PatchSiren

Cisco CVE debriefs · Page 2

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Cisco CVE published 2026-09-16

CVE-2026-20334

A Cisco internal security review led to a software hardening release addressing multiple vulnerabilities, including CVE-2026-20334, related to improper adherence to coding standards (CWE-710). The vulnerabilities were found in Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software, and Cisco Secure Firewall Management Center Software. Defenders should assess expos [truncated]

HIGH Cisco CVE published 2026-09-16

CVE-2026-20333

A Cisco internal security review led to a software hardening release addressing multiple vulnerabilities, including CVE-2026-20333, related to incorrect comparison conditions (CWE-697). Defenders responsible for Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software, and Cisco Secure Firewall Management Center Software deployments should assess exposure and verify [truncated]

CRITICAL Cisco CVE published 2026-09-16

CVE-2026-20332

A Cisco internal security review led to a software hardening release addressing multiple vulnerabilities, including CVE-2026-20332, related to improper access control issues. The vulnerability has a CVSS score of 9.9 and is considered critical. Affected products include Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software, and Cisco Secure Firewall Management Ce [truncated]

HIGH Cisco CVE published 2026-09-16

CVE-2026-20323

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to impersonate the peer device and obtain access at the level of the manager role, which is equivalent to root. This vulnerability is due to improper management of the TLS certificate for the sftunnel management connection. An atta [truncated]

MEDIUM Cisco CVE published 2026-09-16

CVE-2026-20309

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading [truncated]

HIGH Cisco CVE published 2026-09-16

CVE-2026-20300

A vulnerability in Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected device. To exploit this vulnerability, the attacker must have at least low-privileged administrative credentials. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A [truncated]

HIGH Cisco CVE published 2026-09-16

CVE-2026-20295

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to exhaust the available memory of an affected device. This vulnerability is due to improper management of memory resources during sftunnel TLS connection setup. An attacker could exploit this vulnerability by sending crafted sftunne [truncated]

MEDIUM Cisco CVE published 2026-09-16

CVE-2026-20290

A vulnerability in SSL/TLS certificate parsing in the Snort 2 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 2 Detection Engine to restart. This vulnerability is due to incomplete validation of the SSL certificate. An attacker could exploit this vulnerability by sending a crafted SSL connection setup request to be [truncated]

MEDIUM Cisco CVE published 2026-09-16

CVE-2026-20287

A Cisco internal security review led to a software hardening release addressing multiple vulnerabilities, including CVE-2026-20287, related to improper privilege management issues in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC). The vulnerabilities were found during a comprehensive review aimed at enhancing the security posture of Cisco's products. This proactive [truncated]

MEDIUM Cisco CVE published 2026-09-16

CVE-2026-20286

A vulnerability in the web-based management interface of Cisco Identify Services Engine (ISE) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. This vulnerability is due to the lack of server-side validation of Administrator permissions. An attacker could exploit this vulnerability by submitting a crafted HTTP request to an affected system. A success [truncated]

MEDIUM Cisco CVE published 2026-09-16

CVE-2026-20285

CVE-2026-20285 is a vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) that could allow an authenticated, remote attacker to modify parts of the configuration on an affected device due to lack of server-side validation of Administrator permissions. The vulnerability can be exploited by submitting a crafted HTTP req [truncated]

CRITICAL Cisco CVE published 2026-09-16

CVE-2026-20284

A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks. This vulnerability is due to insufficient validation of user-supplied input in REST API calls. An attacker could exploit this vulnerability by sending crafted input to an affected device. A successful exploit could allow the attacker to view or modify data on the underlying data [truncated]

MEDIUM Cisco CVE published 2026-09-16

CVE-2026-20283

CVE-2026-20283 is a vulnerability in the IPsec Open API endpoint of Cisco ISE that could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system. The vulnerability is due to insufficient validation of user-supplied input in IPsec Open API calls. To exploit this vulnerability, the attacker must have valid administrative credentials and the node must have more [truncated]

MEDIUM Cisco CVE published 2026-09-16

CVE-2026-20282

CVE-2026-20282 is a vulnerability in Cisco ISE that could allow an authenticated, remote attacker to obtain write access on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of user-supplied input. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability has a High Security Impact Rating (SIR) from C [truncated]

HIGH Cisco CVE published 2026-09-16

CVE-2026-20250

A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Secure Firewall 3100 Series and 4200 Series devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper resource man [truncated]

HIGH Cisco CVE published 2026-09-16

CVE-2026-20249

A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2) for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly. This vulnerability is due to a logic error during the certificate authentication [truncated]

MEDIUM Cisco CVE published 2026-09-16

CVE-2026-20248

A vulnerability in the DNS over TCP implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the TCP DNS response handler to unexpectedly restart, causing the device to reload. This vulnerability is due to a logic error when parsing a DNS query and tracking the size of [truncated]

HIGH Cisco CVE published 2026-09-16

CVE-2026-20247

A vulnerability in Cisco ISE could allow an unauthenticated, remote attacker to conduct SQL injection attacks on an affected device. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to modify data in the underlying database.

