSH connection handling of Cisco Integrated Management Controller (IMC) for Cisco UCS B-Series, UCS C-Series, UCS S-Series, and UCS X-Series Servers could allow an authenticated, remote attacker to access internal services with elevated privileges.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Customer Collaboration Platform Information Disclosure Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-customer-collaboration-platform-information-disclosure-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:22:23 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-customer-collaboration-platform-information-disclosure-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 4.3&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMiner, could allow an unauthenticated, remote attacker to persuade users to disclose sensitive data. This vulnerability is due to improper sanitization of HTTP requests that are sent to the web-based chat interface. An attacker could exploit this vulnerability by sending crafted HTTP requests to the…&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;No fixed release listed&lt;/strong&gt; yet; apply mitigations and monitor.&lt;/li&gt;&#xA;&lt;li&gt;Workarounds are documented in the advisory.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2025-20129.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the web-based chat interface of Cisco Customer Collaboration Platform (CCP), formerly Cisco SocialMiner, could allow an unauthenticated, remote attacker to persuade users to disclose sensitive data.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Identity Services Engine on Cloud Platforms Static Credential Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-identity-services-engine-on-cloud-platforms-static-credential-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:21:15 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-identity-services-engine-on-cloud-platforms-static-credential-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#b91c1c;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: CRITICAL — CVSS 9.9&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to access sensitive data, execute limited administrative operations, modify system configurations, or disrupt services within the impacted systems. This vulnerability exists because credentials are improperly generated when Cisco ISE is being deployed…&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;No fixed release listed&lt;/strong&gt; yet; apply mitigations and monitor.&lt;/li&gt;&#xA;&lt;li&gt;Workarounds are documented in the advisory.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2025-20286.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;The credentials that exist in Cisco ISE that is deployed in the cloud are specific to each release and platform. For example:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco IOS XE Wireless Controller Software Arbitrary File Upload Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-ios-xe-wireless-controller-software-arbitrary-file-upload-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:19:49 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-ios-xe-wireless-controller-software-arbitrary-file-upload-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#b91c1c;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: CRITICAL — CVSS 10.0&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system. This vulnerability is due to the presence of a hard-coded JSON Web Token (JWT) on…&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;No fixed release listed&lt;/strong&gt; yet; apply mitigations and monitor.&lt;/li&gt;&#xA;&lt;li&gt;Workarounds are documented in the advisory.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2025-20188.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Multiple Cisco Products Unauthenticated Remote Code Execution in Erlang/OTP SSH Server: April 2025</title>
      <link>https://www.phllaps.net/posts/multiple-cisco-products-unauthenticated-remote-code-execution-in-erlang-otp-ssh-server-april-2025/</link>
      <pubDate>Sat, 09 Aug 2025 15:18:37 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/multiple-cisco-products-unauthenticated-remote-code-execution-in-erlang-otp-ssh-server-april-2025/</guid>
      <description>&lt;div style=&#34;background:#b91c1c;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: CRITICAL — CVSS 10.0&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;On April 16, 2025, a critical vulnerability in the Erlang/OTP SSH server was disclosed. This vulnerability could allow an unauthenticated, remote attacker to perform remote code execution (RCE) on an affected device. The vulnerability is due to a flaw in the handling of SSH messages during the authentication phase. For a description of this vulnerability, see the Erlang announcement [&amp;ldquo;https://github.com/erlang/otp/security/advisories/GHSA-37cp-fgq5-7wc2&amp;rdquo;].&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;No fixed release listed&lt;/strong&gt; yet; apply mitigations and monitor.&lt;/li&gt;&#xA;&lt;li&gt;Workarounds are documented in the advisory.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2025-32433.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;On April 16, 2025, a critical vulnerability in the Erlang/OTP SSH server was disclosed. This vulnerability could allow an unauthenticated, remote attacker to perform remote code execution (RCE) on an affected device.