Authenticated users of Cisco ISE’s web management interface could trigger reflected XSS or pull sensitive data due to weak input validation, with fixes only via patched releases and no interim workaround.
Every CISA KEV addition, plus critical-severity flaws in the kit that sits at the edge of a network: firewalls, VPN gateways, load balancers, routers, switches and management consoles.
Colour on the left of each entry is the CVSS severity. A pink CISA KEV badge means the flaw is being exploited right now — treat those first, whatever the score says. How each post is sourced and checked is set out in the methodology.
Cisco Identity Services Engine RADIUS Suppression Denial of Service Vulnerability
A vulnerability in the RADIUS setting Reject RADIUS requests from clients with repeated failures on Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause Cisco …
Multiple Cisco Contact Center Products Vulnerabilities
Authenticated users of Cisco’s Contact Centre platforms can exploit several bugs to read sensitive data, upload and run files, and escalate to root, with no workaround until patched.
Cisco BroadWorks CommPilot Application Software Cross-Site Scripting Vulnerability
A stored XSS bug in Cisco BroadWorks CommPilot lets an already-authenticated admin plant script that runs in another logged-in admin’s browser, with no workaround available beyond patching.
Cisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure Vulnerability
On Cisco TelePresence CE and RoomOS devices with SIP media logging switched on, audit logs store credentials unencrypted, letting an admin-level user harvest access they shouldn’t have.
Multiple Cisco Products Snort 3 MIME Denial of Service Vulnerabilities
Flaws in the Snort 3 MIME decoder let a remote attacker with no credentials crash the detection engine or pull sensitive data from traffic passing through Firepower and ISA appliances, with no workaround to fall back on.
Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Vulnerabilities
A buffer overflow in the web UI of several Cisco SIP desk and video phones lets a remote attacker crash the device with a single crafted HTTP request, provided Web Access is turned on.
Cisco Unified Communications Manager Stored Cross-Site Scripting Vulnerability
An authenticated admin on Cisco Unified Communications Manager’s web interface can plant script that runs in another admin’s browser session, with no workaround available other than upgrading.
Cisco Cyber Vision Center Stored Cross-Site Scripting Vulnerabilities
Two stored XSS flaws in Cisco Cyber Vision Center’s Sensor Explorer and Reports pages let an authenticated user plant scripts that run in other admins’ browsers, with no workaround and a fix-only path.
Cisco IOS XE Software Web Authentication Reflected Cross-Site Scripting Vulnerability
A reflected XSS bug in Cisco IOS XE’s web authentication portal lets an attacker steal a user’s session cookie if they click a crafted link, but only on devices running HTTP/HTTPS with Web Authentication enabled.