A local, authenticated user on Windows machines running the Cisco ThousandEyes Endpoint Agent can trick the upgrade process into deleting files it shouldn’t touch, using a symbolic link trick.
Every CISA KEV addition, plus critical-severity flaws in the kit that sits at the edge of a network: firewalls, VPN gateways, load balancers, routers, switches and management consoles.
Colour on the left of each entry is the CVSS severity. A pink CISA KEV badge means the flaw is being exploited right now — treat those first, whatever the score says. How each post is sourced and checked is set out in the methodology.
Cisco Unified Contact Center Express Editor Remote Code Execution Vulnerability
Opening a booby-trapped .aef script file in Cisco’s Unified CCX Editor can let an attacker run their own code on the machine, using whatever access the person who opened the file already has.
Cisco Unified Contact Center Express Vulnerabilities
Three separate flaws in the Cisco Unified CCX admin web interface let an already-authenticated administrator plant a stored XSS payload, deserialise a malicious Java object for code execution, or use path traversal plus SSH to run commands as root.
Cisco Integrated Management Controller Privilege Escalation Vulnerability
An authenticated attacker with SSH access to Cisco IMC on UCS B, C, S and X-Series servers can use crafted SSH syntax to reach internal services with elevated rights, up to creating new admin accounts.
Cisco Customer Collaboration Platform Information Disclosure Vulnerability
Cisco’s Customer Collaboration Platform chat interface fails to sanitise HTTP requests, letting an unauthenticated remote attacker craft requests that could redirect a user’s chat session to an attacker-controlled server.
Cisco Identity Services Engine on Cloud Platforms Static Credential Vulnerability
Cloud deployments of Cisco ISE on AWS, Azure and OCI ship with the same static credentials across every instance of a given release and platform, letting anyone who knows them reach the admin node without authenticating.
Cisco IOS XE Wireless Controller Software Arbitrary File Upload Vulnerability
Cisco Catalyst 9800 wireless controllers ship with a hard-coded authentication token in the AP file upload service, letting anyone reach the interface remotely without credentials and push files onto the controller.
Multiple Cisco Products Unauthenticated Remote Code Execution in Erlang/OTP SSH Server: April 2025
A flaw in how Erlang/OTP’s SSH server handles authentication messages lets an unauthenticated remote attacker run code on affected Cisco products, with fixes staggered across trains through late 2025.
Cisco Meraki MX and Z Series AnyConnect VPN with Client Certificate Authentication Denial of Service Vulnerability
Unauthenticated attackers can crash the AnyConnect SSL VPN service on Meraki MX and Z Series gateways that use client certificate authentication, dropping every active remote-access session and blocking new ones.
ClamAV UDF File Parsing Out-of-Bounds Read Information Disclosure Vulnerability
An out-of-bounds read while ClamAV parses UDF file content lets a remote, unauthenticated attacker crash the scanning engine on Cisco Secure Endpoint Connector for Linux, Mac and Windows.