Advisories
Cisco PSIRTActive exploitation (sightings)HIGH2026-04-15
Cisco Identity Services Engine Remote Code Execution and Path Traversal Vulnerabilities
CVEs:CVE-2026-20147CVE-2026-20148
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-111903 |
affected |
Cisco |
— |
— |
| CVRFPID-292424 |
affected |
Cisco |
— |
— |
Cisco PSIRTActive exploitation (sightings)CRITICAL2026-04-15
Cisco Identity Services Engine Remote Code Execution Vulnerabilities
CVEs:CVE-2026-20180CVE-2026-20186
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-111903 |
affected |
Cisco |
— |
— |
Cisco PSIRTActive exploitation (sightings)HIGH2026-04-01
Cisco Integrated Management Controller Command Injection and Remote Code Execution Vulnerabilities
CVEs:CVE-2026-20094CVE-2026-20095CVE-2026-20096CVE-2026-20097
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-191638 |
affected |
Cisco |
— |
— |
| CVRFPID-201970 |
affected |
Cisco |
— |
— |
| CVRFPID-235874 |
affected |
Cisco |
— |
— |
Cisco PSIRTActive exploitation (sightings)CRITICAL2026-04-01
Cisco Integrated Management Controller Authentication Bypass Vulnerability
CVEs:CVE-2026-20093
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-191638 |
affected |
Cisco |
— |
— |
| CVRFPID-201970 |
affected |
Cisco |
— |
— |
| CVRFPID-235874 |
affected |
Cisco |
— |
— |
Cisco PSIRTActive exploitation (sightings)CRITICAL2026-04-01
Cisco Smart Software Manager On-Prem Arbitrary Command Execution Vulnerability
CVEs:CVE-2026-20160
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-274027 |
affected |
Cisco |
— |
— |
Cisco PSIRTActive exploitation (sightings)CRITICAL2026-04-15
Cisco Webex Services Certificate Validation Vulnerability
CVEs:CVE-2026-20184
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-228295 |
affected |
Cisco |
— |
— |
Cisco PSIRTActive exploitation (sightings)HIGH2026-04-15
Cisco Identity Services Engine Authenticated Privilege Escalation Vulnerability
CVEs:CVE-2026-20136
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-111903 |
affected |
Cisco |
— |
— |
Cisco PSIRTActive exploitation (sightings)HIGH2026-04-01
Cisco Nexus Dashboard Insights Arbitrary File Write Vulnerability
CVEs:CVE-2026-20174
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-280977 |
affected |
Cisco |
— |
— |
| CVRFPID-284336 |
affected |
Cisco |
— |
— |
Cisco PSIRTActive exploitation (sightings)HIGH2026-04-15
Cisco Unity Connection Arbitrary File Download Vulnerabilities
CVEs:CVE-2026-20078CVE-2026-20081
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-73608 |
affected |
Cisco |
— |
— |
Cisco PSIRTActive exploitation (sightings)HIGH2026-04-15
Cisco Secure Web Appliance Authentication Bypass Vulnerability
CVEs:CVE-2026-20152
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-189789 |
affected |
Cisco |
— |
— |
Cisco PSIRTActive exploitation (sightings)HIGH2026-04-01
Cisco Smart Software Manager On-Prem Privilege Escalation Vulnerability
CVEs:CVE-2026-20151
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-274027 |
affected |
Cisco |
— |
— |
Cisco PSIRTActive exploitation (sightings)HIGH2026-04-01
Cisco Evolved Programmable Network Manager Improper Authorization Vulnerability
CVEs:CVE-2026-20155
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-213688 |
affected |
Cisco |
— |
— |
Cisco PSIRTActive exploitation (sightings)HIGH2026-04-15
Cisco Unity Connection Cross-Site Scripting, Open Redirect, and SQL Injection Vulnerabilities
CVEs:CVE-2026-20059CVE-2026-20060CVE-2026-20061
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-73608 |
affected |
Cisco |
— |
— |
Cisco PSIRTActive exploitation (sightings)HIGH2026-04-15
Cisco Identity Services Engine Multiple Cross-Site Scripting Vulnerabilities
CVEs:CVE-2026-20132
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-111903 |
affected |
Cisco |
— |
— |
Cisco PSIRTActive exploitation (sightings)HIGH2026-04-15
Cisco ThousandEyes Enterprise Agent Arbitrary File Overwrite Vulnerability
CVEs:CVE-2026-20161
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-305280 |
affected |
Cisco |
— |
— |
Cisco PSIRTPoC exploitHIGH2026-04-01
Cisco Nexus Dashboard and Nexus Dashboard Insights Server-Side Request Forgery Vulnerability
CVEs:CVE-2026-20041
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-280977 |
affected |
Cisco |
— |
— |
| CVRFPID-284336 |
affected |
Cisco |
— |
— |
Cisco PSIRTCoalition ESS < 30%CRITICAL2026-04-01
Cisco Nexus Dashboard Configuration Backup REST API Unauthorized Access Vulnerability
CVEs:CVE-2026-20042
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-280977 |
affected |
Cisco |
— |
— |
Cisco PSIRTCoalition ESS < 30%HIGH2026-04-01
Cisco Integrated Management Controller Cross-Site Scripting Vulnerabilities
CVEs:CVE-2026-20087CVE-2026-20085CVE-2026-20088CVE-2026-20090CVE-2026-20089
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-191638 |
affected |
Cisco |
— |
— |
| CVRFPID-201970 |
affected |
Cisco |
— |
— |
| CVRFPID-235874 |
affected |
Cisco |
— |
— |
Cisco PSIRTCoalition ESS < 30%HIGH2026-04-15
Cisco Webex Contact Center Cross-Site Scripting Vulnerability
CVEs:CVE-2026-20170
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| CVRFPID-302888 |
affected |
Cisco |
— |
— |
Cisco PSIRTAll remainingCRITICAL2026-04-23
Continued Evolution of Persistence Mechanism Against Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense