Cisco PSIRT (RSS)
cisco-psirt · A · active
https://sec.cloudapps.cisco.com/security/center/psirtrss20/CiscoSecurityAdvisory.xml
Cisco Product Security Incident Response Team feed (added 2026-05-08). 2026-05-08 audit: 5 dated advisories May 6 2026 (Unity Connection RCE, ISE auth bypass, etc.), primary source for Cisco vuln context that ANSSI/CERT-EU advisories often cite. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → rss: python3 tools/fetch_source.py feed https://sec.cloudapps.cisco.com/security/center/psirtrss20/CiscoSecurityAdvisory.xml 5 (item links are full advisory URLs with title+CVE+impact; webfetch the cisco-sa-* URL for full body). AVOID: Feed summaries already carry CVE IDs + Security Impact Rating, often enough; strip the long ?vs_f=... query string when citing.. | 2026-07-05 admiralty audit: A (vendor-psirt), Cisco's own PSIRT feed, first-party advisories for its products; feed clean and current. Status stays active.
Cited in 22 entries
Citation cadence
Citation days per ISO week (19 weeks of coverage span, total 15).
- CVE-2026-76460 (+ CVE-2026-76423), Cisco Identity Services Engine: unauthenticated API authentication bypass to root, found while resolving a customer support case, no workaround beyond ACLs (CVSS 10.0)2026-09-17
- CVE-2026-76461: Cisco Secure Email Gateway unauthenticated SQL injection in email parsing reaches root command execution, exploited before disclosure (CVSS 9.8)2026-09-15
- CVE-2026-20212, Cisco Nexus 9000 Series: unauthenticated root RCE via the Silicon One hardware-abstraction layer on TCP 43210/432112026-09-04
- CVE-2026-20349, Cisco Secure Firewall ASA/FTD: one crafted HTTP request to the Remote Access SSL VPN reloads the device, exploitation confirmed, no workaround and a three-day KEV deadline2026-08-12
- Cisco IOS XE August 2026 hardening release, seven CVEs that each stand for a whole class of internally found bugs, no workarounds, and frontier AI models among the discovery tools2026-08-08
- CVE-2026-20079, Cisco Secure Firewall Management Center: unauthenticated authentication bypass to root, unpatched for five months and only exploitable in a post-boot window (CVSS 10.0)2026-08-04
- CVE-2026-20316; Cisco Secure Firewall Management Center ships a static low-privilege account in its web interface, and Cisco confirms exploitation has been ongoing2026-07-30
- Cisco Catalyst SD-WAN Manager CVE-2026-202452026-06-26
- CVE-2026-20230, Cisco Unified CM: WebDialer SSRF to arbitrary file write to root, reconnaissance-stage exploitation observed2026-06-24
- CVE-2026-55803 / CVE-2026-55804, Drupal core: PHP object-injection chain in JSON:API, BSI-rated critical2026-06-19
- CVE-2026-20181 / CVE-2026-20190, Cisco Identity Services Engine: unauthenticated credential read chaining to authenticated root command execution2026-06-19
- Cisco ISE CVE-2026-20181 + CVE-2026-20190: an unauthenticated credential-harvest primitive feeding authenticated root code execution on the identity plane2026-06-19
- CVE-2026-48611 / CVE-2026-48612, phpBB: unauthenticated authentication bypass to admin, one HTTP request2026-06-16
- CVE-2026-20262, Cisco Catalyst SD-WAN Manager: authenticated arbitrary file write to root RCE (CISA KEV)2026-06-16
- Cisco Catalyst SD-WAN Manager CVE-2026-20262: authenticated arbitrary file write to root RCE2026-06-16
- CVE-2026-20245, Cisco Catalyst SD-WAN Manager: actively-exploited command-injection to root (no patch)2026-06-06
- CVE-2026-10868, MISP: critical mass-assignment account-takeover in the EU threat-sharing platform2026-06-06
- CVE-2026-20230, Cisco Unified Communications Manager: unauthenticated SSRF to OS-root file write2026-06-04
- CVE-2026-10611, MISP: OTP bypass when LDAP mixed-auth and OTP enforcement are both enabled2026-06-04
- CVE-2026-20223, Cisco Secure Workload: CVSS 10.0 zero-auth REST API grants Site Admin privileges across all tenants, no workaround2026-05-22
- CVE-2026-46300, Linux kernel: local privilege escalation via xfrm ESP-in-TCP ("Fragnesia"), PoC public2026-05-15
- CVE-2026-20182, Cisco Catalyst SD-WAN Controller/Manager: pre-auth authentication bypass enabling full fabric takeover2026-05-15