These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-20313 is related to Improper link resolution before file access issues in Cisco SD-WAN, classified under CWE-1284 with a CVSS score of 7.7. This vulnerability could potentially allow attackers to access sensitive files or directories. Cisco has addressed this issue through software hardening releases. The CVE record was published on 2026-08-05T17:16:52.437Z and has not been modified since then. C [truncated]
CVE-2026-20304 is a critical vulnerability in Cisco Catalyst SD-WAN due to improper access control, tracked under CWE-284 with a CVSS score of 9.9. The vulnerability was discovered during an internal security review by Cisco, leading to a software hardening release. This vulnerability affects Cisco SD-WAN deployments, potentially allowing attackers to exploit the system. Cisco SD-WAN customers and adminis [truncated]
CVE-2026-20303 is a critical vulnerability in Cisco SD-WAN due to improper input validation, classified under CWE-20. It has a CVSS score of 9.9. Cisco conducted an internal security review, leading to software hardening releases. Affected Cisco SD-WAN customers and administrators should be aware of this critical vulnerability and take immediate action to patch their systems. The vulnerability's critical [truncated]
A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of malformed XMCP packets. An attacker could exploit this vulnerability by send [truncated]
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficient access control enforcement for specific template types that are not included in the encryption allowlist. A low-privileged attacker could exploit this vulnerability b [truncated]
The CVE-2026-20289 vulnerability affects Cisco RoomOS, specifically its logging subsystem, which could allow an authenticated, local attacker with low privileges to access sensitive information. This type of vulnerability typically arises from the logging of sensitive information. Exploitation could occur by enabling a specific logging level and collecting system logs, potentially allowing an attacker to [truncated]
The CVE-2026-20288 vulnerability exists in the web-based management interface of Cisco IMC due to improper validation of user-supplied input. An authenticated, remote attacker with Admin privileges could exploit this vulnerability to execute arbitrary commands on the underlying operating system as the root user. This could allow the attacker to elevate privileges to root. The vulnerability has a CVSS scor [truncated]
The CVE-2026-20273 vulnerability is related to improper input validation issues in Cisco IOS XE Software, classified under CWE-20. Cisco conducted an internal security review, leading to a software hardening release addressing multiple vulnerabilities. Affected product context requires defensive impact assessment and source-grounded technical framing without unsupported root-cause or exploit claims. Cisco [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T17:16:49.053Z and has not been modified since then. The vulnerability tracked by CVE-2026-20272 is related to issues with improper neutralization of special elements that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-74. Cisco IOS XE Software users and administrators should b [truncated]
CVE-2026-20271 is related to insufficient control flow management issues in Cisco IOS XE Software, grouped under CWE-691. Cisco conducted an internal security review leading to software hardening releases addressing this vulnerability. Affected product deployments should be reviewed for potential exposure. Cisco IOS XE Software users and administrators should be aware of this vulnerability and take steps [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T17:16:48.340Z and has not been modified since then. CVE-2026-20270 addresses incorrect calculation issues in Cisco IOS XE Software, categorized under CWE-682. The vulnerability has a CVSS score of 8.6 and HIGH severity. Cisco's internal security review led to software hardening releases to addres [truncated]
CVE-2026-20269 is related to issues with improper control of a resource through its lifetime in Cisco IOS XE Software, grouped under CWE-664. Cisco conducted an internal security review leading to software hardening releases addressing multiple internally discovered vulnerabilities. The vulnerability affects Cisco IOS XE Software users, who should prioritize patching to address potential improper control [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T17:16:47.830Z and has not been modified since then. The vulnerability tracked by CVE-2026-20268 relates to improper restriction of operations within the bounds of a memory buffer, classified under CWE-119. This vulnerability was discovered during an internal security review by Cisco, leading to s [truncated]
CVE-2026-20267 is a critical vulnerability in Cisco IOS XE Software caused by improper access control, leading to potential unauthorized access and malicious activity. It has a CVSS score of 9 and is categorized under CWE-284. The vulnerability was discovered during a comprehensive internal security review by Cisco's IOS XE Software engineering team. Users are advised to apply patches or updates provided [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T17:16:47.310Z and has not been modified since then. CVE-2026-20263 is a vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software. It allows an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device due to imprope [truncated]
A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web- [truncated]
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted li [truncated]
A vulnerability exists in the network driver of Cisco Terminal Service (TS) Agent, which could allow an authenticated, remote attacker to bypass firewall rules associated with their account. This is due to an incorrect mapping of network connections to user accounts. The attacker must have at least user-level credentials and can exploit this vulnerability by sending crafted network traffic to an affected [truncated]
