PatchSiren

Cisco CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Cisco CVE published 2026-09-16

CVE-2026-76451

CVE-2026-76451 debrief based on the supplied source corpus. The vulnerability affects Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), allowing an authenticated, remote attacker to conduct an SQL or HQL injection attack. This could enable the attacker to execute arbitrary SQL or HQL queries, potentially leading to unauthorized data access or modification, disruption [truncated]

MEDIUM Cisco CVE published 2026-09-16

CVE-2026-76450

CVE-2026-76450 debrief: Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain a SQL injection vulnerability. This allows authenticated remote attackers to execute arbitrary SQL or HQL queries, potentially leading to unauthorized data access or modification. Cisco provides advisory details on affected versions and mitigation strategies. Administrators should assess [truncated]

MEDIUM Cisco CVE published 2026-09-16

CVE-2026-76449

CVE-2026-76449 debrief: Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain a SQL injection vulnerability. This allows authenticated remote attackers to execute arbitrary SQL or HQL queries, potentially enabling unauthorized data access or modification. Cisco provides advisory details and recommends immediate assessment and patching to prevent potential data bre [truncated]

MEDIUM Cisco CVE published 2026-09-16

CVE-2026-76448

CVE-2026-76448 debrief: Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) SQL injection vulnerability allows authenticated remote attackers to execute arbitrary SQL or HQL queries. Cisco provides advisory details. The vulnerability is due to insufficient validation of user-supplied input to the affected APIs before it is used to build database queries. An attacker cou [truncated]

MEDIUM Cisco CVE published 2026-09-16

CVE-2026-76447

A vulnerability in the Online Certificate Status Protocol (OCSP) responder of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to cause an administrative reload of the OCSP responder certificate and key material. This vulnerability is due to missing authentication on a function of the OCSP responder. An attacker could exploit this vulnerability by sending a crafted request to an [truncated]

MEDIUM Cisco CVE published 2026-09-16

CVE-2026-76446

CVE-2026-76446 debrief based on the supplied source corpus. The vulnerability in Cisco ISE and Cisco ISE-PIC API allows an authenticated, remote attacker to read specific files on the underlying operating system due to improper restriction of XML external entity references. Defenders should assess exposure and implement compensating controls. The CVE record was published on 2026-09-16T21:17:20.597Z and ha [truncated]

MEDIUM Cisco CVE published 2026-09-16

CVE-2026-76444

A vulnerability in Cisco ISE and Cisco ISE-PIC allows unauthenticated, remote attackers to retrieve sensitive configuration information. This is due to missing authentication on the Policy Runtime Repository Table (PRRT) service. Exploitation requires sending a crafted request to an affected device. Network administrators and security teams should assess exposure and apply necessary mitigations as per Cis [truncated]

MEDIUM Cisco CVE published 2026-09-16

CVE-2026-76439

A vulnerability in the endpoint posture status reporting functionality of the guest portal web application of Cisco ISE could allow an unauthenticated, remote attacker to submit forged posture status events into the endpoint posture pipeline. This vulnerability is due to insufficient authentication on an internal interface that is exposed through the guest portal. An attacker could exploit this vulnerabil [truncated]

MEDIUM Cisco CVE published 2026-09-16

CVE-2026-76438

CVE-2026-76438 debrief: Cisco BroadWorks CommPilot Application Software has a vulnerability allowing low-privileged authenticated remote attackers to alter configurations due to missing authorization checks. This issue affects Cisco BroadWorks CommPilot Application Software, potentially impacting configuration integrity. Administrators and security teams should verify and apply patches to prevent configur [truncated]

MEDIUM Cisco CVE published 2026-09-16

CVE-2026-76434

CVE-2026-76434 is a medium-severity vulnerability in Cisco ISE and Cisco ISE-PIC that allows authenticated remote attackers to read arbitrary files due to insufficient input validation. This vulnerability can lead to sensitive information disclosure and potential data breaches. Cisco ISE and Cisco ISE-PIC administrators should assess exposure and apply patches to prevent potential data breaches. The CVE r [truncated]

