<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from csaf_cisco</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 07:10:12 +0000</lastBuildDate>
    <item>
      <title>cisco-sa-notice-fBn58ELx — Cisco Advance Notification for Publication of October 7, 2026, Security Advisories</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-notice-fbn58elx</link>
      <description>&lt;p&gt;On October 7, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products:&#13;
&#13;
Application Policy Infrastructure Controller (security hardening release)&#13;
Finesse&#13;
License On-Prem, formerly Cisco Smart Software Manager On-Prem (security hardening release)&#13;
Meraki (security hardening release)&#13;
NX-OS Software for MDS 9000, Nexus 3000, 7000, and 9000 Series Switches, Nexus 9000 in ACI mode, and UCS Fabric Interconnects (security hardening release)&#13;
&#13;
To remediate vulnerabilities to be disclosed on October 7, 2026, Cisco strongly recommends that customers upgrade to the fixed software indicated in the advisories.&#13;
&#13;
For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the Foundation: A Predictable, Customer-Focused Response to AI-Accelerated Vulnerability Discovery [&amp;#34;https://blogs.cisco.com/security/strengthening-the-foundation-a-predictable-customer-focused-response-to-ai-accelerated-vulnerability-discovery&amp;#34;].&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;On October 7, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products:&#13;
&#13;
Application Policy Infrastructure Controller (security hardening release)&#13;
Finesse&#13;
License On-Prem, formerly Cisco Smart Software Manager On-Prem (security hardening release)&#13;
Meraki (security hardening release)&#13;
NX-OS Software for MDS 9000, Nexus 3000, 7000, and 9000 Series Switches, Nexus 9000 in ACI mode, and UCS Fabric Interconnects (security hardening release)&#13;
&#13;
To remediate vulnerabilities to be disclosed on October 7, 2026, Cisco strongly recommends that customers upgrade to the fixed software indicated in the advisories.&#13;
&#13;
For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the Foundation: A Predictable, Customer-Focused Response to AI-Accelerated Vulnerability Discovery [&amp;#34;https://blogs.cisco.com/security/strengthening-the-foundation-a-predictable-customer-focused-response-to-ai-accelerated-vulnerability-discovery&amp;#34;].&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-notice-fbn58elx</guid>
      <pubDate>Wed, 30 Sep 2026 16:00:00 +0000</pubDate>
    </item>
    <item>
      <title>cisco-sa-sdwan-webauth-xr8beuuU — Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-sdwan-webauth-xr8beuuu</link>
      <description>&lt;p&gt;A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user.&#13;
&#13;
This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.&#13;
&#13;
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user.&#13;
&#13;
This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user.&#13;
&#13;
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-sdwan-webauth-xr8beuuu</guid>
      <pubDate>Wed, 30 Sep 2026 13:00:00 +0000</pubDate>
    </item>
    <item>
      <title>cisco-sa-ise-multiauth-bypass-sgD2HbL4 — Cisco Identity Services Engine Authentication Bypass Vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-ise-multiauth-bypass-sgd2hbl4</link>
      <description>&lt;p&gt;Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to access or manipulate data, obtain sensitive information, or cause a reload of certificate and key material on an affected device.&#13;
&#13;
For more information about these vulnerabilities, see the Details [&amp;#34;#details&amp;#34;] section of this advisory.&#13;
&#13;
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.&#13;
&#13;
&#13;
&#13;
This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-jfxK98ZP&amp;#34;]. In addition, for further documentation of improvements and fixes in Cisco Identity Services Engine, see Cisco Identity Services Engine Security Hardening Release: September 2026 [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ise-XU5EwX5T&amp;#34;].&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to access or manipulate data, obtain sensitive information, or cause a reload of certificate and key material on an affected device.&#13;
&#13;
For more information about these vulnerabilities, see the Details [&amp;#34;#details&amp;#34;] section of this advisory.&#13;
&#13;
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.&#13;
&#13;
&#13;
&#13;
This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-jfxK98ZP&amp;#34;]. In addition, for further documentation of improvements and fixes in Cisco Identity Services Engine, see Cisco Identity Services Engine Security Hardening Release: September 2026 [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ise-XU5EwX5T&amp;#34;].&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-ise-multiauth-bypass-sgd2hbl4</guid>
      <pubDate>Wed, 16 Sep 2026 16:00:00 +0000</pubDate>
    </item>