MEDIUM Cisco CVE published 2026-09-16

CVE-2026-20235

A vulnerability in the API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. The vulnerability is due to insufficient validation of user-supplied parameters in API requests. An attacker could exploit this vulnerability by sending a [truncated]

HIGH Cisco CVE published 2026-09-16

CVE-2026-20222

A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition. The vulnerability is due to improper resource management when handling EIGRP update messages. An attacker could exploit this vulnerability by sending crafted EIGRP updates [truncated]

HIGH Cisco CVE published 2026-09-16

CVE-2026-20154

A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization, resulting in a denial of service (DoS) condition. The vulnerability is due to improper rate limiting for syslog message 419002. An attacker could exploit this vulnerability by sending a flo [truncated]

HIGH Cisco CVE published 2026-09-16

CVE-2026-20135

A vulnerability in Cisco Secure Firewall Threat Defense (FTD) Software's TLS 1.3 implementation could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition by sending a crafted TLS 1.3 packet, causing the device to reload unexpectedly. This vulnerability affects Cisco Secure Firewall Threat Defense (FTD) Software and could lead to temporary disruption of network operations [truncated]

MEDIUM Cisco CVE published 2026-09-16

CVE-2026-20121

A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access controls. The vulnerability is due to a logic error in populating group access control policies (ACPs) with OGS configured. An attacker could exploit this vulnerability by sending traffic that [truncated]

MEDIUM Cisco CVE published 2026-09-16

CVE-2026-20120

A vulnerability in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access controls. The vulnerability is due to a logic error in populating group access control policies (ACPs) with Object Group Search (OGS) configured. An attacker could exploit this vulnerability b [truncated]

MEDIUM Cisco CVE published 2026-09-16

CVE-2026-20072

A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive information from network users outside their assigned security group due to improper authorization enforcement on certain files. An attacker with administrative privileges could exploit this by exporting users, potentially viewing passwords normally not visible to administrators.

LOW Cisco CVE published 2026-09-16

CVE-2026-20071

A vulnerability in the SSID bring-your-own-device (BYOD) onboarding workflow of Cisco ISE could allow an unauthenticated, adjacent attacker to hijack the onboarding session of another user and access protected 802.1X networks. This vulnerability is due to insufficient authentication checks that are performed while a user is being onboarded. An attacker could exploit this vulnerability by spoofing the legi [truncated]

CRITICAL Cisco CVE published 2026-09-16

CVE-2026-20330

A Cisco internal security review led to a software hardening release addressing multiple vulnerabilities, including CVE-2026-20330, related to improper neutralization issues grouped under CWE-707. The CVE has a CVSS score of 9.9 and is considered CRITICAL. Defenders should verify exposure and assess potential impact due to the high CVSS score and critical severity. This vulnerability affects Cisco Secure [truncated]

CRITICAL Cisco CVE published 2026-09-16

CVE-2026-20329

CVE-2026-20329 is a critical vulnerability in Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software, and Cisco Secure Firewall Management Center Software. The vulnerability is related to improper handling of exceptional conditions and has a CVSS score of 9.9. Cisco has released a software hardening release to address this vulnerability.

CRITICAL Cisco CVE published 2026-09-16

CVE-2026-20326

A Cisco Nexus Dashboard vulnerability (CVE-2026-20326) with a CVSS score of 9.8 was disclosed, related to missing authentication for a critical function. The vulnerability was discovered during an internal security review by Cisco's Nexus Dashboard engineering team. The issue is tracked under CWE-306. This vulnerability affects Cisco Nexus Dashboard deployments, which defenders should assess for exposure [truncated]

CRITICAL Cisco CVE published 2026-09-16

CVE-2026-20325

A Cisco Nexus Dashboard vulnerability allows for improper neutralization of special elements used in a command. This issue, tracked by CVE-2026-20325, was found during an internal security review. The vulnerability has a CVSS score of 9.9 and is considered critical. The issue arises from a software hardening release addressing multiple internally discovered vulnerabilities. Defenders should assess exposur [truncated]