<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Cisco</title><description>Actively exploited vulnerabilities affecting Cisco products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/cisco.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-20349 — Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-20349</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-20349</guid><description>This vulnerability affects Cisco&apos;s widely deployed ASA and FTD firewall products, which sit at the perimeter of many enterprise networks. An unauthenticated remote attacker can exploit a heap inspection flaw to crash the device, triggering a denial-of-service condition. Because no authentication is required, the attack surface is broad — any internet-exposed ASA or FTD appliance could be targeted, potentially taking down a critical network security boundary and disrupting connectivity for an entire organization.</description><pubDate>Tue, 11 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) </category></item><item><title>CVE-2026-20316 — Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-20316</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-20316</guid><description>Cisco&apos;s Secure Firewall Management Center contains a hard-coded password that ships with the product itself — meaning an attacker who knows this credential (which can often be discovered through public research or reverse engineering) can remotely log in without any prior access. Because FMC is used to centrally manage firewall policies and security infrastructure, unauthorized access could expose sensitive network configuration data and potentially allow manipulation of security controls across an entire environment.</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>Secure Firewall Management Center (FMC)</category></item><item><title>CVE-2008-4128 — Cisco IOS Cross-Site Request Forgery Vulnerability</title><link>https://wildfortech.com/security#CVE-2008-4128</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2008-4128</guid><description>This vulnerability affects Cisco IOS 12.4 routers running the HTTP management interface. An attacker can trick an authenticated administrator into unknowingly executing privileged commands — including configuration changes — simply by visiting a malicious page or clicking a crafted link. Because the attack exploits the router&apos;s trust in the administrator&apos;s browser session, it can lead to full device compromise without requiring the attacker to have credentials of their own.</description><pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>IOS</category></item><item><title>CVE-2026-20230 — Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-20230</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-20230</guid><description>This vulnerability in Cisco Unified Communications Manager allows an unauthenticated remote attacker to exploit a server-side request forgery flaw to write arbitrary files to the underlying operating system. Those written files could then be leveraged to escalate privileges all the way to root. Because no authentication is required, any internet-exposed Unified CM or Unified CM SME instance is at risk of full system compromise without any user interaction.</description><pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>Unified Communications Manager</category></item><item><title>CVE-2026-20262 — Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-20262</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-20262</guid><description>This vulnerability in Cisco Catalyst SD-WAN Manager allows an authenticated remote attacker to traverse directory paths and either create new files or overwrite existing ones anywhere on the affected system&apos;s filesystem. Because attackers can manipulate critical system files, this could lead to privilege escalation, persistent backdoors, or system compromise. The fact that it only requires authentication — not administrative rights — makes it a significant risk in environments where SD-WAN Manager is internet-exposed.</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>Catalyst SD-WAN Manager</category></item><item><title>CVE-2026-20245 — Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-20245</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-20245</guid><description>This vulnerability in Cisco Catalyst SD-WAN Manager allows an authenticated local attacker to escalate privileges and execute arbitrary commands as root by supplying a crafted file to the system. Because root-level code execution can give an attacker complete control over the SD-WAN management plane, the blast radius is severe — potentially exposing the entire SD-WAN fabric to further compromise. The requirement for local, authenticated access limits exposure somewhat, but insider threats and compromised credentials remain realistic attack paths.</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>Catalyst SD-WAN Manager</category></item><item><title>CVE-2026-20182 — Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-20182</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-20182</guid><description>This vulnerability allows an unauthenticated remote attacker to completely bypass authentication on Cisco Catalyst SD-WAN Controllers and Managers, gaining full administrative control. Because SD-WAN controllers sit at the heart of wide-area network infrastructure, a successful exploit could let an attacker reroute traffic, alter network configurations, or pivot deeper into the organization — all without needing any valid credentials. The wide network exposure of these management interfaces makes this a high-priority threat.