<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — Cisco</title><description>Vulnerabilities in Cisco IOS XE, ASA, and other network infrastructure — the gear that, when compromised, hands attackers the keys to entire networks. Combined article + CVE feed for the Cisco beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>CVE-2004-1464 — Cisco IOS Denial-of-Service Vulnerability</title><link>https://0daynews.com/cve/cve-2004-1464/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2004-1464/</guid><description>Cisco IOS contains an unspecified vulnerability that may block further telnet, reverse telnet, Remote Shell (RSH), Secure Shell (SSH), and in some cases, Hypertext Transport Protocol (HTTP) access to the Cisco device.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>medium</category><category>cve</category></item><item><title>CVE-2008-4128 — Cisco IOS 12.4 HTTP admin CSRF on the 871 Integrated Services Router</title><link>https://0daynews.com/cve/cve-2008-4128/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2008-4128/</guid><description>Multiple CSRF flaws in the HTTP admin component of Cisco IOS 12.4 (on the 871 ISR) allow remote command execution via crafted /level/15/exec/ requests. Added to CISA KEV 2026-07-13.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>medium</category><category>cve</category></item><item><title>CVE-2009-2055 — Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability</title><link>https://0daynews.com/cve/cve-2009-2055/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2009-2055/</guid><description>Cisco IOS XR,when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>medium</category><category>cve</category></item><item><title>CVE-2010-3035 — Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability</title><link>https://0daynews.com/cve/cve-2010-3035/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2010-3035/</guid><description>Cisco IOS XR, when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2014-2120 — Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability</title><link>https://0daynews.com/cve/cve-2014-2120/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2014-2120/</guid><description>Cisco Adaptive Security Appliance (ASA) contains a cross-site scripting (XSS) vulnerability in the WebVPN login page. This vulnerability allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>medium</category><category>cve</category></item><item><title>CVE-2015-0666 — Cisco Prime Data Center Network Manager (DCNM) Directory Traversal Vulnerability</title><link>https://0daynews.com/cve/cve-2015-0666/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2015-0666/</guid><description>Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) allows remote attackers to read arbitrary files.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2016-6366 — Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability</title><link>https://0daynews.com/cve/cve-2016-6366/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-6366/</guid><description>A buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) code of Cisco ASA software could allow an attacker to cause a reload of the affected system or to remotely execute code.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2016-6367 — Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2016-6367/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-6367/</guid><description>A vulnerability in the command-line interface (CLI) parser of Cisco ASA software could allow an authenticated, local attacker to create a denial-of-service (DoS) condition or potentially execute code.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2016-6415 — Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability</title><link>https://0daynews.com/cve/cve-2016-6415/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2016-6415/</guid><description>Cisco IOS, IOS XR, and IOS XE contain insufficient condition checks in the part of the code that handles Internet Key Exchange version 1 (IKEv1) security negotiation requests. contains an information disclosure vulnerability in the Internet Key Exchange version 1 (IKEv1) that could allow an attacker to retrieve memory contents. Successful exploitation could allow the attacker to retrieve memory contents, which can lead to information disclosure.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2017-12231 — Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability</title><link>https://0daynews.com/cve/cve-2017-12231/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-12231/</guid><description>A vulnerability in the implementation of Network Address Translation (NAT) functionality in Cisco IOS could allow an unauthenticated, remote attacker to cause a denial of service.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2017-12232 — Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability</title><link>https://0daynews.com/cve/cve-2017-12232/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-12232/</guid><description>A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>medium</category><category>cve</category></item><item><title>CVE-2017-12233 — Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability</title><link>https://0daynews.com/cve/cve-2017-12233/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-12233/</guid><description>There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2017-12234 — Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability</title><link>https://0daynews.com/cve/cve-2017-12234/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-12234/</guid><description>There is a vulnerability in the implementation of the Common Industrial Protocol (CIP) feature in Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2017-12235 — Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability</title><link>https://0daynews.com/cve/cve-2017-12235/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-12235/</guid><description>A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2017-12237 — Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability</title><link>https://0daynews.com/cve/cve-2017-12237/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-12237/</guid><description>A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS and Cisco IOS XE could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a reload of an affected device that leads to a denial of service.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2017-12238 — Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability</title><link>https://0daynews.com/cve/cve-2017-12238/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-12238/</guid><description>A vulnerability in the Virtual Private LAN Service (VPLS) code of Cisco IOS for Cisco Catalyst 6800 Series Switches could allow an unauthenticated, adjacent attacker to cause a denial of service.