Threat intel

What's happening in cyber, in plain English

We pull from NCSC, CISA, Have I Been Pwned and the NVD every six hours, then summarise each item into what it is, who it affects, and what you can do about it.

  • MediumAdvisoryCisco PSIRT — security advisories· 22 Apr 2026· summary pending

    Cisco Integrated Management Controller Cross-Site Scripting Vulnerabilities

    Multiple vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. For more information about these vulner

  • MediumAdvisoryCisco PSIRT — security advisories· 16 Apr 2026· summary pending

    Cisco Secure Web Appliance Authentication Bypass Vulnerability

    A vulnerability in the authentication service feature of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass authentication policy requirements. This vulnerability is due to improper validation of use

  • MediumAdvisoryCisco PSIRT — security advisories· 15 Apr 2026· summary pending

    Cisco Identity Services Engine Authenticated Privilege Escalation Vulnerability

    A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, local attacker with administrative privileges to perform a command injection attack on the underlying operating

  • MediumAdvisoryCisco PSIRT — security advisories· 15 Apr 2026· summary pending

    Cisco Identity Services Engine Multiple Cross-Site Scripting Vulnerabilities

    Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative write privileges to conduct a stored cross-site scripting (XSS) attack or a reflected XSS a

  • MediumAdvisoryCisco PSIRT — security advisories· 15 Apr 2026· summary pending

    Cisco ThousandEyes Enterprise Agent Arbitrary File Overwrite Vulnerability

    A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent could allow an authenticated, local attacker with low privileges to overwrite arbitrary files on the local system of an affected device. This vulnerability is due to improper access controls on

  • MediumAdvisoryCisco PSIRT — security advisories· 15 Apr 2026· summary pending

    Cisco Unity Connection Arbitrary File Download Vulnerabilities

    Multiple vulnerabilities in Cisco Unity Connection could allow an authenticated, remote attacker to download arbitrary files from an affected system. To exploit these vulnerabilities, the attacker must have valid administrative credentials. These vulnerabiliti

  • MediumAdvisoryCisco PSIRT — security advisories· 15 Apr 2026· summary pending

    Cisco Unity Connection Cross-Site Scripting, Open Redirect, and SQL Injection Vulnerabilities

    Multiple vulnerabilities in Cisco Unity Connection could allow a remote attacker to conduct a cross-site scripting (XSS) attack, an open redirect attack, and an SQL injection attack. For more information about these vulnerabilities, see the Details section of

  • MediumAdvisoryCisco PSIRT — security advisories· 15 Apr 2026· summary pending

    Cisco Webex Contact Center Cross-Site Scripting Vulnerability

    A vulnerability in the Desktop Agent functionality of Cisco Webex Contact Center could have allowed an unauthenticated, remote attacker to conduct cross-site scripting attacks. Cisco has addressed this vulnerability in the Cisco Webex Contact Center service, a

  • MediumAdvisoryCisco PSIRT — security advisories· 2 Apr 2026· summary pending

    Cisco IOS XE Software Denial of Service Vulnerability

    A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists because incorrect privileges are associated with the start maintenanc

  • MediumAdvisoryCisco PSIRT — security advisories· 1 Apr 2026· summary pending

    Cisco Nexus Dashboard Insights Arbitrary File Write Vulnerability

    A vulnerability in the Metadata update feature of Cisco Nexus Dashboard Insights could allow an authenticated, remote attacker to write arbitrary files to an affected system. This vulnerability is due to insufficient validation of the metadata update file. An

  • MediumAdvisoryCisco PSIRT — security advisories· 1 Apr 2026· summary pending

    Cisco Nexus Dashboard and Nexus Dashboard Insights Server-Side Request Forgery Vulnerability

    A vulnerability in Cisco Nexus Dashboard and Cisco Nexus Dashboard Insights could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device. This vulnerability is due to improper input validatio

  • MediumAdvisoryCisco PSIRT — security advisories· 1 Apr 2026· summary pending

    Cisco Nexus Dashboard Configuration Backup REST API Unauthorized Access Vulnerability

    A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encryption password and access to Full or Config-only backup files to access sensitive information. This vulnerability exists because authenticatio

  • MediumAdvisoryCisco PSIRT — security advisories· 25 Mar 2026· summary pending

    Cisco IOS XE Software Secure Channel for Meraki Information Disclosure Vulnerability