</description><pubDate>Thu, 14 May 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>Catalyst SD-WAN</category></item><item><title>CVE-2026-20122 — Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-20122</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-20122</guid><description>This flaw in Cisco Catalyst SD-WAN Manager lets an attacker abuse privileged APIs by uploading a malicious file through the API interface. If successful, the attacker can overwrite arbitrary files on the system and elevate their access to vmanage user privileges — effectively gaining administrative-level control over SD-WAN management infrastructure. Because SD-WAN managers are central to network orchestration, a compromise can have broad downstream impact across the managed network.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>Catalyst SD-WAN Manger</category></item><item><title>CVE-2026-20128 — Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-20128</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-20128</guid><description>This flaw in Cisco Catalyst SD-WAN Manager stores passwords in a recoverable format, meaning a low-privileged local user can read a credential file on the filesystem and escalate to DCA user privileges. While an attacker needs existing local access, privilege escalation within SD-WAN management infrastructure is serious — SD-WAN managers control wide-area network policy and routing, so a compromised DCA account could have significant downstream impact across the network.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>Catalyst SD-WAN Manager</category></item><item><title>CVE-2026-20133 — Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-20133</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-20133</guid><description>This vulnerability in Cisco Catalyst SD-WAN Manager allows remote attackers to access sensitive information without authentication or authorization. SD-WAN Manager is a central control plane for wide-area network infrastructure, meaning exposed data could reveal network topology, credentials, or configuration details that attackers could exploit for deeper network compromise. CISA has issued an Emergency Directive (ED 26-03) reflecting the severity and active risk this poses to organizations running Cisco SD-WAN environments.</description><pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>Catalyst SD-WAN Manager</category></item><item><title>CVE-2026-20131 — Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-20131</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-20131</guid><description>This critical flaw in Cisco&apos;s Firewall Management Center and Security Cloud Control allows a completely unauthenticated remote attacker to execute arbitrary Java code with root-level privileges through the web management interface. Because no login is required and the attacker gains full system control, a successful exploit could lead to complete compromise of firewall policy management — effectively giving an adversary control over network security controls. This vulnerability is already known to be used in ransomware attacks, making rapid action essential.</description><pubDate>Thu, 19 Mar 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>Secure Firewall Management Center (FMC)</category></item><item><title>CVE-2022-20775 — Cisco SD-WAN Path Traversal Vulnerability</title><link>https://wildfortech.com/security#CVE-2022-20775</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2022-20775</guid><description>This vulnerability in Cisco SD-WAN&apos;s command-line interface allows an authenticated local attacker to traverse file paths and abuse improperly restricted CLI commands to escalate privileges all the way to root. While the attacker must already have local authenticated access, successful exploitation grants complete control over the device — a serious risk in SD-WAN environments where these devices sit at the heart of enterprise network infrastructure.</description><pubDate>Wed, 25 Feb 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>SD-WAN</category></item><item><title>CVE-2026-20127 — Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-20127</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-20127</guid><description>This vulnerability allows a remote, unauthenticated attacker to completely bypass login controls on Cisco Catalyst SD-WAN Controllers and Managers and gain high-privileged access. Once in, the attacker can use NETCONF to directly manipulate the network configuration of the entire SD-WAN fabric. Because SD-WAN controllers govern routing and policy for potentially thousands of sites, a successful exploit could give an attacker broad control over enterprise or carrier network infrastructure with no prior credentials required.</description><pubDate>Wed, 25 Feb 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>Catalyst SD-WAN Controller and Manager</category></item><item><title>CVE-2026-20045 — Cisco Unified Communications Products Code Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-20045</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-20045</guid><description>This vulnerability affects multiple widely-deployed Cisco Unified Communications products, including Unified CM, Unified CM SME, Unified CM IM&amp;P, Unity Connection, and Webex Calling Dedicated Instance. An attacker who exploits it can inject code to gain initial user-level access to the underlying operating system, then escalate privileges all the way to root. Full root compromise means an attacker could exfiltrate data, pivot deeper into the network, or disrupt critical voice and messaging infrastructure.