Cisco Security Advisories

Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026

Mon, 09/14/2026 - 4:00pm

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.

These vulnerabilities were found during internal testing. One of them is known to be actively exploited. For more information, see Cisco Secure Email Gateway SQL Injection Vulnerability. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures identifier (CVE ID) to each CWE grouping.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm

<br/>Security Impact Rating: Critical <br/>CVE: CVE-2026-20353,CVE-2026-76440,CVE-2026-76441,CVE-2026-76442,CVE-2026-76443
Categories: Cisco

Cisco Secure Email Gateway SQL Injection Vulnerability

Mon, 09/14/2026 - 4:00pm

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.

This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX

<br/>Security Impact Rating: Critical <br/>CVE: CVE-2026-76461
Categories: Cisco

Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability

Wed, 09/09/2026 - 4:00pm

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. 

This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device. 

Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2

This advisory is part of the March 2026 release of the Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: March 2026 Semiannual Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication.

<br/>Security Impact Rating: Critical <br/>CVE: CVE-2026-20079
Categories: Cisco

Cisco Advance Notification for Publication of September 16, 2026, Security Advisories

Wed, 09/09/2026 - 4:00pm

On September 16, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products:

  • BroadWorks CommPilot Application Software 
  • Identity Services Engine (ISE) (security hardening release)
  • Nexus Dashboard (security hardening release)
  • Secure Firewall Adaptive Security Appliance (ASA) (security hardening release)
  • Secure Firewall Management Center (FMC) (security hardening release)
  • Secure FirewallThreat Defense (FTD) (security hardening release)
  • ThousandEyes Virtual Appliance

Note: All three Cisco Secure Firewall products will be included in the same security hardening release. For more information about Cisco Secure FMC Software, including recently disclosed vulnerabilities and their available fixes, see the Cisco Talos blog post.

To remediate vulnerabilities to be disclosed on September 16, 2026, Cisco strongly recommends that customers upgrade to the fixed software indicated in the advisories.

For more information about changes in Cisco PSIRT vulnerability disclosure, see Cisco's Transition to a Risk-Based Vulnerability Disclosure Model.

<br/>Security Impact Rating: Informational
Categories: Cisco

Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability

Tue, 09/08/2026 - 4:00pm

A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin or an unauthenticated attacker with physical access to an affected device to bypass UEFI Secure Boot validation checks and execute unauthorized software.

This vulnerability is due to the availability of memory write commands in the UEFI Shell while UEFI Secure Boot is enabled on a device. An attacker could exploit this vulnerability by selecting the UEFI Shell boot option at boot time and using available shell commands to modify UEFI memory variables. A successful exploit could allow the attacker to manipulate the preboot environment, overwrite UEFI Secure Boot-related memory values, and execute unauthorized software on the affected device.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucs-uefi-sb-bypass-eb6xC5GW

<br/>Security Impact Rating: High <br/>CVE: CVE-2026-20293
Categories: Cisco

Cisco IOS XR Software Security Hardening Release: September 2026

Wed, 09/02/2026 - 4:00pm

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.  

These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures identifier (CVE ID) to each CWE grouping.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM

<br/>Security Impact Rating: Critical <br/>CVE: CVE-2026-20274,CVE-2026-20275,CVE-2026-20276,CVE-2026-20277,CVE-2026-20278,CVE-2026-20279,CVE-2026-20280
Categories: Cisco

Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities

Wed, 09/02/2026 - 4:00pm

Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages.

These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication.

There are no workarounds that address these vulnerabilities.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-smime-disc-dzw4rEdY

<br/>Security Impact Rating: Medium <br/>CVE: CVE-2026-20354,CVE-2026-20355
Categories: Cisco

Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability

Wed, 09/02/2026 - 4:00pm

A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges.

This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device and send crafted input that could be executed as code with root privileges. The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload.

Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n9k-s1-rce-EH8dEtr

<br/>Security Impact Rating: Critical <br/>CVE: CVE-2026-20212
Categories: Cisco

Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability

Wed, 09/02/2026 - 4:00pm

A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session Initiation Protocol (SIP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

This vulnerability is due to improper memory management when an affected device processes HTTP packets. An attacker could exploit this vulnerability by sending a continuous stream of crafted HTTP packets to the device. A successful exploit could allow the attacker to cause the affected device to continuously consume memory, resulting in a DoS condition. A manual reboot of the device is required to recover from this condition.

Note: For this vulnerability to be exploitable, the phone must be registered to Cisco Unified Communications Manager (Unified CM) and have Web Access enabled. Web Access is disabled by default.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-phone-dos-txMYNRzv

<br/>Security Impact Rating: High <br/>CVE: CVE-2026-20281
Categories: Cisco

Cisco Advance Notification for Publication of September 2, 2026, Security Advisories

Wed, 08/26/2026 - 4:00pm

On September 2, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products:

  • Desk Phone 9800, 7800 and 8800, and 8875 Series Software
  • IOS XR Software (security hardening release)
  • Nexus 9000 Series Switches Silicon One
  • Secure Email 

To fully remediate vulnerabilities to be disclosed on September 2, 2026, Cisco strongly recommends that customers upgrade to the fixed software indicated in the advisories.

For more information about changes in Cisco PSIRT vulnerability disclosure, see Cisco's Transition to a Risk-Based Vulnerability Disclosure Model.