    A vulnerability in Cisco IOS XE Software for Cisco Meraki could allow a remote, unauthenticated attacker to view confidential device information. This vulnerability is due to a device configuration upload being performed over an insecure tunnel. An attacker co

  • MediumAdvisoryCisco PSIRT — security advisories· 25 Mar 2026· summary pending

    Cisco IOS XE Software Lobby Ambassador Privilege Escalation Vulnerability

    A vulnerability in the Lobby Ambassador web-based management API of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate their privileges and access management APIs that would not normally be available for Lobby Ambassador users. This

  • MediumAdvisoryCisco PSIRT — security advisories· 25 Mar 2026· summary pending

    Cisco IOx Application Hosting Environment Carriage Return Line Feed Injection Vulnerability

    A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a carriage return line feed (CRLF) injection attack against a user. This vulnera

  • MediumAdvisoryCisco PSIRT — security advisories· 25 Mar 2026· summary pending

    Cisco IOx Application Hosting Environment Stored Cross-Site Scripting Vulnerability

    A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based managem

  • MediumAdvisoryCisco PSIRT — security advisories· 25 Mar 2026· summary pending

    Cisco IOS XE Software Secure Copy Protocol Server Denial of Service Vulnerability

    A vulnerability in the Secure Copy Protocol (SCP) server feature of Cisco IOS XE Software could allow an authenticated, local attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper

  • MediumAdvisoryCisco PSIRT — security advisories· 25 Mar 2026· summary pending

    Cisco Catalyst SD-WAN Manager Cross-Site Scripting Vulnerability

    A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due

  • MediumAdvisoryCisco PSIRT — security advisories· 11 Mar 2026· summary pending

    Multiple Cisco Contact Center Products Cross-Site Scripting Vulnerabilities

    Multiple vulnerabilities in the web-based management interface of Cisco Finesse, Cisco Packaged Contact Center Enterprise (Packaged CCE), Cisco Unified Contact Center Enterprise (Unified CCE), Cisco Unified Contact Center Express (Unified CCX), and Cisco Unifi

  • MediumAdvisoryCisco PSIRT — security advisories· 4 Mar 2026· summary pending

    Cisco Secure Firewall Management Center Software SQL Injection Vulnerability

    A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to perform an SQL injection attack against an affected

  • MediumAdvisoryCisco PSIRT — security advisories· 4 Mar 2026· summary pending

    Cisco Adaptive Security Appliance and Firepower Threat Defense Software Command Injection Vulnerability

    A vulnerability in the Cisco Adaptive Security Appliance (ASA) restore functionality that is available in Cisco ASA Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands on the und

  • MediumAdvisoryCisco PSIRT — security advisories· 4 Mar 2026· summary pending

    Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Lua Code Injection Vulnerability

    A vulnerability in a small subset of CLI commands that are used on Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to craft Lua code that coul

  • MediumAdvisoryCisco PSIRT — security advisories· 4 Mar 2026· summary pending

    Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software VPN Web Services Cross-Site Scripting Vulnerability

    A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS

  • MediumAdvisoryCisco PSIRT — security advisories· 4 Mar 2026· summary pending

    Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software VPN Web Services Client-Side Request Smuggling Vulnerability

    A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct browser-based attacks again

  • MediumAdvisoryCisco PSIRT — security advisories· 4 Mar 2026· summary pending

    Cisco Secure Firewall Adaptive Security Appliance Software SSH Partial Private Key Authentication Bypass Vulnerability

    A vulnerability in the implementation of the proprietary SSH stack with SSH key-based authentication in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to log in to a Cisco Secure Firewall ASA de

  • MediumAdvisoryCisco PSIRT — security advisories· 4 Mar 2026· summary pending

    Multiple Cisco Products Snort 3 Denial of Service Vulnerabilities

    Multiple Cisco products are affected by vulnerabilities in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspection. For more informati

  • MediumAdvisoryCisco PSIRT — security advisories· 4 Mar 2026· summary pending

    Cisco Webex Services Cross-Site Scripting Vulnerability

    A vulnerability in Cisco Webex could have allowed an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. Cisco has addressed this vulnerability, and no customer action is needed. This vulnerability was due to improper filtering of

Sources are pulled directly from each provider's public feed and never modified. AI summaries are produced for plain-English readability and are clearly labelled — always follow the source link for the authoritative advisory.