Friday, August 28, 2026
Follow on LinkedIn

Cisco

Cisco Unified Contact Center Express Vulnerabilities Enables Remote Code Execution Attacks

A critical security advisory addressing multiple severe vulnerabilities in Cisco Unified Contact Center Express (Unified CCX). That could allow unauthenticated remote attackers to execute arbitrary commands and compromise affected systems. The vulnerabilities were disclosed on November 5, 2025, with the advisory...

Cisco IMC Virtual Keyboard Video Monitor Let Attacker Direct User to Malicious Website

Cisco disclosed a high-severity open redirect vulnerability in the Virtual Keyboard Video Monitor (vKVM) component of its Integrated Management Controller (IMC). Tracked as CVE-2025-20317 with a CVSS 3.1 base score of 7.1, the vulnerability could enable an unauthenticated remote attacker...

Cisco Unified Intelligence Center Vulnerability Allows Remote Attackers to Upload Arbitrary Files

A critical vulnerability in Cisco’s Unified Intelligence Center (CUIC) web-based management interface has been classified with high severity, allowing authenticated remote attackers with Report Designer privileges to upload arbitrary files to affected systems.  Tracked as CVE-2025-20274 and assigned a CVSS...

Massive Spike in Password Attacks Targeting Cisco ASA VPN Followed by Microsoft 365

A dramatic surge in password spray attacks targeting enterprise infrastructure, with Cisco ASA VPN systems experiencing an unprecedented 399% increase in attacks during Q1 2025, while Microsoft 365 authentication services saw a 21% rise in similar attacks. The alarming statistics...

Cisco Unified CM Vulnerability Allows Remote Attacker to Login As Root User

A severe vulnerability in Cisco Unified Communications Manager (Unified CM) systems could allow remote attackers to gain root-level access to affected devices.  The vulnerability, designated CVE-2025-20309 with a maximum CVSS score of 10.0, affects Engineering Special releases and stems from...

Cisco AnyConnect VPN Server Vulnerability Let Attackers Trigger DoS Attack

A critical security vulnerability affecting Cisco Meraki MX and Z Series devices could allow unauthenticated attackers to launch denial of service (DoS) attacks against AnyConnect VPN services.  The vulnerability, tracked as CVE-2025-20271 with a CVSS score of 8.6, was published...

Cisco Nexus Dashboard Vulnerability Lets Attackers Impersonate as Managed Devices

A high-severity vulnerability has been discovered in Cisco's Nexus Dashboard Fabric Controller (NDFC) that could allow unauthenticated attackers to impersonate managed network devices through compromised SSH connections.  The vulnerability, tracked as CVE-2025-20163, carries a CVSS base score of 8.7 and...

Cisco ISE Vulnerability Allows Remote to Access Sensitive Data – PoC Exploit Available

A critical vulnerability affecting its Identity Services Engine (ISE) when deployed on major cloud platforms, warning that proof-of-concept exploit code is now publicly available.  The flaw, tracked as CVE-2025-20286 with a CVSS score of 9.9, enables unauthenticated remote attackers to...

Critical Cisco IOS XE Vulnerability Allows Arbitrary File Upload – PoC Released

A critical security vulnerability in Cisco IOS XE Wireless Controller Software has emerged as a significant threat to enterprise networks, with researchers releasing proof-of-concept (PoC) exploit code that demonstrates how attackers can achieve remote code execution with root privileges.  The...

Cisco Webex Meetings Vulnerability Let Attackers Manipulate HTTP Responses

Cisco disclosed a security vulnerability (CVE-2025-20255) affecting its Webex Meetings service that could allow remote attackers to manipulate cached HTTP responses.  The vulnerability, assigned a CVSS score of 4.3 (Medium severity), stems from improper handling of malicious HTTP requests in...

Latest News

Latest News