</description><pubDate>Wed, 21 Jan 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>Unified Communications Manager</category></item><item><title>CVE-2025-20393 — Cisco Multiple Products Improper Input Validation Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-20393</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-20393</guid><description>This vulnerability in Cisco&apos;s Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances allows attackers to inject malicious input that bypasses validation checks, ultimately executing arbitrary commands as root. Root-level access means a successful attacker has complete control over the underlying operating system — able to modify configurations, exfiltrate data, install backdoors, or pivot deeper into the network. These are perimeter security appliances, making compromise especially serious since they are trusted to inspect and filter traffic.</description><pubDate>Wed, 17 Dec 2025 00:00:00 GMT</pubDate><category>Cisco</category><category>Multiple Products</category></item><item><title>CVE-2025-20352 — Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-20352</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-20352</guid><description>A stack-based buffer overflow in the SNMP subsystem of Cisco IOS and IOS XE creates two serious risk scenarios: a low-privileged attacker can crash affected devices by forcing a reload (denial of service), while a high-privileged attacker can execute arbitrary code as root, gaining full system control. SNMP is widely deployed for network device management, making this a high-value target. Both network availability and complete device integrity are at stake.</description><pubDate>Mon, 29 Sep 2025 00:00:00 GMT</pubDate><category>Cisco</category><category>IOS and IOS XE</category></item><item><title>CVE-2025-20333 — Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-20333</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-20333</guid><description>This buffer overflow flaw in Cisco&apos;s ASA and FTD VPN web server allows an unauthenticated remote attacker to execute arbitrary code on affected devices — essentially taking control of the firewall itself. The risk is compounded because it can be chained with a second vulnerability, CVE-2025-20362, potentially enabling more complex or reliable attacks. Perimeter security devices like these are high-value targets, and remote code execution at this layer can expose entire internal networks.</description><pubDate>Thu, 25 Sep 2025 00:00:00 GMT</pubDate><category>Cisco</category><category>Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense</category></item><item><title>CVE-2025-20362 — Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-20362</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-20362</guid><description>This vulnerability in Cisco&apos;s ASA and FTD products allows attackers to bypass authorization controls in the VPN web server component. Its real danger is amplified because it can be chained with a second vulnerability (CVE-2025-20333), meaning attackers could combine the two flaws to achieve a more severe exploit than either vulnerability allows alone. Organizations running ASA or FTD for remote access VPN are potentially exposed to unauthorized access to protected resources.</description><pubDate>Thu, 25 Sep 2025 00:00:00 GMT</pubDate><category>Cisco</category><category>Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense</category></item><item><title>CVE-2025-20281 — Cisco Identity Services Engine Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-20281</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-20281</guid><description>Cisco Identity Services Engine (ISE) is a widely deployed network access control and policy platform. This vulnerability allows an unauthenticated attacker to send a specially crafted API request that bypasses input validation, resulting in remote code execution with root-level privileges. Because ISE controls network authentication and authorization decisions, a full compromise could give attackers the ability to manipulate access policies, move laterally, or pivot into broader network infrastructure.</description><pubDate>Mon, 28 Jul 2025 00:00:00 GMT</pubDate><category>Cisco</category><category>Identity Services Engine</category></item><item><title>CVE-2025-20337 — Cisco Identity Services Engine Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-20337</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-20337</guid><description>Cisco Identity Services Engine (ISE) is a widely deployed network access control platform. This vulnerability allows an unauthenticated attacker to send a specially crafted API request that bypasses input validation, execute arbitrary code remotely, and ultimately gain root-level control of the device. Because ISE acts as a central policy and authentication hub, a full compromise could give attackers broad access to network resources and user credentials across the organization.</description><pubDate>Mon, 28 Jul 2025 00:00:00 GMT</pubDate><category>Cisco</category><category>Identity Services Engine</category></item></channel></rss>