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Meraki MX and Z Series AnyConnect VPN with Client Certificate Authentication Denial of Service Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-meraki-mx-and-z-series-anyconnect-vpn-with-client-certificate-authentication-denial-of-service-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:17:23 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-meraki-mx-and-z-series-anyconnect-vpn-with-client-certificate-authentication-denial-of-service-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 8.6&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition in the Cisco AnyConnect service on an affected device. This vulnerability is due to variable initialization errors when an SSL VPN session is established. An attacker…&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;No fixed release listed&lt;/strong&gt; yet; apply mitigations and monitor.&lt;/li&gt;&#xA;&lt;li&gt;Workarounds are documented in the advisory.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2025-20271.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition in the Cisco AnyConnect service on an affected device.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ClamAV UDF File Parsing Out-of-Bounds Read Information Disclosure Vulnerability</title>
      <link>https://www.phllaps.net/posts/clamav-udf-file-parsing-out-of-bounds-read-information-disclosure-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:15:52 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/clamav-udf-file-parsing-out-of-bounds-read-information-disclosure-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 5.3&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;A vulnerability in Universal Disk Format (UDF) processing of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a memory overread during UDF file scanning. An attacker could exploit this vulnerability by submitting a crafted file containing UDF content to be scanned by ClamAV on…&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;No fixed release listed&lt;/strong&gt; yet; apply mitigations and monitor.&lt;/li&gt;&#xA;&lt;li&gt;Workarounds are documented in the advisory.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2025-20234.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;Impacts of ClamAV DoS Vulnerability on Affected Platforms&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Identity Services Engine Authorization Bypass Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-identity-services-engine-authorization-bypass-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:13:54 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-identity-services-engine-authorization-bypass-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.4&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific administrative functions. This vulnerability is due to insufficient authorization enforcement mechanisms for users created by SAML SSO integration with an external identity provider. An attacker could exploit this vulnerability by submitting a series of…&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;No fixed release listed&lt;/strong&gt; yet; apply mitigations and monitor.&lt;/li&gt;&#xA;&lt;li&gt;Workarounds are documented in the advisory.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2025-20264.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to bypass the authorization mechanisms for specific administrative functions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Identity Services Stored Cross-Site Scripting Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-identity-services-stored-cross-site-scripting-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:12:50 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-identity-services-stored-cross-site-scripting-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 4.8&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code…&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;No fixed release listed&lt;/strong&gt; yet; apply mitigations and monitor.&lt;/li&gt;&#xA;&lt;li&gt;Workarounds are documented in the advisory.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2025-20267.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Unified Communications Manager Static SSH Credentials Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-unified-communications-manager-static-ssh-credentials-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:11:40 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-unified-communications-manager-static-ssh-credentials-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#b91c1c;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: CRITICAL — CVSS 10.0&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to log in to an affected device using the root account, which has default, static credentials that cannot be changed or deleted. This vulnerability is due to the presence of static user credentials for…&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;No fixed release listed&lt;/strong&gt; yet; apply mitigations and monitor.&lt;/li&gt;&#xA;&lt;li&gt;Workarounds are documented in the advisory.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2025-20309.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to log in to an affected device using the root account, which has default, static credentials that cannot be changed or deleted.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Enterprise Chat and Email Stored Cross-Site Scripting Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-enterprise-chat-and-email-stored-cross-site-scripting-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:10:01 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-enterprise-chat-and-email-stored-cross-site-scripting-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.1&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;A vulnerability in the web UI of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web UI does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to…&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;No fixed release listed&lt;/strong&gt; yet; apply mitigations and monitor.