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>medium</category><category>cve</category></item><item><title>CVE-2017-12240 — Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2017-12240/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-12240/</guid><description>The Dynamic Host Configuration Protocol (DHCP) relay subsystem of Cisco IOS and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>critical</category><category>cve</category></item><item><title>CVE-2017-12319 — Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability</title><link>https://0daynews.com/cve/cve-2017-12319/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-12319/</guid><description>A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or potentially corrupt the BGP routing table, which could result in network instability.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>medium</category><category>cve</category></item><item><title>CVE-2017-3881 — Cisco IOS and IOS XE Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2017-3881/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-3881/</guid><description>A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>critical</category><category>cve</category></item><item><title>CVE-2017-6627 — Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability</title><link>https://0daynews.com/cve/cve-2017-6627/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-6627/</guid><description>A vulnerability in the UDP processing code of Cisco IOS and IOS XE could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP packets, causing an interface queue wedge and denial of service.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2017-6663 — Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability</title><link>https://0daynews.com/cve/cve-2017-6663/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-6663/</guid><description>A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in denial-of-service (DoS).</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>medium</category><category>cve</category></item><item><title>CVE-2017-6736 — Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2017-6736/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-6736/</guid><description>The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2017-6737 — Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2017-6737/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-6737/</guid><description>The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2017-6738 — Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2017-6738/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-6738/</guid><description>The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2017-6739 — Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2017-6739/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-6739/</guid><description>The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2017-6740 — Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2017-6740/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-6740/</guid><description>The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2017-6742 — Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2017-6742/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-6742/</guid><description>The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2017-6743 — Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2017-6743/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-6743/</guid><description>The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2017-6744 — Cisco IOS Software SNMP Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2017-6744/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2017-6744/</guid><description>The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS 1 contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2018-0125 — Cisco VPN Routers Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2018-0125/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-0125/</guid><description>A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full control of an affected system.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>critical</category><category>cve</category></item><item><title>CVE-2018-0147 — Cisco Secure Access Control System Java Deserialization Vulnerability</title><link>https://0daynews.com/cve/cve-2018-0147/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-0147/</guid><description>A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>critical</category><category>cve</category></item><item><title>CVE-2018-0151 — Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2018-0151/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-0151/</guid><description>A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>critical</category><category>cve</category></item><item><title>CVE-2018-0154 — Cisco IOS Software Integrated Services Module for VPN Denial-of-Service Vulnerability</title><link>https://0daynews.com/cve/cve-2018-0154/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-0154/</guid><description>A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2018-0155 — Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service Vulnerability</title><link>https://0daynews.com/cve/cve-2018-0155/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-0155/</guid><description>A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches could allow an unauthenticated, remote attacker to cause a crash of the iosd process, causing a denial-of-service (DoS) condition.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2018-0156 — Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability</title><link>https://0daynews.com/cve/cve-2018-0156/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-0156/</guid><description>A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial-of-service (DoS) condition.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2018-0158 — Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability</title><link>https://0daynews.com/cve/cve-2018-0158/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-0158/</guid><description>A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial-of-service (DoS) condition.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2018-0159 — Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability</title><link>https://0daynews.com/cve/cve-2018-0159/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-0159/</guid><description>A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial-of-service (DoS) condition.