    <item>
      <title>cisco-sa-asaftdvirtual-dos-MuenGnYR — Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL VPN Denial of Service…</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-asaftdvirtual-dos-muengnyr</link>
      <description>&lt;p&gt;Update for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv) models. However, it was later found that this vulnerability affects all Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software platforms.&#13;
&#13;
A vulnerability in the VPN and management web servers of the Cisco Secure Firewall ASA Software and Cisco Secure FTD Software platforms could allow an unauthenticated, remote attacker to cause an affected device to run out of system memory or buffer blocks, which in turn could cause SSL VPN connection processing to slow down and eventually cease altogether.&#13;
&#13;
This vulnerability is due to a lack of proper memory management for new incoming SSL/TLS connections. An attacker could exploit this vulnerability by sending a large number of new incoming SSL/TLS connections to the targeted device. A successful exploit could allow the attacker to deplete system memory or buffers, resulting in a denial of service (DoS) condition. The memory or buffers could be reclaimed slowly if the attack traffic is stopped, but a manual reload may be required to restore operations quickly.&#13;
&#13;
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&#13;
&#13;
&#13;
&#13;
This advisory is part of the October 2024 release of the Cisco ASA, FMC, and FT…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Update for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv) models. However, it was later found that this vulnerability affects all Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software platforms.&#13;
&#13;
A vulnerability in the VPN and management web servers of the Cisco Secure Firewall ASA Software and Cisco Secure FTD Software platforms could allow an unauthenticated, remote attacker to cause an affected device to run out of system memory or buffer blocks, which in turn could cause SSL VPN connection processing to slow down and eventually cease altogether.&#13;
&#13;
This vulnerability is due to a lack of proper memory management for new incoming SSL/TLS connections. An attacker could exploit this vulnerability by sending a large number of new incoming SSL/TLS connections to the targeted device. A successful exploit could allow the attacker to deplete system memory or buffers, resulting in a denial of service (DoS) condition. The memory or buffers could be reclaimed slowly if the attack traffic is stopped, but a manual reload may be required to restore operations quickly.&#13;
&#13;
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&#13;
&#13;
&#13;
&#13;
This advisory is part of the October 2024 release of the Cisco ASA, FMC, and FT…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-asaftdvirtual-dos-muengnyr</guid>
      <pubDate>Wed, 23 Oct 2024 16:00:00 +0000</pubDate>
    </item>
    <item>
      <title>cisco-sa-asa-ftd-logging-dos-ZXXNesfN — Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Logging Denial of Service…</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-asa-ftd-logging-dos-zxxnesfn</link>
      <description>&lt;p&gt;A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a denial of service (DoS) condition.&#13;
&#13;
This vulnerability is due to improper rate limiting for syslog message 419002. An attacker could exploit this vulnerability by sending a flood of TCP synchronization (SYN) packets to an affected device. A successful exploit could allow the attacker to cause high CPU utilization, resulting in performance degradation.&#13;
&#13;
Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability.&#13;
&#13;
&#13;
&#13;
This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-jfxK98ZP&amp;#34;]. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026 [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-asa…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a denial of service (DoS) condition.&#13;
&#13;
This vulnerability is due to improper rate limiting for syslog message 419002. An attacker could exploit this vulnerability by sending a flood of TCP synchronization (SYN) packets to an affected device. A successful exploit could allow the attacker to cause high CPU utilization, resulting in performance degradation.&#13;
&#13;
Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability.&#13;
&#13;
&#13;
&#13;
This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-jfxK98ZP&amp;#34;]. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026 [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-asa…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-asa-ftd-logging-dos-zxxnesfn</guid>
      <pubDate>Wed, 16 Sep 2026 16:00:00 +0000</pubDate>
    </item>
    <item>
      <title>cisco-sa-hardening-asaftdfmc-uvpPROhN — Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Cente…</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-hardening-asaftdfmc-uvpprohn</link>
