Vendor

Cisco

Cisco news

Severity: ElevatedAction: Be aware

The Fine Art of Frustrating the Adversary

What really frustrates an adversary? Eight Cisco Talos researchers share practical ways to make their next move slower and riskier. From deception and behavioral detection to breaking attack dependencies and resisting manufactured urgency.

Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

Cisco warns of new SD-WAN zero-day exploited in attacks

CISA added CVE-2026-76504 (Cisco Catalyst SD-WAN Manager) to its Known Exploited Vulnerabilities catalog on September 30, 2026, which means there is reliable evidence of exploitation in the wild. Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI…

Why it matters

CISA lists this as exploited in the wild. Unpatched Cisco networking & security and Catalyst SD-WAN Manager systems are exposed to active attacks now.

Act now

Treat this as an emergency.

Severity: ElevatedAction: Be aware

The Closed Quorum: Inside the first reported autonomous AI C2 implant

CLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous command and control (C2). It represents a shift in effort displacement for attackers, in which expanding portions of the attack chain can be executed without operator involvement.

Severity: CriticalAction: Act nowExploitation: ExploitedCISA KEV

Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability (CVE-2026-76460) is being actively exploited, CISA warns

CISA added CVE-2026-76460 (Cisco Identity Services Engine) to its Known Exploited Vulnerabilities catalog on September 16, 2026, which means there is reliable evidence of exploitation in the wild. Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized…

Why it matters

CISA lists this as exploited in the wild. Unpatched Cisco networking & security and Identity Services Engine systems are exposed to active attacks now.

Act now

Treat this as an emergency.

Recent intelligence

The latest developments from the last 30 days, newest first.

  1. Coverage

    The Fine Art of Frustrating the Adversary

    Basis: Cisco Talos Intelligence (security research)

  2. DisclosedCVE-2026-76504

    Cisco warns of new SD-WAN zero-day exploited in attacks

    Basis: Reporting by BleepingComputer

  3. Added to CISA KEVUpdateCVE-2026-76504

    CVE-2026-76504 added to CISA KEV: Cisco Catalyst SD-WAN Manager, Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability

    Basis: CISA Known Exploited Vulnerabilities catalog

  4. Coverage

    China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor

    Basis: Cisco Talos Intelligence (security research)

Actively exploited

All 100 →

Cisco Catalyst SD-WAN Manager

Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability

Added Sep 30, 2026Fed. due Oct 3, 2026Coverage →

Cisco Identity Services Engine

Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

Added Sep 16, 2026Fed. due Sep 19, 2026Coverage →

Cisco Secure Email Gateway

Cisco Secure Email Gateway SQL Injection Vulnerability

Added Sep 14, 2026Fed. due Sep 17, 2026

Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management

Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability

Added Sep 9, 2026Fed. due Sep 12, 2026

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability

Added Aug 11, 2026Fed. due Aug 14, 2026
CVE-2026-20316RansomwareCVSS 5.3

Cisco Secure Firewall Management Center (FMC)

Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability

Added Jul 29, 2026Fed. due Aug 1, 2026

Cisco IOS

Cisco IOS Cross-Site Request Forgery Vulnerability

Added Jul 13, 2026Fed. due Jul 16, 2026

Cisco Unified Communications Manager

Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability

Added Jun 25, 2026Fed. due Jun 28, 2026

Cisco Catalyst SD-WAN Manager

Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability

Added Jun 15, 2026Fed. due Jun 29, 2026

Cisco Catalyst SD-WAN Manager

Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability

Added Jun 9, 2026Fed. due Jun 23, 2026

Cisco Catalyst SD-WAN

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

Added May 14, 2026Fed. due May 17, 2026

Cisco Catalyst SD-WAN Manager

Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability

Added Apr 20, 2026Fed. due Apr 23, 2026

Cisco Catalyst SD-WAN Manager

Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

Added Apr 20, 2026Fed. due Apr 23, 2026

Cisco Catalyst SD-WAN Manger

Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability

Added Apr 20, 2026Fed. due Apr 23, 2026
CVE-2026-20131RansomwareCVSS 10.0

Cisco Secure Firewall Management Center (FMC)

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability

Added Mar 19, 2026Fed. due Mar 22, 2026

Cisco Catalyst SD-WAN Controller and Manager

Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability

Added Feb 25, 2026Fed. due Feb 27, 2026

Cisco SD-WAN

Cisco SD-WAN Path Traversal Vulnerability

Added Feb 25, 2026Fed. due Feb 27, 2026

Cisco Unified Communications Manager

Cisco Unified Communications Products Code Injection Vulnerability

Added Jan 21, 2026Fed. due Feb 11, 2026

Cisco Multiple Products

Cisco Multiple Products Improper Input Validation Vulnerability

Added Dec 17, 2025Fed. due Dec 24, 2025

Cisco IOS and IOS XE

Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability

Added Sep 29, 2025Fed. due Oct 20, 2025

Products

IOS and IOS XE Software · 14 KEVIOS Software · 10 KEVAdaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) · 6 KEVIOS XR · 6 KEVCatalyst SD-WAN Manager · 5 KEVSmall Business RV160, RV260, RV340, and RV345 Series Routers · 5 KEVAdaptive Security Appliance (ASA) · 4 KEVIOS and IOS XE · 4 KEVIdentity Services Engine · 3 KEVIOS Software and Cisco IOS XE Software · 3 KEVAnyConnect Secure · 2 KEVHyperFlex HX · 2 KEVIOS · 2 KEVIOS XE Software · 2 KEVIOS, XR, and XE Software · 2 KEVSecure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense · 2 KEVSecure Firewall Management Center (FMC) · 2 KEVUnified Communications Manager · 2 KEVAdaptive Security Appliance and Firepower Threat Defense · 1 KEVCatalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches · 1 KEVCatalyst 6800 Series Switches · 1 KEVCatalyst SD-WAN · 1 KEVCatalyst SD-WAN Controller and Manager · 1 KEVCatalyst SD-WAN Manger · 1 KEVCisco IOS XE Web UI · 1 KEVCisco IP Phones · 1 KEVIOS, IOS XR, and IOS XE · 1 KEVIOS XE Web UI · 1 KEVMultiple Products · 1 KEVNX-OS · 1 KEVPrime Data Center Network Manager (DCNM) · 1 KEVRV Series Routers · 1 KEVSD-WAN · 1 KEVSecure Access Control System (ACS) · 1 KEVSecure Email Gateway · 1 KEVSecure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) · 1 KEVSecure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management · 1 KEVSmall Business RV320 and RV325 Dual Gigabit WAN VPN Routers · 1 KEVSmall Business RV320 and RV325 Routers · 1 KEVSmall Business RV Series Routers · 1 KEVSmart Licensing Utility · 1 KEVVPN Routers · 1 KEVCisco networking & security