Updated just now · 7 advisories
Remotely exploitable — could allow full system takeover — no credentials needed
Exploitable from adjacent network — could allow full system takeover — no credentials needed
Remotely exploitable — no credentials needed
Remotely exploitable — could expose sensitive process data — no credentials needed
An attacker can send a specially crafted login request to crash the Ethernet switch's authentication process, causing the device to stop responding and disabling network connectivity for connected equipment. This is a denial-of-service attack with no legitimate workaround.
An attacker could send a specially crafted network message that crashes the Freelance controller, causing loss of control over your process equipment and operational downtime.
An attacker with network access could read sensitive telemetry data and firmware information from the ELD system without authentication, potentially revealing operational details about vehicle location, routes, and system configuration.
An attacker could hijack dynovaPRO™ user accounts and gain remote control of the system, potentially allowing unauthorized modification of industrial processes or operational parameters depending on the compromised user's privileges.
A local attacker with low privileges can bypass the block password protection on GX Works3 or Motion Control Settings, then modify executable modules in memory to view, alter, or delete PLC control programs. This could allow unauthorized changes to industrial process logic or complete loss of control program integrity.
An authenticated attacker with valid user credentials can hijack the inter-device communication channel on your Secure Firewall Management Center and execute arbitrary commands as root, potentially taking full control of the device and all managed firewalls.
An attacker with administrative credentials could inject SQL or HQL commands into the ISE database, allowing them to view or modify data they should not access, including authentication records, user information, and system configurations.
A remote attacker could crash your firewall's IKEv2 VPN process, causing it to reload. During this outage, VPN connectivity would be interrupted and your firewall would be unavailable to protect your network.
An attacker could bypass authentication mechanisms in Cisco ISE to access or modify data without proper credentials, or trigger certificate/key reloads that could disrupt identity verification services.
An attacker can flood your firewall with SYN packets to trigger excessive syslog message generation, causing high CPU usage and performance degradation or shutdown of network traffic inspection capabilities. This can prevent legitimate traffic from reaching your facility while the firewall is overloaded.
An attacker on the same network segment could crash your firewall by sending malicious EIGRP routing messages, causing it to reload and interrupt all traffic passing through it.
An attacker with network access to your Firewall Management Center could gain full administrator control and forge user sessions, allowing them to reconfigure firewalls, modify security policies, or disable threat protections across your entire network infrastructure.
An attacker with administrator credentials could modify configuration settings on Cisco ISE, potentially altering file descriptions and other configuration details that could affect the integrity of identity authentication and authorization policies.
An authenticated administrator with valid credentials could execute arbitrary commands as root on your Identity Services Engine, potentially compromising network access controls, authentication systems, and the integrity of all devices managed through this platform.
A remote attacker could exploit path traversal vulnerabilities in Cisco ISE to read or write unauthorized files on the affected system, potentially exposing sensitive configuration data or gaining a foothold for further attacks on your identity and access control infrastructure.
Multiple critical vulnerabilities in Cisco ISE could allow unauthenticated attackers to execute arbitrary code or bypass authentication controls, potentially compromising network access enforcement and enabling unauthorized access to your network infrastructure.
An attacker can send a malformed SSL/TLS connection to your firewall, causing the Snort intrusion detection engine to restart. This causes a brief loss of threat detection and network inspection until the engine recovers.
An attacker can send network traffic that bypasses your firewall's access control rules, potentially reaching protected systems or networks that should be blocked. This happens because of a logic error in how the firewall processes object group-based rules.
An attacker who can intercept or control DNS responses can force your firewall to reload, causing a temporary outage of all network traffic through that device and interrupting both data flow and security inspections.
An attacker with low-level credentials (like an engineer or junior technician) could gain complete control over your firewall, potentially intercepting, modifying, or blocking all network traffic entering and leaving your facility. This could disrupt communications, allow data theft, or prevent critical network services from reaching your OT environment.
An attacker with high-level admin access to the FMC could execute arbitrary commands with root privileges, read sensitive configuration and credential files, disrupt management operations, or manipulate firewall policy through SQL injection. This directly impacts your ability to manage and monitor all connected firewalls across your network.
An attacker can send a specially crafted TLS 1.3 packet to your firewall, causing it to crash and reload, interrupting all traffic filtering and network protection during the outage.
An unauthenticated attacker on the network can bypass authentication to the sftunnel service or cause it to become unavailable, potentially disrupting secure communication between your firewall appliances and management center.
