An unauthenticated attacker can slip past N-central’s login checks via an alternate access path, reading and altering data on a platform many MSPs use to manage customer endpoints.
Every CISA KEV addition, plus critical-severity flaws in the kit that sits at the edge of a network: firewalls, VPN gateways, load balancers, routers, switches and management consoles.
Colour on the left of each entry is the CVSS severity. A pink CISA KEV badge means the flaw is being exploited right now — treat those first, whatever the score says. How each post is sourced and checked is set out in the methodology.
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
A second, more thorough fix was needed after an earlier patch for N-central’s login flow failed to close an alternate authentication path, letting attackers seize administrator accounts outright.
Cisco Catalyst Center Virtual Appliance Privilege Escalation Vulnerability
An authenticated user with only Observer-level access to Cisco Catalyst Center’s virtual appliance can send a crafted HTTP request to gain full Administrator control.
Cisco Catalyst Center REST API Command Injection Vulnerability
An authenticated user with only low-level Observer access to Cisco Catalyst Center’s REST API can inject commands that run as root inside a restricted container, thanks to weak input validation.
Cisco Catalyst Center Cross-Site Scripting Vulnerability
Cisco Catalyst Center’s web management interface fails to properly validate user input, letting an unauthenticated attacker run script in an admin’s browser via a crafted link, with no workaround and no exploitation confirmed.
Cisco Catalyst Center Privilege Escalation Vulnerability
A broken access control check in Cisco Catalyst Center lets a logged-in read-only user change policy configurations that should be locked to Administrator accounts.
Cisco Catalyst Center Virtual Appliance HTTP Open Redirect Vulnerability
An unauthenticated flaw in the web management interface of Cisco Catalyst Center Virtual Appliance on ESXi lets attackers craft links that redirect users to malicious sites, with no workaround available.
Cisco Unified Contact Center Express Remote Code Execution Vulnerabilities
Two unauthenticated flaws in the Java RMI process of Cisco Unified CCX let a remote attacker upload files, bypass login, and run commands as root, with no workaround available.
Cisco Identity Services Engine Reflected Cross-Site Scripting and Information Disclosure Vulnerabilities
Authenticated users of Cisco ISE’s web management interface could trigger reflected XSS or pull sensitive data due to weak input validation, with fixes only via patched releases and no interim workaround.
Cisco Identity Services Engine RADIUS Suppression Denial of Service Vulnerability
A default-on RADIUS setting in Cisco ISE 3.4 lets an unauthenticated attacker send crafted access requests that crash and restart the appliance, knocking out network authentication.