Three maximum-severity flaws let anyone reach Cisco ISE’s APIs without logging in and run commands as root, with one variant also allowing arbitrary file uploads into privileged directories.
Every CISA KEV addition, plus critical-severity flaws in the kit that sits at the edge of a network: firewalls, VPN gateways, load balancers, routers, switches and management consoles.
Colour on the left of each entry is the CVSS severity. A pink CISA KEV badge means the flaw is being exploited right now — treat those first, whatever the score says. How each post is sourced and checked is set out in the methodology.
SNMP Remote Code Execution Vulnerabilities in Cisco IOS and IOS XE Software
Flaws in the SNMP subsystem of Cisco IOS and IOS XE let anyone with a read-only community string or valid SNMPv3 credentials send a crafted packet to execute code or reload the device.