cisco

Cisco Patches Nine Flaws in Crosswork and Secure Workload Software
Cisco has released security updates addressing nine vulnerabilities affecting its Crosswork platforms and Secure Workload Software. Five of these flaws have received a critical CVSS score of 10.0. The vulnerabilities impact Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, irrespective of device configuration.

U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to patch them by specific deadlines. The vulnerabilities affect Cisco Secure Firewall, Microsoft Windows, and Metabase, with the Metabase flaw being a critical SQL injection that was actively exploited.

Cisco Identity Services Engine Vulnerable to Command Injection
A critical vulnerability has been discovered in Cisco Identity Services Engine that permits remote attackers to execute arbitrary code. Exploitation requires prior authentication. The vulnerability has been assigned a CVSS score of 7.2.

Cisco Identity Services Engine Leaks Information Due to Missing Authentication
A critical vulnerability has been discovered in Cisco Identity Services Engine, allowing unauthenticated remote attackers to access sensitive information. The flaw stems from a missing authentication check for a critical function within the software. This could lead to significant data exposure on affected systems.

Cisco Identity Services Engine Vulnerable to RCE via Directory Traversal
A directory traversal vulnerability in Cisco Identity Services Engine could allow authenticated remote attackers to execute arbitrary code on affected systems. The vulnerability has a CVSS score of 7.2, indicating a significant security risk.

Cisco Identity Services Engine Vulnerability Discloses Sensitive Information
A directory traversal vulnerability in Cisco Identity Services Engine allows authenticated remote attackers to access sensitive information. The vulnerability, assigned CVE-2026-20148, has a CVSS score of 4.9, indicating a medium severity.

SharpHound Recon Attack – How AI enhanced the threat hunt
Researchers integrated an AI-driven security agent with full packet capture technology at Cisco Live AMER 2026 to automate threat hunting and analysis. The system successfully identified a potential SharpHound reconnaissance attack, analyzed network traffic, and accurately determined it to be a benign near-miss, saving significant analyst time and demonstrating the AI's potential to boost SOC efficiency.

Cisco Live Event SOC Educates Attendees on Security Operations
The Cisco Event SOC at Cisco Live AMER 2026 served a dual purpose of providing security operations during the event and educating attendees. Through guided tours, dedicated speaker sessions, and interactions at the World of Solutions, the SOC shared insights into its live operations.

In Less Than 24 Hours, Attackers Weaponize Cisco CUCM Flaw
A critical vulnerability affecting Cisco Unified CM and Unified CM SME deployments, which allows for server-side request forgery (SSRF) and root privilege escalation, was rapidly exploited by attackers. Threat actors weaponized the flaw within 24 hours of its public disclosure.