An attacker could bypass authentication to the REST API, execute arbitrary commands on your ISE device, extract or modify database contents via SQL injection, or read sensitive files through XML injection. This could allow complete compromise of your identity and access control infrastructure.
An attacker with control of a host in your FMC's external database access list could gain root-level command execution on your FMC appliance, allowing them to compromise firewall policies, extract sensitive configuration data, or disrupt your security monitoring infrastructure.
An attacker could send crafted DTLS traffic to cause a Secure Firewall device to reload, interrupting all traffic inspection and security enforcement until the device recovers. This results in a complete loss of firewall protection for the network segment during the outage.
An attacker with network access to the webserver could bypass authentication and execute arbitrary commands on the I/O module, potentially altering its input readings or blocking legitimate operations. They could also extract configuration files containing credentials used for engineering access or inter-system communications.
An attacker could force these devices into protection mode, temporarily disabling remote Web Access and preventing operators from monitoring or managing the devices remotely until manual intervention restores connectivity.
An attacker gaining administrative control could view all live and recorded surveillance footage, modify device settings, and use the recorder as a pivot point to attack other systems on your network.
An attacker could inject malicious updates, run arbitrary code on the FOS-Onboard system, or steal credentials to gain privileged access, potentially allowing them to modify marine propulsion system configurations, engine parameters, or operational controls.
An attacker on your network could gain unauthorized access to the mySCADA Pro Manager's administrative functions without credentials, allowing them to modify SCADA system settings or send unauthorized SMS messages through any connected cellular modem.
An attacker with network access to a CareCam CM2507 camera could view live video feeds, steal device credentials, enable unauthorized remote access services, or modify camera operation. Cameras deployed in sensitive areas of your facility could expose physical security footage or enable unauthorized control of monitoring systems.
An authenticated attacker could inject commands into Malcolm to execute arbitrary actions on the system, access sensitive configuration and data, bypass security controls, or redirect users to malicious sites. This could compromise the integrity and availability of network traffic analysis and threat intelligence operations.
An authenticated attacker could upload a malicious PNG or JPEG image that crashes the Orthanc DICOM server, taking down medical imaging services and preventing access to patient images.
An attacker with valid credentials could steal patient data or disrupt the message routing system, preventing healthcare facilities from exchanging critical patient information between systems.
An attacker with local access to the Pipeline Integrity Monitor system could disclose sensitive information, brute-force password hashes, or run arbitrary code in a user's browser session, potentially allowing unauthorized control of pipeline monitoring and integrity data.
An attacker with network access to these systems could delete files with system privileges, modify configuration settings, crash the license manager causing service disruption, and access sensitive license or configuration data. This could lead to loss of control system functionality or unauthorized changes to device behavior.
Cisco will disclose multiple security vulnerabilities affecting firewall, authentication, and network monitoring products on September 16, 2026. Until patches are available, organizations using these products face unknown but potentially significant risks.
Attackers could gain elevated privileges on Windows systems running ABB zenon with vulnerable WIBU CodeMeter Runtime, or disrupt licensing and operations on systems configured as CodeMeter license servers. This could allow unauthorized access to the control system and modifications to process logic.
An attacker could cause firewalls to stop responding (denial of service) or, on some models, execute commands as root. This could halt network traffic and leave your facility without perimeter protection.
An authenticated administrator with CLI access to a PAN-OS device configured with a Luna HSM could run arbitrary commands as root, potentially compromising the firewall's integrity and allowing bypass of security controls that protect your network.
An authenticated administrator with malicious intent could inject JavaScript code into the firewall's web interface that executes when other administrators access the interface, potentially allowing credential theft or unauthorized configuration changes to critical security policies.
A regular user on an employee's Windows, macOS, or Linux laptop running GlobalProtect can escalate to full administrative control and execute any command, potentially compromising credentials, installing malware, or accessing sensitive data stored locally.
A user with local access to a Windows computer running Prisma Access Agent could bypass DLP controls and steal sensitive data that the organization has configured DLP rules to protect, such as credentials, proprietary information, or operational data.
A local user on a Linux machine running Prisma Access Agent could read sensitive configuration files and credentials stored by the agent, potentially gaining unauthorized access to protected networks or systems that the agent connects to.
An attacker with low-level user access and the ability to intercept network traffic could run commands with root privileges on the Cortex XDR Broker VM, potentially compromising endpoint detection and response capabilities across your organization.