      <description>&lt;p&gt;As part of Cisco&amp;#39;s ongoing commitment to proactive security and product quality, the Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software and Cisco Secure Firewall Management Center (FMC) Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.&#13;
&#13;
These vulnerabilities were found during internal testing. Two of them are known to be actively exploited. For more information, see the following advisories: Cisco Secure Firewall Management Center Software Static Credential Vulnerability [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh&amp;#34;] and Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2&amp;#34;]. To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures Identifier (CVE ID) to each CWE grouping.&#13;
&#13;
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.&#13;
&#13;
&#13;
&#13;
This advisory is part of a group of advisories. For a c…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;As part of Cisco&amp;#39;s ongoing commitment to proactive security and product quality, the Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software and Cisco Secure Firewall Management Center (FMC) Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.&#13;
&#13;
These vulnerabilities were found during internal testing. Two of them are known to be actively exploited. For more information, see the following advisories: Cisco Secure Firewall Management Center Software Static Credential Vulnerability [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh&amp;#34;] and Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2&amp;#34;]. To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures Identifier (CVE ID) to each CWE grouping.&#13;
&#13;
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.&#13;
&#13;
&#13;
&#13;
This advisory is part of a group of advisories. For a c…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-hardening-asaftdfmc-uvpprohn</guid>
      <pubDate>Wed, 16 Sep 2026 16:00:00 +0000</pubDate>
    </item>
    <item>
      <title>cisco-sa-asaftd-dtls-dos-Kp57HkyO — Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Secure Firewall 3100…</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-asaftd-dtls-dos-kp57hkyo</link>
      <description>&lt;p&gt;A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Secure Firewall 3100 Series and 4200 Series devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.&#13;
&#13;
This vulnerability is due to improper resource management when processing certain DTLS messages. An attacker could exploit this vulnerability by sending a crafted stream of DTLS traffic to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.&#13;
&#13;
Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability.&#13;
&#13;
&#13;
&#13;
This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-jfxK98ZP&amp;#34;]. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026 [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Secure Firewall 3100 Series and 4200 Series devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.&#13;
&#13;
This vulnerability is due to improper resource management when processing certain DTLS messages. An attacker could exploit this vulnerability by sending a crafted stream of DTLS traffic to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.&#13;
&#13;
Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability.&#13;
&#13;
&#13;
&#13;
This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-jfxK98ZP&amp;#34;]. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026 [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-asaftd-dtls-dos-kp57hkyo</guid>
      <pubDate>Wed, 16 Sep 2026 16:00:00 +0000</pubDate>
    </item>
    <item>
      <title>cisco-sa-ftd-acl-bypass-8p6vFvw — Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Object Group Access Contr…</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-ftd-acl-bypass-8p6vfvw</link>
      <description>&lt;p&gt;Multiple vulnerabilities in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access controls.&#13;
&#13;
These vulnerabilities are due to a logic error in populating group access control policies (ACPs) with OGS configured. An attacker could exploit these vulnerabilities by sending traffic that should be blocked through the device. A successful exploit could allow the attacker to bypass access controls and reach devices in protected networks.&#13;
&#13;
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.&#13;
&#13;
&#13;
&#13;
This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-jfxK98ZP&amp;#34;]. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026 [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-asaftdfmc-uvpP…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Multiple vulnerabilities in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access controls.&#13;
&#13;
