One Encoded URL Can Hand Attackers Cisco SD-WAN Admin Access

Cisco says attackers are exploiting a critical SD-WAN Manager flaw that turns one encoded HTTP request into administrator-level API access.

Cisco says attackers are exploiting a critical SD-WAN Manager flaw that turns one encoded HTTP request into administrator-level API access.

Cisco's review found missing authentication, injection and other weaknesses in Nexus Dashboard. The important patch question is which control-plane build is actually running.

The platform deciding who may enter your network has an exploited login bypass. Patching Cisco ISE closes the flaw, but deciding whether a node can still be trusted takes a separate investigation.

Cisco says attackers are exploiting a critical flaw in Secure Email Gateway. A crafted message can pass through the appliance and become root-level commands, with no login or user click.

A critical Cisco Nexus 9000 flaw exposes root-level remote code execution through TCP ports 43210 and 43211 on affected Silicon One switches.

Seven flaws affect every Cisco IOS XR release, two carry a 9.8 score, and operators have no general workaround while planning fixes.

Cisco warns that model publishers and country labels can hide inherited weights, training data and upstream dependencies.

Cisco Talos found UAT-10147 using agentic AI to scale exploitation and post-compromise work across a target list containing approximately 170,000 web-server URLs.

Cisco has documented three distinct FMC attack campaigns, including no-login root access, Sandworm-linked tooling and ransomware preparation. Patch exposed managers and investigate each cluster separately.

Cisco says attackers are exploiting a denial-of-service flaw in ASA and Secure Firewall Threat Defense. The lesson is not only to patch the VPN edge, but to design for the moment the security device itself becomes unavailable.