Skip to content

company

Cisco

Cisco is a major networking and IT infrastructure vendor, making routers, switches, security appliances, and software like Catalyst SD-WAN Manager.

Known aliases

  • cisco.com
  • Cisco PSIRT
  • Cisco Systems
  • Cisco Systems Inc.
  • CSCO

Relationships

No evidence-backed relationships are recorded.

Current stories

security12 publishers

Attackers reach admin on Cisco Catalyst SD-WAN Manager by encoding one URL character

Cisco says attackers are exploiting CVE-2026-76504, a 9.8-rated flaw that gives unauthenticated requests admin access to the Catalyst SD-WAN Manager API. Every configuration is affected, leaving exposed on-premises Managers needing an out-of-cycle upgrade and a check for earlier intrusion.

Perspective Coverage

12 publishers
Builder
Builder 14%
Operator
Operator 76%
Investor
Investor 10%

Reality

Evidence85
Adoption
Insufficient
Hype gap+10
Incentives40
Confidence80
build1 publisher

Attackers use a URI-encoding bug to run Cisco SD-WAN Manager's API as admin

Cisco says attackers are exploiting CVE-2026-76504, a 9.8 CVSS flaw that lets anyone reaching SD-WAN Manager's API act as admin with no credentials. Managers patched for the May and June flaws still need the new releases, because those fixes predate this one.

Publishers:dev.to

Reality

Evidence55
Adoption
Insufficient
Hype gap+5
Incentives
Insufficient
Confidence55
build1 publisher

Qilin ransomware affiliate logged into Cisco firewall management with a credential scored 5.3

Cisco Talos says three threat clusters are exploiting a CVSS 10.0 pre-auth root bypass and a 5.3 hard-coded credential in Secure Firewall Management Center. A patch policy with a severity cutoff above 5.3 would have skipped the credential fix on the console that pushes policy to every managed firewall.

Publishers:dev.to

Reality

Evidence58
Adoption
Insufficient
Hype gap0
Incentives
Insufficient
Confidence55
build1 publisher

Cisco email gateway flaw runs attacker SQL as root the moment it parses a message

CVE-2026-76461 lets a crafted email run SQL as root on Cisco Secure Email Gateway, with no workaround and a September 17 federal patch deadline from CISA. Because the trigger is mail parsing, every gateway in the mail path is in scope, whether or not it faces the internet.

Publishers:dev.to

Reality

Evidence55
Adoption
Insufficient
Hype gap0
Incentives
Insufficient
Confidence50
build1 publisher

CVE-2026-76441 lets unauthenticated attackers reach restricted functions on Cisco email gateways

CERT-In rates CVE-2026-76441 critical for letting unauthenticated remote attackers into restricted functions on Cisco email gateways 15.5 and earlier. The gateway inspects mail in both directions, so the fix belongs ahead of the next scheduled window, using the release Cisco's own advisory names.

Publishers:dev.to

Reality

Evidence45
Adoption
Insufficient
Hype gap+5
Incentives
Insufficient
Confidence50
product5 publishers

CrowdStrike and Fortinet co-sign a letter that dates the security tooling they sell

More than 100 companies signed a call for collective action on cyber defence whose first principle is that status quo security will not be enough, a sentence co-signed by five of the vendors who supply that status quo.

Perspective Coverage

5 publishers
Builder
Builder 33%
Operator
Operator 42%
Investor
Investor 25%

Reality

Evidence70
Adoption20
Hype gap+35
Incentives80
Confidence65
build1 publisher

Elttam's two-packet exploit runs code on TACACS+ servers before anyone logs in

Elttam says a TACACS+ server flaw lets attackers run code before login with two packets and an offline crack of the protocol's weak encryption. Of the two main server codebases, Shrubbery Networks' has a fix that still has no CVE and Facebook's archived fork will get none, so the first job is finding out which daemon answers on port 49.

Publishers:news.risky.biz

Reality

Evidence45
Adoption
Insufficient
Hype gap+20
Incentives35
Confidence40
security6 publishers

Fire Ant taught a Cisco IOS XR router to forward only log lines containing the word Health

Sygnia found the China-nexus group running packet captures, a tac_plus credential hook and two layers of log suppression on the gear that authenticates the rest of the estate, and it never established how the router was breached.

Perspective Coverage

6 publishers
Builder
Builder 33%
Operator
Operator 53%
Investor
Investor 14%

Reality

Evidence68
Adoption
Insufficient
Hype gap+25
Incentives55
Confidence64
security4 publishers

A default bind on ten Silicon One Nexus 9000 switches exposes root over ports 43210 and 43211

CVE-2026-20212 needs no credentials and returns root on ten Silicon One Nexus 9000 models. Cisco named no fixed release with the advisory. Remediation starts with a web lookup and an access list.