MEDIUM Cisco CVE published 2026-09-16

CVE-2026-76433

CVE-2026-76433 debrief: Cisco ISE and Cisco ISE-PIC client provisioning download feature allows unauthenticated remote attackers to access protected files due to insufficient directory traversal validation. This vulnerability can lead to potential exposure of sensitive information and possible unauthorized access to protected files. Defenders should verify affected versions and deployments, and prioritize [truncated]

MEDIUM Cisco CVE published 2026-09-16

CVE-2026-76432

CVE-2026-76432 is a vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC that could allow an authenticated, remote attacker with administrative-level privileges to write arbitrary files on an affected device. The vulnerability exists because the affected software does not properly validate directory traversal character sequences in a user-supplied file path during the upload process.

MEDIUM Cisco CVE published 2026-09-16

CVE-2026-76431

CVE-2026-76431 debrief based on the supplied source corpus. The vulnerability in Cisco ISE and Cisco ISE-PIC allows an authenticated, remote attacker to delete arbitrary files and directories on an affected device due to improper validation of directory traversal character sequences. Cisco ISE and Cisco ISE-PIC administrators should assess exposure and apply patches or mitigations as needed. The CVE recor [truncated]

MEDIUM Cisco CVE published 2026-09-16

CVE-2026-76428

CVE-2026-76428 is a SQL injection vulnerability in the REST APIs of Cisco ISE and Cisco ISE-PIC. An authenticated, remote attacker could exploit this vulnerability to read information from the session database. The vulnerability is due to certain parameters being concatenated directly into SQL clauses without parameterization. Defenders should assess exposure and potential impact on sensitive data and sys [truncated]

MEDIUM Cisco CVE published 2026-09-16

CVE-2026-76427

A vulnerability in the offline profiler feed service of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files that are stored on an affected device. The vulnerability is due to the parsing of attacker-controlled feed metadata with an XML parser that does not disable external entity resolution. An attacker could exploit this vulnerability by uploading a crafted offline feed packag [truncated]

MEDIUM Cisco CVE published 2026-09-16

CVE-2026-76426

CVE-2026-76426 debrief based on the supplied source corpus. The vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection attacks against the monitoring database. This is due to insufficient validation of specific parameters that are then concatenated into an SQL statement. An attacker could exploit this vulnerability by sending a c [truncated]

HIGH Cisco CVE published 2026-09-16

CVE-2026-76425

A vulnerability in Cisco ISE APIs could allow an authenticated, remote attacker to conduct SQL injection attacks. Insufficient parameter validation enables attackers to inject SQL statements, potentially allowing them to read arbitrary database content and conduct server-side request forgery (SSRF) attacks. Exploitation requires valid administrative credentials.

HIGH Cisco CVE published 2026-09-16

CVE-2026-76424

CVE-2026-76424 is a high-severity vulnerability in the REST API of Cisco ISE, allowing authenticated remote attackers to upload or copy arbitrary files on affected devices due to insufficient validation in file operations. This could enable attackers to execute arbitrary commands as root. Cisco ISE administrators and security teams should review configurations, monitor for suspicious activity, and verify [truncated]

HIGH Cisco CVE published 2026-09-16

CVE-2026-76413

CVE-2026-76413 debrief: Cisco ASDM SSO token vulnerability allows unauthenticated login as administrator. This high-severity vulnerability in Cisco Adaptive Security Device Manager (ASDM) single sign-on (SSO) handler for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to log in as the Cisco ASDM administrator user. The vulnerability is due to improper management of the Cisco ASDM [truncated]

HIGH Cisco CVE published 2026-09-16

CVE-2026-76409

A Cisco Nexus Dashboard vulnerability (CVE-2026-76409) with a CVSS score of 8.8 was internally discovered and patched. The issue relates to improper pathname limitations, categorized under CWE-22. Defenders should assess exposure, prioritize verification, and consider compensating controls. This vulnerability was found during an internal security review by the Cisco Nexus Dashboard engineering team, highl [truncated]