<br/>Security Impact Rating: Informational
Categories: Cisco

Cisco Advance Notification for Publication of August 19, 2026, Security Advisories

Wed, 08/19/2026 - 4:00pm

On August 19, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories:

Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco Crosswork Security Hardening Release: August 2026 CVE-2026-20030
CVE-2026-20357
CVE-2026-20358
CVE-2026-20359 Critical 10.0 Cisco Secure Workload Software Security Hardening Release: August 2026 CVE-2026-20231
CVE-2026-20315
CVE-2026-20317
CVE-2026-20318
CVE-2026-20319 Critical 10.0 Cisco BroadWorks Out-of-Band Blind XML External Entity Injection Vulnerability CVE-2026-20320 High 7.5 Cisco Unified Intelligence Center SQL Injection Vulnerability CVE-2026-20327 Medium 6.5 Cisco RoomOS Stack Overflow Vulnerability CVE-2026-20302 Medium 6.1 Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerability CVE-2026-20232 Medium 5.4 Cisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability CVE-2026-20177 Medium 5.3 Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Server-Side Request Forgery Vulnerability CVE-2026-20314 Medium 5.0

To fully remediate the vulnerabilities that were disclosed on August 19, 2026, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories.

For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the Foundation: A Predictable, Customer-Focused Response to AI-Accelerated Vulnerability Discovery.

<br/>Security Impact Rating: Informational
Categories: Cisco

Cisco Secure Workload Software Security Hardening Release: August 2026

Wed, 08/19/2026 - 4:00pm

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.

These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures Identifier (CVE ID) to each CWE grouping.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-csw1-shSvndWP

<br/>Security Impact Rating: Critical <br/>CVE: CVE-2026-20231,CVE-2026-20315,CVE-2026-20317,CVE-2026-20318,CVE-2026-20319
Categories: Cisco

Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerability

Wed, 08/19/2026 - 4:00pm

A vulnerability in the web-based management interface of Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface.

This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of another user. To exploit this vulnerability, the attacker must have valid user credentials on the affected system.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ie1k-NgXUFF52

<br/>Security Impact Rating: Medium <br/>CVE: CVE-2026-20232
Categories: Cisco

Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Server-Side Request Forgery Vulnerability

Wed, 08/19/2026 - 4:00pm

A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device.

This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to send arbitrary network requests that are sourced from the affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device. 

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucce-pcce-ssrf-TghHxD

<br/>Security Impact Rating: Medium <br/>CVE: CVE-2026-20314
Categories: Cisco

Cisco Unified Intelligence Center SQL Injection Vulnerability

Wed, 08/19/2026 - 4:00pm

A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, local attacker to perform a blind SQL injection attack against an affected device.

This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to read the contents of the internal database of an affected device. To exploit this vulnerability, the attacker must have valid user credentials on the affected device.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cuic-sql-inject-2qbfWSm5

<br/>Security Impact Rating: Medium <br/>CVE: CVE-2026-20327
Categories: Cisco

Cisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability

Wed, 08/19/2026 - 4:00pm

A vulnerability in the handling of management plane packets by Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an unauthenticated, remote attacker to cause the device manager, SSH, or API to become inaccessible.

This vulnerability is due to insufficient protection against management plane flooding attacks. An attacker could exploit this vulnerability by sending a high rate of ICMP, SSH, or HTTP traffic to an affected device. A successful exploit could allow the attacker to cause the CPU of the device to increase, resulting in a denial of service (DoS) condition on the device manager web GUI, SSH, or API. Data traffic through the device is not affected.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ie1k-uxq86Lnx

<br/>Security Impact Rating: Medium <br/>CVE: CVE-2026-20177
Categories: Cisco

Cisco RoomOS Stack Overflow Vulnerability

Wed, 08/19/2026 - 4:00pm

A vulnerability in the USB driver of Cisco RoomOS could allow an unauthenticated, local attacker with physical access to the USB port on an affected device to execute arbitrary code with root privileges.

This vulnerability is due to insufficient boundary checks for specific data that is provided through the USB driver. An attacker could exploit this vulnerability by connecting a malicious USB device to an affected device. A successful exploit could allow the attacker to cause a buffer overflow condition on the affected system and execute arbitrary code with root privileges.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-bof-vTMANZgu

<br/>Security Impact Rating: Medium <br/>CVE: CVE-2026-20302
Categories: Cisco

Cisco BroadWorks Out-of-Band Blind XML External Entity Injection Vulnerability

Wed, 08/19/2026 - 4:00pm

A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system.

This vulnerability exists because XML entries are improperly parsed due to external entity resolution being allowed by default. An attacker could exploit this vulnerability by sending a crafted XML message to the Open Client Interface – Provisioning (OCI-P) service. A successful exploit could allow the attacker to view sensitive files from the filesystem with the privileges of the Cisco BroadWorks user.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bworks-xxe-uwUd7CEt

<br/>Security Impact Rating: High <br/>CVE: CVE-2026-20320
Categories: Cisco

Cisco Crosswork Security Hardening Release: August 2026

Wed, 08/19/2026 - 4:00pm

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. 

These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures Identifier (CVE ID) to each CWE grouping.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. 

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-crosswork-UzDTU9Vh

<br/>Security Impact Rating: Critical <br/>CVE: CVE-2026-20030,CVE-2026-20357,CVE-2026-20358,CVE-2026-20359
Categories: Cisco