Cisco Secure Firewall Management Center (FMC) instances have a use of hard-coded password vulnerability. This vulnerability affects the management center's functionality and could allow an attacker to gain unauthorized access. The vulnerability was published on 2026-07-29T00:00:00.000Z and has not been modified since then. Organizations using Cisco Secure Firewall Management Center (FMC) should prioritize [truncated]
A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of user [truncated]
CVE-2008-4128 is a Cross-Site Request Forgery Vulnerability in Cisco IOS. The vulnerability has a CVSS score of 4.3 and a severity rating of MEDIUM. This vulnerability affects Cisco IOS systems, which are widely used in various networks. The vulnerability allows an attacker to perform unauthorized actions on behalf of a legitimate user. Security teams and administrators responsible for Cisco IOS systems s [truncated]
An OS command injection vulnerability exists in the start_lltd() function of the 'rc' binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The machine_name configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges. This vulnerability has a high impact on the [truncated]
An OS command injection vulnerability exists in the sub_34984() function of the 'rc' binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The lan_ipv6_prefixlen configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges. This vulnerability has a high impact on [truncated]
An OS command injection vulnerability exists in the save_syslog_to_file() function of the 'httpd' binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The model_name configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges. This vulnerability has a high impa [truncated]
An OS command injection vulnerability exists in the start_bonjour() function of the 'rc' binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The wan_hostname configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges. The affected products are Cisco RV130, RV [truncated]
A vulnerability in the DMG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in DMG files during scanning, which may result in an integer overflow on 32-bit platforms only. The vulnerability affect [truncated]
CVE-2026-20243 is a high-severity vulnerability in the ALZ file format parser of ClamAV, which could allow an unauthenticated, remote attacker to cause a DoS condition or potentially other expanded impacts due to memory corruption on an affected device. This vulnerability is caused by improper boundary checks for content in ALZ files during scanning, potentially leading to an out-of-bounds buffer write. A [truncated]
CVE-2026-20217 is a vulnerability in ClamAV's PESpin file format parser. This vulnerability could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts due to memory corruption on an affected device. The vulnerability is caused by improper boundary checks for content in PESpin files during scanning, which may result in an out-of-bounds buffer write. An attac [truncated]
CVE-2026-20216 is a vulnerability in the InstallShield file format parser of ClamAV, which could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper handling of temporary resources during file scanning. The vulnerability affects ClamAV and Cisco Secure Endpoint. Users of these products should be aware of this vulnerability and tak [truncated]
A vulnerability in the 7z file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or other impacts due to memory corruption. This is caused by improper boundary checks for 7z file content during scanning, potentially leading to an out-of-bounds buffer write. Cisco Secure Endpoint and ClamAV users should review and apply patches or updates provided by Cisco.
A vulnerability in the FSG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in FSG files during scanning, which may result in an out-of-bounds buffer write. The vulnerability affects ClamAV and Ci [truncated]
A vulnerability in the PE file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PE files during scanning, which may result in an out-of-bounds buffer write. The vulnerability affects ClamAV, which i [truncated]
A vulnerability in the browser-based version of Cisco Webex App could have allowed an unauthenticated, remote attacker to redirect users to a malicious webpage. Cisco has addressed this vulnerability in the Cisco Webex App, and no customer action is needed. This vulnerability existed due to improper input validation of URL parameters in an HTTP request. Prior to this vulnerability being addressed, an atta [truncated]
CVE-2026-20246 is a medium-severity vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance. An authenticated, local attacker could exploit insufficient validation of user-supplied commands to elevate privileges to root. This vulnerability exists due to inadequate command validation in the vmadmin CLI, allowing an attacker with vmadmin privileges to use certain commands and potentially gain e [truncated]
CVE-2026-20220 is a medium-severity vulnerability in the web-based management interface of Cisco Crosswork Network Controller. The vulnerability allows an authenticated, remote attacker to execute arbitrary commands on an affected device due to insufficient input validation in the configuration template engine. This could allow an attacker to execute arbitrary commands on the underlying operating system i [truncated]
A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain access to sensitive informati [truncated]
CVE-2026-20262 is a vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage. The vulnerability allows an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This is possible due to improper validation of user-supplied input during a file upload process. An attacker could exploit this vulnerability by sending a crafted [truncated]
CVE-2026-20223 is a critical authentication and access-validation flaw affecting Cisco Secure Workload’s internal REST APIs. According to the CVE record, an unauthenticated remote attacker who can reach a vulnerable endpoint may be able to access site resources as a Site Admin, including sensitive data exposure and configuration changes across tenant boundaries.
