IOS XR devices with the management interface up can be knocked offline by an ARP flood on that interface, since Cisco’s LPTS protections don’t rate-limit management-plane traffic and there’s no workaround short of upgrading.
Every CISA KEV addition, plus critical-severity flaws in the kit that sits at the edge of a network: firewalls, VPN gateways, load balancers, routers, switches and management consoles.
Colour on the left of each entry is the CVSS severity. A pink CISA KEV badge means the flaw is being exploited right now — treat those first, whatever the score says. How each post is sourced and checked is set out in the methodology.
Cisco IOS XR Software Image Verification Bypass Vulnerability
A flaw in how Cisco IOS XR checks .iso install files lets someone who already has root-system access load unsigned software, quietly defeating the image signature check.
Cisco IOS XR Software Management Interface ACL Bypass Vulnerability
On several IOS XR platforms, ACLs applied to the management interface silently fail to restrict SSH, NETCONF or gRPC, so anyone who can reach that interface can reach those services regardless of the filter you configured.
Cisco Evolved Programmable Network Manager Arbitrary File Upload Vulnerability
An authenticated attacker holding Config Managers credentials on Cisco EPNM can push arbitrary files onto the system via a flawed API endpoint, with no workaround available short of upgrading to 8.1.
Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Information Disclosure Vulnerability
A flaw in the web management API of Cisco EPNM and Prime Infrastructure lets any logged-in, low-privileged user pull configuration data they shouldn’t be able to see.
Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Stored Cross-Site Scripting Vulnerability
A stored XSS bug in Cisco EPNM and Prime Infrastructure lets an already-authenticated admin plant script in management interface data fields that later runs in another admin’s browser session.
Cisco Unified Communications Manager IM & Presence Service Cross-Site Scripting Vulnerability
A stored input-validation flaw in Cisco Unified CM IM&P’s admin web interface lets an attacker run script in a user’s browser session if that user clicks a crafted link.
Cisco Webex Meetings URL Redirection Vulnerability
Cisco Webex Meetings failed to properly validate URLs in meeting-join links, letting an unauthenticated attacker craft links that send users to an untrusted site instead of the genuine Webex page.
Cisco Webex Meetings Cross-Site Scripting Vulnerability
An authenticated user tricked into clicking a crafted link could trigger script execution in another Webex Meetings user’s session, but Cisco has already fixed this server-side with nothing for customers to patch.
Cisco Unified Communications Manager Cross-Site Request Forgery Vulnerability
Cisco’s Unified Communications Manager admin web interface lacks proper CSRF protection, letting an attacker trick a logged-in administrator into unknowingly executing actions on the call-management system.