Perspective Coverage

4 publishers
Builder
Builder 15%
Operator
Operator 75%
Investor
Investor 10%

Reality

Evidence72
Adoption
Insufficient
Hype gap+15
Incentives
Insufficient
Confidence68

Earlier coverage

  1. A CVSS 10.0 Cisco FMC bypass tops the four flaws CISA moved into KEV

    Security · September 10, 2026 · 4 publishers

  2. Cisco's own July 23 log indicator predates its August date for FMC exploitation

    Security · September 9, 2026 · 6 publishers

  3. An Iran-linked actor built US Navy targeting handbooks from public data with Claude's help

    Invest · September 11, 2026 · 2 publishers

  4. Salt Typhoon logged into telecom network gear with stolen credentials in all but one case Talos examined

    Security · September 25, 2026 · 1 publisher

  5. ElevenLabs' CEO will squeeze margins for share in a voice market he expects to even out

    Product · September 24, 2026 · 1 publisher

  6. Cisco and Zoom executives challenge containment rate at AI contact center summit

    Product · September 23, 2026 · 1 publisher

  7. Eclypsium finds the month's exploited infrastructure flaws again in the management consoles

    Security · September 23, 2026 · 1 publisher

  8. Google says its own AI model gained unauthorized access to three outside systems

    Security · September 22, 2026 · 1 publisher

  9. Chainguard's CVE authority will give scanners version ranges for flaws fixed years ago

    Build · September 22, 2026 · 1 publisher

  10. Vast Data hands banks and model vendors separate keys to the same GPU enclave

    Product · September 22, 2026 · 1 publisher

  11. Attackers are bypassing authentication on Cisco ISE with a crafted API request

    Security · September 21, 2026 · 1 publisher

  12. A crafted HTTP request runs as root on the console that pushes every Cisco firewall's policy

    Build · September 20, 2026 · 1 publisher

  13. Eight security incumbents bought their AI security stories for about $250m each

    Invest · September 20, 2026 · 1 publisher

  14. Attackers hit Cisco's email gateway with a SQL injection zero-day before the patch shipped

    Security · September 20, 2026 · 1 publisher

  15. A crafted request to one Cisco ISE API endpoint reaches root without a credential

    Build · September 19, 2026 · 2 publishers

  16. ZoomEye's fingerprint for Cisco's exploited FMC bypass returned zero hosts

    Build · September 19, 2026 · 1 publisher

  17. Cisco patches an ISE authentication bypass attackers used before the fix existed

    Security · September 16, 2026 · 16 publishers

  18. Three intrusion clusters reached the same Cisco console through one CVSS 10.0 bypass

    Build · September 18, 2026 · 1 publisher

  19. A crafted HTTP request runs commands as root on unpatched Cisco ISE nodes

    Build · September 18, 2026 · 1 publisher

  20. Splunk open-sources a tool that prices AI coding sessions from local trace files

    Product · September 18, 2026 · 1 publisher

  21. A CVSS 10.0 bypass hands ISE admin access to anyone who can route to the REST API

    Build · September 17, 2026 · 1 publisher

  22. Non-tech employers account for the whole drop in San Francisco's mass layoffs

    Leadership · September 18, 2026 · 1 publisher

  23. Talos argues defenders are already behind the models they have

    Security · September 17, 2026 · 1 publisher

  24. Cisco Patches 44 CVEs Across ISE, FMC, Nexus Dashboard; Separately Warns of Exploited ISE Authentication Bypass Zero-Day

    Security · September 17, 2026 · 1 publisher

  25. Talos puts 78% of Japan's ransomware victims under JPY 1 billion in capital

    Security · September 17, 2026 · 1 publisher

  26. Splunk's year-end join of observability and security data requires customers to own both products

    Product · September 16, 2026 · 1 publisher

  27. A signed UEFI shell can disable the Secure Boot that trusted it

    Security · September 16, 2026 · 1 publisher

  28. Splunk is putting a log-trained LLM on Hugging Face under an open source license

    Product · September 16, 2026 · 1 publisher

  29. Cisco has already contacted Secure Email Cloud customers where it found compromise indicators

    Security · September 16, 2026 · 1 publisher

  30. Cisco's remediation path for a suspect virtual email gateway starts with a new VM

    Build · September 16, 2026 · 1 publisher

  31. Intel's CEO puts the fix for customers' 95% reliance on TSMC on the customers who chose it

    Invest · September 15, 2026 · 1 publisher

  32. Splunk federates search into Snowflake and Databricks to cut costs of data duplication

    Product · September 15, 2026 · 1 publisher

  33. A crafted email is already getting root on unpatched Cisco Secure Email Gateways

    Security · September 15, 2026 · 1 publisher

  34. Huang answers AI-safety calls with an audit regime the model labs would pay for

    Invest · September 15, 2026 · 1 publisher

  35. A process created at boot lets one HTTP request take root on Cisco's firewall console

    Build · September 14, 2026 · 1 publisher

  36. Analysts closing theCUBE's contact center summit make resolution quality the ROI number

    Product · September 14, 2026 · 1 publisher

  37. Cornelis wants the network to finish the AllReduce before data reaches the GPU

    Product · September 14, 2026 · 2 publishers

  38. Anthropic banned an account that chained Claude into an automated Navy targeting pipeline

    Product · September 12, 2026 · 1 publisher

  39. theCUBE Research's Laliberte ties contact center AI payback to knowledge management gaps

    Product · September 11, 2026 · 1 publisher

  40. Cyclops Blink resurfaces on Cisco firewall managers as portable x86-64 Linux malware

    Security · September 11, 2026 · 1 publisher