Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 31 results
criticalbug_reportVulnerabilityCisco patches critical RCE in Nexus 9000 and 7 IOS XR umbrella CVEs
Cisco Silicon One-based Nexus 9000 switches (10 models, NX-OS 10.3(1) through 10.6(3s)) via CVE-2026-20212. All Cisco IOS XR releases across all platforms via 7 umbrella CVEs (CVE-2026-20274 through 20280), including XR7 (LNT) platforms: Cisco 8000 S…
highperson_alertThreat ActorFire Ant compromises Cisco routers for network surveillance
Fire Ant is a Chinese espionage-focused threat actor attributed by Sygnia, with operational overlap to UNC3886 (previously documented by Google). The group targets critical infrastructure and high-value networks through a "target behind the target" s…
highperson_alertThreat ActorFire Ant Expands Espionage to Cisco Routers and TACACS Servers
Fire Ant is a China-linked cyber espionage actor that has conducted long-running campaigns targeting network infrastructure and virtualization platforms.
criticalbug_reportVulnerabilityCisco patches nine flaws in Crosswork and Secure Workload; five rated 10.0
Cisco Crosswork Data Gateway, Crosswork Network Controller, Crosswork Planning (Release 7.2.1 and earlier); Cisco Secure Workload SaaS and on-premises (Release 3.10 and earlier, Release 4.0).
criticalbug_reportVulnerabilityCisco Secure Firewall DoS flaw under active exploitation
Cisco Secure Firewall products (specific versions not disclosed in available data). Organizations using Cisco ASA, FTD, or Firepower appliances should assume exposure until vendor advisory is reviewed.
highbug_reportVulnerabilityCisco ASA/FTD remote DoS flaw exploited in wild, CISA orders patch by Aug 14
Cisco Secure Firewall ASA Software (versions 9.16.1, 9.18.1, 9.20, 9.22, 9.23, 9.24) and FTD Software (versions 7.0, 7.2, 7.4, 7.6, 7.7, 10.0) with IKEv2 Remote Access VPN, SSL-VPN, or Zero Trust Network Access enabled.
highbug_reportVulnerabilityCisco ASA/FTD VPN flaw CVE-2026-20349 actively exploited for DoS
Cisco Secure Firewall ASA (versions 9.16, 9.18, 9.20, 9.22, 9.23, 9.24) and Threat Defense FTD (versions 7.0, 7.2, 7.4, 7.6, 7.7, 10.0) with Remote Access SSL VPN, IKEv2 Remote Access VPN with client services, or Zero Trust Network Access enabled.
criticalbug_reportVulnerabilityCisco patches 12 critical SD-WAN and IOS XE flaws, three rated 9.8+
Cisco Catalyst SD-WAN Software (all versions prior to 20.9, versions 20.9–26.1); Cisco IOS XE Software versions 17.9–26.1 running in autonomous or controller mode; Cisco Integrated Management Controller (IMC) web interface.
criticalbug_reportVulnerabilityCritical Cisco Catalyst SD-WAN flaws require immediate patching
Cisco Catalyst SD-WAN Software (specific versions not disclosed in advisory). Scope: SD-WAN infrastructure components used for enterprise WAN connectivity and management.
highbug_reportVulnerabilityCisco IOS/IOS XE vulnerabilities require immediate patching per CERT.BE
Cisco IOS and IOS XE platforms. Specific affected versions not provided in advisory. Multiple vulnerabilities of high severity impact network infrastructure devices including routers and switches running these operating systems.
criticalbug_reportVulnerabilityCisco Secure Firewall Management Center under active exploitation
Cisco Secure Firewall Management Center (formerly Firepower Management Center). Specific affected versions not disclosed in available data. Vulnerability details including CVE identifier not yet published.
highbug_reportVulnerabilityCisco FMC static credential flaw exploited in zero-day attacks
Cisco Secure Firewall Management Center (FMC) Software versions 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. Does not affect Cloud-Delivered FMC, Firewall Device Manager, ASA Software, Threat Defense Software, or Security Cloud Control.
highbug_reportVulnerabilityCisco Unified CM vulnerability under active exploitation post-patch
Cisco Unified Communications Manager (Unified CM). Specific vulnerable versions not disclosed; patched versions available since early June 2024. Affects organizations running unpatched Unified CM deployments.