HIGH Cisco CVE published 2026-09-16

CVE-2026-20360

A Cisco Nexus Dashboard vulnerability (CVE-2026-20360) with a CVSS score of 8.8 was internally discovered and patched. The issue relates to information exposure and insecure handling, classified under CWE-200. Defenders should assess exposure, prioritize verification, and consider compensating controls. This vulnerability was found during a comprehensive internal security review by the Cisco Nexus Dashboa [truncated]

HIGH Cisco CVE published 2026-09-16

CVE-2026-20352

A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain RADIUS requests. An attacker could exploit this vulnerability by sending a crafted RADIUS request directly to an affected device. A successful exploit could [truncated]

MEDIUM Cisco CVE published 2026-09-16

CVE-2026-20350

CVE-2026-20350 debrief based on the supplied source corpus. The CVE record was published on 2026-09-16T21:17:12.380Z and was last modified on 2026-09-18T15:17:07.710Z. The NVD entry is currently Awaiting Analysis. The vulnerability in Cisco ThousandEyes Virtual Appliance allows authenticated remote attackers to inject arbitrary operating system commands due to improper input validation. Defenders with adm [truncated]

HIGH Cisco CVE published 2026-09-16

CVE-2026-20344

A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, remote attacker to perform a SQL injection attack against an affected device. To exploit this vulnerability, the attacker must have a valid account on the device with the role of Security Approver, Access Admin, or Network Admin. This vulnerability is due to insufficient validation of user-supp [truncated]

HIGH Cisco CVE published 2026-09-16

CVE-2026-20343

A vulnerability in a critical API for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to download sensitive files and use unbounded disk space. This vulnerability exists because a critical API lacks authentication. An attacker could exploit this vulnerability by repeatedly invoking the API. A successful exploit could allow the attacker to download sensitive files that should be r [truncated]

HIGH Cisco CVE published 2026-09-16

CVE-2026-20342

CVE-2026-20342 debrief: Cisco Secure FMC Software is vulnerable to arbitrary file download due to unsanitized user input in its file download API, allowing authenticated remote attackers to access sensitive files. Defenders managing Cisco Secure FMC Software, especially those with Security Analyst roles, should assess exposure and verify mitigation to prevent potential data leakage and unauthorized access [truncated]

HIGH Cisco CVE published 2026-09-16

CVE-2026-20340

A vulnerability in Cisco Secure FMC Software could allow an authenticated, remote attacker to execute arbitrary commands at the root privilege level. This vulnerability is due to unsecured deserialization of web-management user-controlled data. An attacker could exploit this vulnerability by authenticating to the device and sending a crafted HTTP payload. A successful exploit could allow the attacker to s [truncated]

HIGH Cisco CVE published 2026-09-16

CVE-2026-20336

CVE-2026-20336 is a high-severity vulnerability in Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software, and Cisco Secure Firewall Management Center Software. The vulnerability is related to improper control of a resource through its lifetime, tracked under CWE-664. Defenders should assess exposure, prioritize remediation, and verify affected versions and scope.

HIGH Cisco CVE published 2026-09-16

CVE-2026-20335

A Cisco internal security review led to a software hardening release addressing multiple vulnerabilities, including CVE-2026-20335, related to incorrect calculation issues grouped under CWE-682. The vulnerability has a CVSS score of 8.1 and is considered HIGH severity. This vulnerability affects Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software, and Cisco Sec [truncated]

HIGH Cisco CVE published 2026-09-16

CVE-2026-20334

A Cisco internal security review led to a software hardening release addressing multiple vulnerabilities, including CVE-2026-20334, related to improper adherence to coding standards (CWE-710). The vulnerabilities were found in Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software, and Cisco Secure Firewall Management Center Software. Defenders should assess expos [truncated]