These vulnerabilities are due to a logic error in populating group access control policies (ACPs) with OGS configured. An attacker could exploit these vulnerabilities by sending traffic that should be blocked through the device. A successful exploit could allow the attacker to bypass access controls and reach devices in protected networks.&#13;
&#13;
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.&#13;
&#13;
&#13;
&#13;
This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-jfxK98ZP&amp;#34;]. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026 [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-asaftdfmc-uvpP…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-ftd-acl-bypass-8p6vfvw</guid>
      <pubDate>Wed, 16 Sep 2026 16:00:00 +0000</pubDate>
    </item>
    <item>
      <title>cisco-sa-asaftd-ikev2cert-dos-uWyc2xtv — Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Certificate Authent…</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-asaftd-ikev2cert-dos-uwyc2xtv</link>
      <description>&lt;p&gt;A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2) for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly.&#13;
&#13;
This vulnerability is due to a logic error during the certificate authentication phase of the IKEv2 connection setup. An attacker could exploit this vulnerability by attempting to establish an IKEv2 VPN connection with a crafted certificate. A successful exploit could allow the attacker to cause the IKEv2 process to crash, causing a denial of service (DoS) condition.&#13;
&#13;
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&#13;
&#13;
&#13;
&#13;
This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-jfxK98ZP&amp;#34;]. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026 [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityA…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2) for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly.&#13;
&#13;
This vulnerability is due to a logic error during the certificate authentication phase of the IKEv2 connection setup. An attacker could exploit this vulnerability by attempting to establish an IKEv2 VPN connection with a crafted certificate. A successful exploit could allow the attacker to cause the IKEv2 process to crash, causing a denial of service (DoS) condition.&#13;
&#13;
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&#13;
&#13;
&#13;
&#13;
This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-jfxK98ZP&amp;#34;]. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026 [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityA…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-asaftd-ikev2cert-dos-uwyc2xtv</guid>
      <pubDate>Wed, 16 Sep 2026 16:00:00 +0000</pubDate>
    </item>
    <item>
      <title>cisco-sa-asaftd-tcpdns-dos-p6dUnjr5 — Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software TCP DNS Denial of Service…</title>
      <link>https://cve.radiocsirt.org/vuln/cisco-sa-asaftd-tcpdns-dos-p6dunjr5</link>
      <description>&lt;p&gt;A vulnerability in the DNS over TCP implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the TCP DNS response handler to unexpectedly restart, causing the device to reload.&#13;
&#13;
This vulnerability is due to a logic error when parsing a DNS query and tracking the size of the incoming buffers. An attacker could exploit this vulnerability by formatting a crafted reply to a DNS query sent from the targeted device. A successful exploit could allow the attacker to cause the device to reload, causing a denial of service (DoS) condition.&#13;
&#13;
Note: The attacker must be able to respond to DNS queries from the device, either by controlling the DNS service or through a machine-in-the-middle attack.&#13;
&#13;
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&#13;
&#13;
&#13;
&#13;
This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-jfxK98ZP&amp;#34;]. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewal…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability in the DNS over TCP implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the TCP DNS response handler to unexpectedly restart, causing the device to reload.&#13;
&#13;
This vulnerability is due to a logic error when parsing a DNS query and tracking the size of the incoming buffers. An attacker could exploit this vulnerability by formatting a crafted reply to a DNS query sent from the targeted device. A successful exploit could allow the attacker to cause the device to reload, causing a denial of service (DoS) condition.&#13;
&#13;
Note: The attacker must be able to respond to DNS queries from the device, either by controlling the DNS service or through a machine-in-the-middle attack.&#13;
&#13;
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.&#13;
&#13;
&#13;
&#13;
This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories [&amp;#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-jfxK98ZP&amp;#34;]. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewal…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cisco-sa-asaftd-tcpdns-dos-p6dunjr5</guid>
      <pubDate>Wed, 16 Sep 2026 16:00:00 +0000</pubDate>
    </item>
  </channel>
</rss>