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2018-0161 — Cisco IOS Software Resource Management Errors Vulnerability</title><link>https://0daynews.com/cve/cve-2018-0161/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-0161/</guid><description>A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to cause a denial-of-service (DoS) condition.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>medium</category><category>cve</category></item><item><title>CVE-2018-0167 — Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability</title><link>https://0daynews.com/cve/cve-2018-0167/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-0167/</guid><description>There is a buffer overflow vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software which could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2018-0171 — Cisco Smart Install unauthenticated RCE in IOS and IOS XE</title><link>https://0daynews.com/cve/cve-2018-0171/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-0171/</guid><description>Unauthenticated remote code execution in the Cisco Smart Install client on IOS and IOS XE. Patched by Cisco in March 2018 and still the primary access vector FSB Centre 16 uses against edge routers on critical-infrastructure networks per a July 2026 joint advisory.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>critical</category><category>cve</category></item><item><title>CVE-2018-0172 — Cisco IOS and IOS XE Software Improper Input Validation Vulnerability</title><link>https://0daynews.com/cve/cve-2018-0172/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-0172/</guid><description>A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS).</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2018-0173 — Cisco IOS and IOS XE Software Improper Input Validation Vulnerability</title><link>https://0daynews.com/cve/cve-2018-0173/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-0173/</guid><description>A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Version 4 (DHCPv4) packets can allow for denial-of-service (DoS).</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2018-0174 — Cisco IOS Software and Cisco IOS XE Software Improper Input Validation Vulnerability</title><link>https://0daynews.com/cve/cve-2018-0174/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-0174/</guid><description>A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow for denial-of-service (DoS).</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2018-0175 — Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability</title><link>https://0daynews.com/cve/cve-2018-0175/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-0175/</guid><description>Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2018-0179 — Cisco IOS Software Denial-of-Service Vulnerability</title><link>https://0daynews.com/cve/cve-2018-0179/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-0179/</guid><description>A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>medium</category><category>cve</category></item><item><title>CVE-2018-0180 — Cisco IOS Software Denial-of-Service Vulnerability</title><link>https://0daynews.com/cve/cve-2018-0180/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-0180/</guid><description>A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>medium</category><category>cve</category></item><item><title>CVE-2018-0296 — Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability</title><link>https://0daynews.com/cve/cve-2018-0296/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-0296/</guid><description>Cisco Adaptive Security Appliance (ASA) contains an improper input validation vulnerability with HTTP URLs. Exploitation could allow an attacker to cause a denial-of-service (DoS) condition or information disclosure.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2019-15271 — Cisco RV Series Routers Deserialization of Untrusted Data Vulnerability</title><link>https://0daynews.com/cve/cve-2019-15271/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-15271/</guid><description>A deserialization of untrusted data vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an attacker to execute code with root privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2019-1652 — Cisco Small Business Routers Improper Input Validation Vulnerability</title><link>https://0daynews.com/cve/cve-2019-1652/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-1652/</guid><description>A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2019-1653 — Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability</title><link>https://0daynews.com/cve/cve-2019-1653/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2019-1653/</guid><description>Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers contain improper access controls for URLs. Exploitation could allow an attacker to download the router configuration or detailed diagnostic information.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2020-3118 — Cisco IOS XR Software Discovery Protocol Format String Vulnerability</title><link>https://0daynews.com/cve/cve-2020-3118/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-3118/</guid><description>Cisco IOS XR improperly validates string input from certain fields in Cisco Discovery Protocol messages. Exploitation could allow an unauthenticated, adjacent attacker to execute code with administrative privileges or cause a reload on an affected device.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2020-3153 — Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability</title><link>https://0daynews.com/cve/cve-2020-3153/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-3153/</guid><description>Cisco AnyConnect Secure Mobility Client for Windows allows for incorrect handling of directory paths. An attacker with valid credentials on Windows would be able to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>medium</category><category>cve</category></item><item><title>CVE-2020-3161 — Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability</title><link>https://0daynews.com/cve/cve-2020-3161/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-3161/</guid><description>Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root privileges or cause a denial-of-service (DoS) condition.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>critical</category><category>cve</category></item><item><title>CVE-2020-3259 — Cisco ASA and FTD Information Disclosure Vulnerability</title><link>https://0daynews.com/cve/cve-2020-3259/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-3259/</guid><description>Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which could lead to the disclosure of confidential information due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. This vulnerability affects only specific AnyConnect and WebVPN configurations.