&lt;/li&gt;&#xA;&lt;li&gt;Workarounds are documented in the advisory.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2025-20310.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the web UI of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Spaces Connector Privilege Escalation Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-spaces-connector-privilege-escalation-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:09:01 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-spaces-connector-privilege-escalation-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.0&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;A vulnerability in Cisco Spaces Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root. This vulnerability is due to insufficient restrictions during the execution of specific CLI commands. An attacker could exploit this vulnerability by logging in to the Cisco Spaces Connector CLI as the spacesadmin user and…&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;No fixed release listed&lt;/strong&gt; yet; apply mitigations and monitor.&lt;/li&gt;&#xA;&lt;li&gt;Workarounds are documented in the advisory.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2025-20308.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in Cisco Spaces Connector could allow an authenticated, local attacker to elevate privileges and execute arbitrary commands on the underlying operating system as root.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco BroadWorks Application Delivery Platform Cross-Site Scripting Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-broadworks-application-delivery-platform-cross-site-scripting-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:07:39 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-broadworks-application-delivery-platform-cross-site-scripting-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 4.8&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code…&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;No fixed release listed&lt;/strong&gt; yet; apply mitigations and monitor.&lt;/li&gt;&#xA;&lt;li&gt;Workarounds are documented in the advisory.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2025-20307.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the web-based management interface of Cisco BroadWorks Application Delivery Platform could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Unified Intelligence Center Server-Side Request Forgery Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-unified-intelligence-center-server-side-request-forgery-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:06:31 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-unified-intelligence-center-server-side-request-forgery-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 5.8&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful…&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;No fixed release listed&lt;/strong&gt; yet; apply mitigations and monitor.&lt;/li&gt;&#xA;&lt;li&gt;Workarounds are documented in the advisory.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2025-20288.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Identity Services Engine Authenticated Remote Code Execution and Authorization Bypass Vulnerabilities</title>
      <link>https://www.phllaps.net/posts/cisco-identity-services-engine-authenticated-remote-code-execution-and-authorization-bypass-vulnerabilities/</link>
      <pubDate>Sat, 09 Aug 2025 15:05:25 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-identity-services-engine-authenticated-remote-code-execution-and-authorization-bypass-vulnerabilities/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.5&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to issue commands on the underlying operating system as the root user and allow IP access filters to be bypassed. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. For more…&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;No fixed release listed&lt;/strong&gt; yet; apply mitigations and monitor.&lt;/li&gt;&#xA;&lt;li&gt;Workarounds are documented in the advisory.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2025-20284, CVE-2025-20283, CVE-2025-20285.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;The vulnerabilities are not dependent on one another. Exploitation of one of the vulnerabilities is not required to exploit another vulnerability. In addition, a software release that is affected by one of the vulnerabilities may not be affected by the other vulnerabilities.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Prime Infrastructure and Evolved Programmable Network Manager Blind SQL Injection Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-prime-infrastructure-and-evolved-programmable-network-manager-blind-sql-injection-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:04:08 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-prime-infrastructure-and-evolved-programmable-network-manager-blind-sql-injection-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 4.3&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, low-privileged, remote attacker to conduct a blind SQL injection attack. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to an affected API. A successful…&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;No fixed release listed&lt;/strong&gt; yet; apply mitigations and monitor.&lt;/li&gt;&#xA;&lt;li&gt;Workarounds are documented in the advisory.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2025-20272.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;A vulnerability in a subset of REST APIs of Cisco Prime Infrastructure and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, low-privileged, remote attacker to conduct a blind SQL injection attack.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Unified Intelligence Center Arbitrary File Upload Vulnerability</title>
