Cisco
Vulnerabilities in Cisco IOS XE, ASA, and other network infrastructure — the gear that, when compromised, hands attackers the keys to entire networks.
Cisco IOS XE Web UI Privilege Escalation Zero-Day
A privilege-escalation vulnerability in the Web UI feature of Cisco IOS XE Software allows a remote, unauthenticated attacker to create an account with privilege level 15 (full admin) access, enabling full device takeover. Exploited at mass scale against tens of thousands of devices.
Cisco Smart Install unauthenticated RCE in IOS and IOS XE
Unauthenticated remote code execution in the Cisco Smart Install client on IOS and IOS XE. Patched by Cisco in March 2018 and still the primary access vector FSB Centre 16 uses against edge routers on critical-infrastructure networks per a July 2026 joint advisory.
Cisco IOS 12.4 HTTP admin CSRF on the 871 Integrated Services Router
Multiple CSRF flaws in the HTTP admin component of Cisco IOS 12.4 (on the 871 ISR) allow remote command execution via crafted /level/15/exec/ requests. Added to CISA KEV 2026-07-13.

Cisco IOS 12.4 CSRF From 2008 Lands in CISA KEV
CISA added CVE-2008-4128 — a Cisco IOS 12.4 mainline HTTP admin CSRF from 2008 — to the KEV catalog on 2026-07-13. IOS 12.4 mainline is obsolete. Upgrade.

Cisco Confirms Active Exploitation of Unified CM Flaw
Cisco updated its Unified Communications Manager advisory this week to state attackers are exploiting the flaw in the wild. Patched builds have been out for a month. If yours isn't on one, that's the whole conversation.

Cisco IOS XE Web UI Zero-Day: Mass Exploitation
CVE-2023-20198, a maximum-severity privilege-escalation flaw in Cisco IOS XE's web management interface, was exploited at mass scale before a patch existed — handing attackers full admin control of network infrastructure.