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2020-3433 — Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability</title><link>https://0daynews.com/cve/cve-2020-3433/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-3433/</guid><description>Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by the application at run time. An attacker with valid credentials on Windows could execute code on the affected machine with SYSTEM privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2020-3452 — Cisco ASA and FTD Read-Only Path Traversal Vulnerability</title><link>https://0daynews.com/cve/cve-2020-3452/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-3452/</guid><description>Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an improper input validation vulnerability when HTTP requests process URLs.  An attacker could exploit this vulnerability by sending a crafted HTTP request containing directory traversal character sequences to an affected device. A successful exploit could allow the attacker to view arbitrary files within the web services file system on the targeted device.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2020-3566 — Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability</title><link>https://0daynews.com/cve/cve-2020-3566/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-3566/</guid><description>Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2020-3569 — Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability</title><link>https://0daynews.com/cve/cve-2020-3569/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-3569/</guid><description>Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2020-3580 — Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability</title><link>https://0daynews.com/cve/cve-2020-3580/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2020-3580/</guid><description>Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface.  Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive browser-based information.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>medium</category><category>cve</category></item><item><title>CVE-2021-1497 — Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2021-1497/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-1497/</guid><description>Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the root user.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>critical</category><category>cve</category></item><item><title>CVE-2021-1498 — Cisco HyperFlex HX Data Platform Command Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2021-1498/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-1498/</guid><description>Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the tomcat8 user.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>critical</category><category>cve</category></item><item><title>CVE-2022-20699 — Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability</title><link>https://0daynews.com/cve/cve-2022-20699/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-20699/</guid><description>A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>critical</category><category>cve</category></item><item><title>CVE-2022-20700 — Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability</title><link>https://0daynews.com/cve/cve-2022-20700/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-20700/</guid><description>A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>critical</category><category>cve</category></item><item><title>CVE-2022-20701 — Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability</title><link>https://0daynews.com/cve/cve-2022-20701/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-20701/</guid><description>A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>critical</category><category>cve</category></item><item><title>CVE-2022-20703 — Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability</title><link>https://0daynews.com/cve/cve-2022-20703/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-20703/</guid><description>A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>critical</category><category>cve</category></item><item><title>CVE-2022-20708 — Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability</title><link>https://0daynews.com/cve/cve-2022-20708/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-20708/</guid><description>A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS).</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>critical</category><category>cve</category></item><item><title>CVE-2022-20775 — Cisco SD-WAN Path Traversal Vulnerability</title><link>https://0daynews.com/cve/cve-2022-20775/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-20775/</guid><description>Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain elevated privileges via improper access controls on commands within the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2022-20821 — Cisco IOS XR Open Port Vulnerability</title><link>https://0daynews.com/cve/cve-2022-20821/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-20821/</guid><description>Cisco IOS XR software health check opens TCP port 6379 by default on activation. An attacker can connect to the Redis instance on the open port and allow access to the Redis instance that is running within the NOSi container.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>medium</category><category>cve</category></item><item><title>CVE-2023-20109 — Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability</title><link>https://0daynews.com/cve/cve-2023-20109/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-20109/</guid><description>Cisco IOS and IOS XE contain an out-of-bounds write vulnerability in the Group Encrypted Transport VPN (GET VPN) feature that could allow an authenticated, remote attacker who has administrative control of either a group member or a key server to execute malicious code or cause a device to crash.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>medium</category><category>cve</category></item><item><title>CVE-2023-20118 — Cisco Small Business RV Series Routers Command Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2023-20118/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-20118/</guid><description>Multiple Cisco Small Business RV Series Routers contains a command injection vulnerability in the web-based management interface. Successful exploitation could allow an authenticated, remote attacker to gain root-level privileges and access unauthorized data.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>medium</category><category>cve</category></item><item><title>CVE-2023-20198 — Cisco IOS XE Web UI Privilege Escalation Zero-Day</title><link>https://0daynews.com/cve/cve-2023-20198/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-20198/</guid><description>A privilege-escalation vulnerability in the Web UI feature of Cisco IOS XE Software allows a remote, unauthenticated attacker to create an account with privilege level 15 (full admin) access, enabling full device takeover. Exploited at mass scale against tens of thousands of devices.