Cisco IOS and IOS XE devices configured for TACACS+ without a shared secret on every server can let a network-positioned attacker read authentication traffic or impersonate the TACACS+ server to bypass login.
Every CISA KEV addition, plus critical-severity flaws in the kit that sits at the edge of a network: firewalls, VPN gateways, load balancers, routers, switches and management consoles.
Colour on the left of each entry is the CVSS severity. A pink CISA KEV badge means the flaw is being exploited right now — treat those first, whatever the score says. How each post is sourced and checked is set out in the methodology.
Cisco IOS XE Software HTTP API Command Injection Vulnerability
A flaw in the HTTP API of Cisco IOS XE lets an authenticated admin, or an admin tricked into clicking a crafted link, trigger root-level command execution on the device.
Cisco IOS XE Software CLI Argument Injection Vulnerability
An admin already logged into an IOS XE device’s CLI can pass crafted arguments to certain commands and escalate from level-15 access to root on the underlying OS.
Cisco IOS XE Software Network-Based Application Recognition Denial of Service Vulnerability
An unauthenticated attacker can crash affected Cisco IOS XE routers and edge platforms by sending malformed CAPWAP packets, but only where NBAR’s CAPWAP inspection feature is turned on.
Cisco IOS XE Software Secure Boot Bypass Vulnerabilities
Two IOS XE flaws let a privilege-15 admin or someone with physical device access plant a crafted file that boots as trusted code, permanently breaking secure boot’s chain of trust.
Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability
A stack overflow in Cisco IOS and IOS XE’s SNMP subsystem lets an authenticated attacker with admin credentials trigger a device reload or, on IOS XE, execute code as root via a crafted SNMP packet.
Cisco IOS XE Software Simple Network Management Protocol Denial of Service Vulnerability
An authenticated attacker with valid SNMP credentials can crash a Cisco IOS XE switch that has WRED for MPLS EXP configured, forcing an unexpected reload.
Cisco IOS XE Software Web UI Reflected Cross-Site Scripting Vulnerability
A reflected XSS bug in Cisco IOS XE’s Web Authentication feature lets an attacker who tricks a user into clicking a crafted link steal that user’s session cookies from the device’s web interface.
Cisco IOS XE Software for Catalyst 9800 Series Wireless Controller for Cloud Unauthenticated Access to Certificate Enrollment Service Vulnerability
Leftover PKI server access on Catalyst 9800-CL virtual controllers lets an unauthenticated attacker request a certificate and join a rogue device to the wireless LAN controller.
Cisco IOS XE SD-WAN Software Packet Filtering Bypass Vulnerability
A crafted packet can slip past Layer 3/4 filters on Cisco IOS XE SD-WAN cEdge routers running Controller mode with SNMP enabled on an SD-WAN tunnel interface, letting an unauthenticated attacker inject traffic past those controls.