CVE-2026-20206 is a command-injection vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent. Cisco states that an authenticated, remote attacker with valid ThousandEyes SaaS credentials and permission to manage transaction tests could submit crafted input and potentially execute arbitrary commands inside the BrowserBot container as the node user. Cisco has already addressed the [truncated]
CVE-2026-20199 is a vulnerability in SSL certificate handling for Cisco ThousandEyes Virtual Appliance. The provided source states that insufficient validation of user-supplied input may allow an authenticated remote attacker with valid administrative credentials to upload a crafted certificate and execute arbitrary code on the underlying operating system as root. NVD lists the record as Awaiting Analysis [truncated]
CVE-2026-20171 is a Cisco-reported BGP denial-of-service issue affecting Nexus 3000 Series and Nexus 9000 Series Switches in standalone NX-OS mode. A remote attacker who can get a crafted BGP update delivered through an established peer session may cause incorrect parsing of a transitive BGP attribute, leading the device to drop the BGP session and flap with the forwarding peer. The practical impact is di [truncated]
CVE-2026-20210 is a medium-severity vulnerability in Cisco Catalyst SD-WAN Manager that allows authenticated, remote attackers with read-only permissions to modify configurations and perform unauthorized actions. This vulnerability exists due to a failure to redact sensitive information within device configurations and templates. An attacker could exploit this vulnerability by elevating their read-only pe [truncated]
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to elevate their privileges from low to high and perform actions as a high-privileged user. This vulnerability exists because sensitive session information is recorded in audit logs. An attacker could exploit this vulnerability by elevating their [truncated]
CVE-2026-20182 is a Cisco Catalyst SD-WAN Controller authentication bypass vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2026-05-14. Because it is on the KEV list, defenders should treat it as a priority exposure and follow CISA’s ED-26-03 and Cisco SD-WAN hunt-and-hardening guidance without delay. CISA’s metadata also notes that, where mitigations are not available, orga [truncated]
A vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an authenticated, remote attacker with read-only Administrator privileges to gain unauthorized access to sensitive information on an affected device. This vulnerability is due to improper role-based access control (RBAC) permissions on the RADIUS Policy API endpoints. An attacker could exploit this vulnerability by bypassing the w [truncated]
A vulnerability in the log file download functionality of Cisco Prime Infrastructure could allow an authenticated, remote attacker to download arbitrary log files from the server. This vulnerability is due to insufficient authorization checks on the download service API. An attacker could exploit this vulnerability by submitting a crafted URL request to an affected device. A successful exploit could allow [truncated]
CVE-2026-20169 is a vulnerability in the web-based management interface of Cisco IoT Field Network Director. An authenticated, remote attacker with low privileges could access files and execute commands on a remote router. This vulnerability is due to insufficient input validation of user-supplied data. An attacker could exploit this vulnerability by submitting crafted input in the web-based management in [truncated]
CVE-2026-20167 is a high-severity vulnerability in the web-based management interface of Cisco IoT Field Network Director. An authenticated, remote attacker with low privileges can exploit improper error handling to cause a DoS condition on a remotely managed router. The vulnerability is due to improper error handling, allowing an attacker to submit crafted input and request unauthorized files from a remo [truncated]
A vulnerability in the web UI of Cisco Unity Connection Web Inbox could allow an unauthenticated, remote attacker to conduct SSRF attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to send arb [truncated]
CVE-2026-20133 is a Cisco Catalyst SD-WAN Manager vulnerability that CISA has added to its Known Exploited Vulnerabilities catalog. The supplied source material indicates the issue involves exposure of sensitive information to an unauthorized actor and directs defenders to Cisco and CISA mitigation guidance. Because CISA assigned a near-term remediation deadline, this should be treated as an urgent exposu [truncated]