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>critical</category><category>cve</category></item><item><title>CVE-2023-20269 — Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability</title><link>https://0daynews.com/cve/cve-2023-20269/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-20269/</guid><description>Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>medium</category><category>cve</category></item><item><title>CVE-2023-20273 — Cisco IOS XE Web UI Command Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2023-20273/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-20273/</guid><description>Cisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198, the attacker can leverage the new local user to elevate privilege to root and write the implant to the file system. Cisco identified CVE-2023-20273 as the vulnerability exploited to deploy the implant. CVE-2021-1435, previously associated with the exploitation events, is no longer believed to be related to this activity.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2024-20353 — Cisco ASA and FTD Denial of Service Vulnerability</title><link>https://0daynews.com/cve/cve-2024-20353/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-20353/</guid><description>Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an infinite loop vulnerability that can lead to remote denial of service condition.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2024-20359 — Cisco ASA and FTD Privilege Escalation Vulnerability</title><link>https://0daynews.com/cve/cve-2024-20359/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-20359/</guid><description>Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a privilege escalation vulnerability that can allow local privilege escalation from Administrator to root.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>medium</category><category>cve</category></item><item><title>CVE-2024-20399 — Cisco NX-OS Command Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2024-20399/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-20399/</guid><description>Cisco NX-OS contains a command injection vulnerability in the command line interface (CLI) that could allow an authenticated, local attacker to execute commands as root on the underlying operating system of an affected device.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>medium</category><category>cve</category></item><item><title>CVE-2024-20439 — Cisco Smart Licensing Utility Static Credential Vulnerability</title><link>https://0daynews.com/cve/cve-2024-20439/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-20439/</guid><description>Cisco Smart Licensing Utility contains a static credential vulnerability that allows an unauthenticated, remote attacker to log in to an affected system and gain administrative credentials.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>critical</category><category>cve</category></item><item><title>CVE-2024-20481 — Cisco ASA and FTD Denial-of-Service Vulnerability</title><link>https://0daynews.com/cve/cve-2024-20481/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2024-20481/</guid><description>Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a missing release of resource after effective lifetime vulnerability that could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) of the RAVPN service.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>medium</category><category>cve</category></item><item><title>CVE-2025-20281 — Cisco Identity Services Engine Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2025-20281/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-20281/</guid><description>Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>critical</category><category>cve</category></item><item><title>CVE-2025-20333 — Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability</title><link>https://0daynews.com/cve/cve-2025-20333/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-20333/</guid><description>Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a buffer overflow vulnerability that allows for remote code execution. This vulnerability could be chained with CVE-2025-20362.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>critical</category><category>cve</category></item><item><title>CVE-2025-20337 — Cisco Identity Services Engine Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2025-20337/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-20337/</guid><description>Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>critical</category><category>cve</category></item><item><title>CVE-2025-20352 — Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability</title><link>https://0daynews.com/cve/cve-2025-20352/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-20352/</guid><description>Cisco IOS and IOS XE contains a stack-based buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) subsystem that could allow for denial of service or remote code execution. A successful exploit could allow a low-privileged attacker to cause the affected system to reload, resulting in a DoS condition, or allow a high-privileged attacker to execute arbitrary code as the root user and obtain full control of the affected system.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2025-20362 — Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability</title><link>https://0daynews.com/cve/cve-2025-20362/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-20362/</guid><description>Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a missing authorization vulnerability. This vulnerability could be chained with CVE-2025-20333.