      <link>https://www.phllaps.net/posts/cisco-unified-intelligence-center-arbitrary-file-upload-vulnerability/</link>
      <pubDate>Sat, 09 Aug 2025 15:03:12 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-unified-intelligence-center-arbitrary-file-upload-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#d97706;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: MEDIUM — CVSS 6.3&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;p&gt;Cisco Unified Intelligence Center (CUIC) contains an authenticated arbitrary file upload vulnerability (CVE-2025-20274). An attacker with valid Report Designer (or higher) credentials could upload files, potentially execute commands and escalate to root. Fixed software is available; there are no workarounds.&lt;/p&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;Improper validation of files uploaded via the CUIC web management interface allows an authenticated remote attacker to upload arbitrary files. A successful exploit can store malicious files and execute arbitrary OS commands; Cisco raised the Security Impact Rating because an attacker could elevate privileges to root. Exploitation requires valid credentials with at least the Report Designer role. Cisco PSIRT is not aware of any public announcements or active malicious use.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco Identity Services Engine Unauthenticated Remote Code Execution Vulnerabilities</title>
      <link>https://www.phllaps.net/posts/cisco-identity-services-engine-unauthenticated-remote-code-execution-vulnerabilities/</link>
      <pubDate>Sat, 09 Aug 2025 15:02:48 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/cisco-identity-services-engine-unauthenticated-remote-code-execution-vulnerabilities/</guid>
      <description>&lt;div style=&#34;background:#b91c1c;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: CRITICAL — CVSS 10.0&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an unauthenticated, remote attacker to issue commands on the underlying operating system as the root user. For more information about these vulnerabilities, see the Details [&amp;quot;#details&amp;quot;] section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds…&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;No fixed release listed&lt;/strong&gt; yet; apply mitigations and monitor.&lt;/li&gt;&#xA;&lt;li&gt;Workarounds are documented in the advisory.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2025-20282, CVE-2025-20281, CVE-2025-20337.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;The vulnerabilities are not dependent on one another. Exploitation of one of the vulnerabilities is not required to exploit another vulnerability. In addition, a software release that is affected by one of the vulnerabilities may not be affected by the other vulnerabilities.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SNMP Remote Code Execution Vulnerabilities in Cisco IOS and IOS XE Software</title>
      <link>https://www.phllaps.net/posts/snmp-remote-code-execution-vulnerabilities-in-cisco-ios-and-ios-xe-software/</link>
      <pubDate>Sat, 09 Aug 2025 15:01:19 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/snmp-remote-code-execution-vulnerabilities-in-cisco-ios-and-ios-xe-software/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&#xA;  &lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&#xA;  &lt;span&gt;SEVERITY: HIGH — CVSS 8.8&lt;/span&gt;&#xA;  &lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&#xA;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE Software contains multiple vulnerabilities that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Only…&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;No fixed release listed&lt;/strong&gt; yet; apply mitigations and monitor.&lt;/li&gt;&#xA;&lt;li&gt;Workarounds are documented in the advisory.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2017-6742, CVE-2017-6741, CVE-2017-6739.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-happened-&#34;&gt;What happened 🕵️‍♂️&lt;/h2&gt;&#xA;&lt;p&gt;The Simple Network Management Protocol (SNMP) is an application-layer protocol that provides a standardized framework and a common language for monitoring and managing devices in a network. It defines a message format for communication between SNMP managers and agents.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Privacy Policy</title>
      <link>https://www.phllaps.net/privacy/</link>
      <pubDate>Sat, 09 Aug 2025 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/privacy/</guid>
      <description>&lt;h2 id=&#34;privacy-policy&#34;&gt;Privacy Policy&lt;/h2&gt;&#xA;&lt;p&gt;PhllapsNET operates the website&#xA;&lt;a href=&#34;https://www.phllaps.net&#34;&gt;https://www.phllaps.net&lt;/a&gt;. This page explains what&#xA;information is collected when you visit, and what happens to it.&lt;/p&gt;&#xA;&lt;p&gt;Last updated: 22 August 2026.&lt;/p&gt;&#xA;&lt;h3 id=&#34;what-we-collect-directly&#34;&gt;What we collect directly&lt;/h3&gt;&#xA;&lt;p&gt;&lt;strong&gt;Nothing.&lt;/strong&gt; This site has no account system, no comment form, no newsletter&#xA;sign-up and no contact form. We do not ask you for your name, your email address&#xA;or anything else, and we do not run our own analytics or tracking.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