criticalbug_reportVulnerabilityCISA orders federal patch for exploited Cisco Unified Comms flaw
Cisco Unified Communications Manager Server. Specific versions not disclosed. Federal agencies mandated to patch; all organizations running this product should consider affected.
highbug_reportVulnerabilityCisco Catalyst SD-WAN zero-day exploited in wild for two months
Cisco Catalyst SD-WAN Manager. Specific affected versions not disclosed. Requires authenticated local access for exploitation.
criticalbug_reportVulnerabilityCisco Catalyst SD-WAN zero-day exploited for root access (CVE-2026-20245)
Cisco Catalyst SD-WAN devices. Specific affected versions not disclosed in available information. Attackers gain root-level access and can create persistent rogue accounts.
criticalbug_reportVulnerabilityCisco Unified CM critical flaw under active exploitation, root access risk
Cisco Unified Communications Manager (CUCM) and Unified CM SME. Specific affected versions not provided in available data. Vulnerability affects HTTP request handling with unauthenticated remote attack vector.
highbug_reportVulnerabilityCisco Unified Communications Manager SSRF under active exploitation
Cisco Unified Communications Manager (CUCM). Specific affected versions not disclosed. SSRF vulnerability (CVE-2026-20230) allows attackers to force the server to make unauthorized requests to internal or external resources.
criticalbug_reportVulnerabilityCisco SD-WAN vulnerability under active exploitation, patches released
Cisco SD-WAN products. Specific affected versions not provided in available data. Organizations running Cisco SD-WAN infrastructure are potentially at risk.
highbug_reportVulnerabilityCisco Catalyst SD-WAN Manager under active exploit (CVE-2026-20262)
Cisco Catalyst SD-WAN Manager. Specific vulnerable versions not provided in summary. Affects web UI component accessible to authenticated remote users.
criticalbug_reportVulnerabilityCisco Catalyst SD-WAN Manager root privilege escalation under attack
Cisco Catalyst SD-WAN Manager (specific versions not provided). Vulnerability allows privilege escalation to root level on affected systems.
highbug_reportVulnerabilityCisco Catalyst SD-WAN Manager actively exploited (CVE-2026-20245)
Cisco Catalyst SD-WAN Manager. Specific affected versions not disclosed. Vulnerability involves improper encoding or escaping of output (CVSS 7.8). Also affects products from Google and Arista (details not provided).
highbug_reportVulnerabilityCisco Catalyst SD-WAN Manager CVE-2026-20245 exploited in wild, no patch
Cisco Catalyst SD-WAN Manager across all deployment types: On-Prem, Cloud-Pro, Cloud (Cisco Managed), and Government (FedRAMP). Specific affected versions not disclosed. CVSS 7.8 (High).
criticalbug_reportVulnerabilityCisco SD-WAN Manager zero-day CVE-2026-20245 exploited for root access
Cisco Catalyst SD-WAN Manager, all versions (specific affected versions not disclosed). Unpatched zero-day vulnerability enabling root privilege escalation.
highbug_reportVulnerabilityCisco Unified Communications Manager high severity flaw with public PoC
Cisco Unified Communications Manager (CUCM). Specific affected versions not disclosed in alert. CVE identifier not yet assigned or published.
criticalbug_reportVulnerabilityCritical vulnerability in Cisco Secure Workload requires immediate patching
Cisco Secure Workload (specific versions not disclosed in advisory). CVE identifier not yet assigned or published.
criticalbug_reportVulnerabilityCisco Secure Workload REST API flaw allows unauthenticated data access
Cisco Secure Workload (formerly Tetration). Specific affected versions not provided in available data. Vulnerability impacts REST API endpoints with insufficient authentication controls.
criticalbug_reportVulnerabilityCisco Secure Workload max-severity flaw grants Site Admin privileges
Cisco Secure Workload platform. Specific affected versions not provided in summary. Vulnerability allows privilege escalation to Site Admin level, affecting administrative access controls.
criticalbug_reportVulnerabilityCisco Catalyst SD-WAN auth bypass grants admin access to attackers
Cisco Catalyst SD-WAN platform. Specific affected versions not disclosed. Vulnerability allows authentication bypass leading to administrative access on SD-WAN infrastructure components.
criticalbug_reportVulnerabilityCisco SD-WAN Manager auth bypass exploited in wild since 2023
Cisco Catalyst SD-WAN controllers and Cisco SD-WAN Manager. Specific affected versions not provided in advisory summary. CVE-2026-20127 allows administrative access compromise.