Vulnerabilities Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities The flaws could lead to remote code execution, authentication bypasses, and path traversal attacks. Ionut Arghire2 hours ago
Vulnerabilities Cisco Patches Firewall Zero-Day Exploited for DoS Attacks CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices. Eduard KovacsAugust 12, 2026
Vulnerabilities Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC Remote, unauthenticated attackers could exploit the bugs to cause a denial-of-service (DoS) condition. Ionut ArghireAugust 10, 2026
Vulnerabilities Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities Patches were rolled out for two dozen vulnerabilities, including one with public proof-of-concept (PoC) code. Ionut ArghireAugust 6, 2026
Vulnerabilities Cisco Secure FMC Zero-Day Exploited in the Wild The vulnerability tracked as CVE-2026-20316 can be exploited by a remote, unauthenticated attacker to log into affected devices. Eduard KovacsJuly 30, 2026
Artificial Intelligence Cisco Launches Low-Cost AI Models for Source Code Security The open-weight Antares models are designed to pinpoint known vulnerabilities in codebases faster and at a fraction of the cost of larger AI models. Kevin TownsendJuly 21, 2026
Vulnerabilities Cisco SD-WAN Zero-Day Exploited Months Before Patching CVE-2026-20245, the 7th Cisco SD-WAN vulnerability exploited in 2026, was used for months prior to its disclosure and patching. Eduard KovacsJune 25, 2026
Network Security Hackers Exploiting Cisco Unified CM Vulnerability Cisco noted that a PoC had been available for CVE-2026-20230 when it announced patches in early June. Eduard KovacsJune 24, 2026
Funding/M&A Cisco to Acquire WideField Security to Boost Splunk’s Agentic SOC WideField will accelerate Agentic SOC capabilities by expanding the lens on threat investigation to include identity, credentials, sessions, and blast radius. Eduard KovacsJune 19, 2026
Network Security Critical Command Execution Vulnerability Patched in Cisco ISE Insufficient validation of user input allows an attacker to gain access to the underlying OS and elevate their privileges to root. Ionut ArghireJune 18, 2026
Network Security Cisco Patches Another SD-WAN Zero-Day Exploited in Attacks Cisco recently became aware of the exploitation of CVE-2026-20262, a Catalyst SD-WAN Manager zero-day that allows arbitrary file write. Eduard KovacsJune 16, 2026
Vulnerabilities Cisco Warns of 7th SD-WAN Zero-Day Exploited in 2026 The vulnerability is tracked as CVE-2026-20245 and it can allow arbitrary command execution as root, but no patch yet. Eduard KovacsJune 5, 2026
Vulnerabilities Cisco Warns of Available PoC for Critical Unified CM Vulnerability The high-severity flaw can be exploited remotely, without authentication, in server-side request forgery (SSRF) attacks. Ionut ArghireJune 4, 2026
Vulnerabilities Cisco Patches Critical Vulnerability in Secure Workload Insufficient validation and authentication in the Secure Workload’s REST APIs provide remote attackers with Site Admin privileges. Ionut ArghireMay 21, 2026
Vulnerabilities Cisco Patches Another SD-WAN Zero-Day, the Sixth Exploited in 2026 The zero-day, tracked as CVE-2026-20182, has been exploited in targeted attacks by a sophisticated threat actor identified as UAT-8616. Eduard KovacsMay 15, 2026
Network Security Cisco Patches High-Severity Vulnerabilities in Enterprise Products Successful exploitation of the flaws could lead to code execution, server-side request forgery attacks, and denial-of-service conditions. Ionut ArghireMay 7, 2026
Artificial Intelligence Cisco Moves to Acquire Astrix Security to Tackle Non-Human Identity Risks The acquisition strengthens Cisco’s push into identity-centric security for AI and machine access. Mike LennonMay 4, 2026
Artificial Intelligence Cisco Releases Open Source Tool for AI Model Provenance The new kit aims to address risks related to poisoned models, regulatory issues, supply chain integrity, and incident response. Eduard KovacsMay 1, 2026
Malware & Threats US Federal Agency’s Cisco Firewall Infected With ‘Firestarter’ Backdoor The malware provides remote access and control of infected devices and maintains post-patching persistence. Ionut ArghireApril 24, 2026
Vulnerabilities Organizations Warned of Exploited Cisco, Kentico, Zimbra Vulnerabilities CISA expanded the KEV catalog with eight flaws, but five of them have been flagged as exploited before. Ionut ArghireApril 21, 2026