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>medium</category><category>cve</category></item><item><title>CVE-2025-20393 — Cisco Multiple Products Improper Input Validation Vulnerability</title><link>https://0daynews.com/cve/cve-2025-20393/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-20393/</guid><description>Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability that allows threat actors to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-20045 — Cisco Unified Communications Products Code Injection Vulnerability</title><link>https://0daynews.com/cve/cve-2026-20045/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-20045/</guid><description>Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM &amp; Presence Service (Unified CM IM&amp;P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance contain a code injection vulnerability that could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2026-20122 — Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability</title><link>https://0daynews.com/cve/cve-2026-20122/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-20122/</guid><description>Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>medium</category><category>cve</category></item><item><title>CVE-2026-20127 — Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2026-20127/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-20127/</guid><description>Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypass vulnerability could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-20128 — Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability</title><link>https://0daynews.com/cve/cve-2026-20128/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-20128/</guid><description>Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file for the DCA user on the filesystem as a low-privileged user.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2026-20131 — Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability</title><link>https://0daynews.com/cve/cve-2026-20131/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-20131/</guid><description>Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-20133 — Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability</title><link>https://0daynews.com/cve/cve-2026-20133/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-20133/</guid><description>Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>medium</category><category>cve</category></item><item><title>CVE-2026-20182 — Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability</title><link>https://0daynews.com/cve/cve-2026-20182/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-20182/</guid><description>Cisco Catalyst SD-WAN Controller &amp; Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-20230 — Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability</title><link>https://0daynews.com/cve/cve-2026-20230/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-20230/</guid><description>Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2026-20245 — Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability</title><link>https://0daynews.com/cve/cve-2026-20245/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-20245/</guid><description>Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>CVE-2026-20262 — Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability</title><link>https://0daynews.com/cve/cve-2026-20262/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-20262/</guid><description>Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>medium</category><category>cve</category></item><item><title>CVE-2026-20316 — Hard-coded credential in Cisco Secure FMC enables unauthenticated login</title><link>https://0daynews.com/cve/cve-2026-20316/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-20316/</guid><description>Cisco Secure FMC ships a static low-privileged account; remote unauthenticated attackers can log in and access sensitive data. CISA KEV confirmed July 29, 2026.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>medium</category><category>cve</category></item><item><title>CVE-2026-20349 — Cisco ASA and FTD VPN Heap Inspection Denial-of-Service Flaw</title><link>https://0daynews.com/cve/cve-2026-20349/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-20349/</guid><description>Unauthenticated remote attackers can crash Cisco Secure Firewall ASA and FTD devices over VPN. Added to CISA KEV on 2026-08-11 with a three-day federal remediation deadline.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>Cisco</category><category>high</category><category>cve</category></item><item><title>Cisco ASA/FTD VPN Flaw Exploited, CISA Sets Aug 14 Deadline</title><link>https://0daynews.com/articles/2026-08-11-cisco-asa-ftd-cve-2026-20349-kev-dos-vpn/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-11-cisco-asa-ftd-cve-2026-20349-kev-dos-vpn/</guid><description>CVE-2026-20349 added to CISA KEV today. Unauthenticated attackers can crash Cisco ASA and FTD devices over VPN — CISA&apos;s due date is August 14.</description><pubDate>Tue, 11 Aug 2026 22:00:00 GMT</pubDate><category>Cisco</category><category>article</category></item><item><title>CISA KEV: Cisco FMC Hard-Coded Password Now Exploited</title><link>https://0daynews.com/articles/2026-07-29-cisco-fmc-cve-2026-20316-kev-hardcoded-credential/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-29-cisco-fmc-cve-2026-20316-kev-hardcoded-credential/</guid><description>CISA added CVE-2026-20316 to its KEV catalog. Cisco Secure FMC carries a hardcoded credential—medium CVSS, High by Cisco&apos;s own rating, now confirmed exploited.</description><pubDate>Wed, 29 Jul 2026 21:00:00 GMT</pubDate><category>Cisco</category><category>article</category></item><item><title>Cisco IOS 12.4 CSRF From 2008 Lands in CISA KEV</title><link>https://0daynews.com/articles/2026-07-13-cisa-kev-cve-2008-4128-cisco-ios-12-4-csrf/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-13-cisa-kev-cve-2008-4128-cisco-ios-12-4-csrf/</guid><description>CISA added CVE-2008-4128 — a Cisco IOS 12.4 mainline HTTP admin CSRF from 2008 — to the KEV catalog on 2026-07-13. IOS 12.4 mainline is obsolete. Upgrade.</description><pubDate>Mon, 13 Jul 2026 18:30:00 GMT</pubDate><category>Cisco</category><category>article</category></item><item><title>Cisco Confirms Active Exploitation of Unified CM Flaw</title><link>https://0daynews.com/articles/2026-07-03-cisco-unified-cm-active-exploitation-confirmed/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-03-cisco-unified-cm-active-exploitation-confirmed/</guid><description>Cisco updated its Unified Communications Manager advisory this week to state attackers are exploiting the flaw in the wild. Patched builds have been out for a month. If yours isn&apos;t on one, that&apos;s the whole conversation.</description><pubDate>Fri, 03 Jul 2026 19:15:00 GMT</pubDate><category>Cisco</category><category>article</category></item><item><title>Cisco IOS XE Web UI Zero-Day: Mass Exploitation</title><link>https://0daynews.com/articles/2026-06-24-cisco-ios-xe-web-ui-zero-day-mass-exploitation/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-06-24-cisco-ios-xe-web-ui-zero-day-mass-exploitation/</guid><description>CVE-2023-20198, a maximum-severity privilege-escalation flaw in Cisco IOS XE&apos;s web management interface, was exploited at mass scale before a patch existed — handing attackers full admin control of network infrastructure.</description><pubDate>Wed, 24 Jun 2026 13:00:00 GMT</pubDate><category>Cisco</category><category>article</category></item></channel></rss>