Feed aggregator
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Certificate Authentication Denial of Service Vulnerability
A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2) for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly.
This vulnerability is due to a logic error during the certificate authentication phase of the IKEv2 connection setup. An attacker could exploit this vulnerability by attempting to establish an IKEv2 VPN connection with a crafted certificate. A successful exploit could allow the attacker to cause the IKEv2 process to crash, causing a denial of service (DoS) condition.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ikev2cert-dos-uWyc2xtv
This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026.
<br/>Security Impact Rating: High <br/>CVE: CVE-2026-20249Cisco Identity Services Engine SQL and HQL Injection Vulnerabilities
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct SQL or HQL injection attacks on an affected device.
These vulnerabilities are due to insufficient validation of user-supplied input to the affected APIs before it is used to build database queries. An attacker could exploit these vulnerabilities by sending a crafted request to an affected device. A successful exploit could allow the attacker to execute arbitrary SQL or HQL queries against the underlying database, which could allow the attacker to view or modify data that they are not authorized to access. To exploit these vulnerabilities, the attacker must have valid administrative credentials.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multisql-inject-JnHK54Rq
This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Identity Services Engine, see Cisco Identity Services Engine Security Hardening Release: September 2026.
<br/>Security Impact Rating: Medium <br/>CVE: CVE-2026-76448,CVE-2026-76449,CVE-2026-76450,CVE-2026-76451Cisco Identity Services Engine SQL Injection Vulnerabilities
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow a remote attacker to conduct SQL injection attacks on an affected device.
For more information about these vulnerabilities, see the Details section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-sql-inj-3QTKR947
This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Identity Services Engine, see Cisco Identity Services Engine Security Hardening Release: September 2026.
<br/>Security Impact Rating: High <br/>CVE: CVE-2026-20247,CVE-2026-20300Cisco Secure Firewall Management Center Software sftunnel Root Arbitrary Code Execution Vulnerability
A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands as root.
This vulnerability exists because a registered sftunnel peer has incorrect permissions to write an arbitrary file to any location on the device. An attacker could exploit this vulnerability by hijacking the sftunnel communication connection or being a valid registered sftunnel peer and sending an sftunnel command to write a malicious file to the disk of an affected device. A successful exploit could allow the attacker to write a file to the device that is executed with root privileges. To exploit this vulnerability, the attacker must have valid user credentials on the affected device.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-sftunn-codex-c3O4Jft2
This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026.
<br/>Security Impact Rating: Critical <br/>CVE: CVE-2026-20324Cisco Identity Services Engine Information Disclosure Vulnerability
A vulnerability in the API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.
This vulnerability is due to insufficient validation of user-supplied parameters in API requests. An attacker could exploit this vulnerability by sending a crafted API request to an affected device. A successful exploit could allow the attacker to gain access to sensitive information, including hashed credentials that could be used in future attacks.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-inf-disc-LFWvcCu
This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Identity Services Engine, see Cisco Identity Services Engine Security Hardening Release: September 2026.
<br/>Security Impact Rating: Medium <br/>CVE: CVE-2026-20235C++26: Trivial infinite loops are no longer undefined behaviour
Article URL: https://www.sandordargo.com/blog/2026/09/16/cpp26-trivial-infinite-loops
Comments URL: https://news.ycombinator.com/item?id=49731789
Points: 1
# Comments: 0
Open Letter to Sir Paul Nurse, President of the Royal Society
Article URL: https://docs.google.com/document/d/1-xOkPeHmDEdRigT2YcP2nLfTB56yOn4FFbBfVUIXCUE/edit?usp=sharing
Comments URL: https://news.ycombinator.com/item?id=49731759
Points: 2
# Comments: 0
Convert Your Chatbot's Markdown to Discord-Complaint Markdown
Article URL: https://markdowntodiscord.com/
Comments URL: https://news.ycombinator.com/item?id=49731730
Points: 1
# Comments: 0
Flet 1.0 released: build desktop, mobile, and web apps in Python
Article URL: https://flet.dev/
Comments URL: https://news.ycombinator.com/item?id=49731717
Points: 1
# Comments: 1
The ZSA Backpack
Article URL: https://newsletters.feedbinusercontent.com/a07/a07862e8dacd093181d102b11d642f1ce4119ed2.html
Comments URL: https://news.ycombinator.com/item?id=49731712
Points: 2
# Comments: 0
You can now play doom directly from Proton Drive
Article URL: https://drive.proton.me/urls/ES5MR2XFYW#3vheWMKe4eAv
Comments URL: https://news.ycombinator.com/item?id=49731700
Points: 1
# Comments: 1
Why AI's Biggest Rivals Are Suddenly Calling for Restraint
Article URL: https://www.cfr.org/articles/why-ais-biggest-rivals-are-suddenly-calling-for-restraint
Comments URL: https://news.ycombinator.com/item?id=49731686
Points: 1
# Comments: 0
AI Doomsaying Is an Aggressive Sales Pitch
Article URL: https://jacobin.com/2026/09/openai-anthropic-human-extinction-criti-hype
Comments URL: https://news.ycombinator.com/item?id=49731679
Points: 1
# Comments: 0
PriFi and the Incomplete Institution: Securing the Transaction Supply Chain
Article URL: https://blog.logos.co/article/pri-fi-securing-transaction-supply-chain
Comments URL: https://news.ycombinator.com/item?id=49731675
Points: 1
# Comments: 0
I rated every track on 445 albums using public data, then built a game on it
Article URL: https://debutle.com/
Comments URL: https://news.ycombinator.com/item?id=49731647
Points: 1
# Comments: 0
A Top Law Firm Went from Standing Up to Trump to Bending the Knee
Article URL: https://www.nytimes.com/2026/08/02/us/politics/paul-weiss-trump.html
Comments URL: https://news.ycombinator.com/item?id=49731633
Points: 2
# Comments: 0
Cortex: An open-source L1 memory and state layer for autonomous AI agents
Article URL: https://github.com/cortex-protocol/cortex-protocol
Comments URL: https://news.ycombinator.com/item?id=49731631
Points: 1
# Comments: 0
How good are frontier models at physics?
Article URL: https://arxiv.org/abs/2609.13009
Comments URL: https://news.ycombinator.com/item?id=49731620
Points: 8
# Comments: 1
Vortex: One Format for Any Shape
Article URL: https://spiraldb.com/blog/vortex-one-format-for-any-shape
Comments URL: https://news.ycombinator.com/item?id=49731613
Points: 4
# Comments: 1
Neurogrid Terminal Coding Agent
Article URL: https://github.com/NeuroGrid-AI-exchange/neurogrid-tui
Comments URL: https://news.ycombinator.com/item?id=49731563
Points: 2
# Comments: 0
