Сisсо Сhаnnеl
17.9K subscribers
2.23K photos
109 videos
579 files
27.8K links
Cisco News and Vulnerabilities
This channel is not official

Boost the channel!!
https://t.me/Cisco?boost

More:

@PopPolls
@QubesOS 💻
@CiscoChat
@Net3A

t.me/Cisco/22556
Download Telegram
I am absolutely thrilled to announce a transformative milestone in our shared journey: Iron Bow, a distinguished Cisco Partner Innovation Challenge Winner, is redefining the future of first responder excellence by strategically orchestrating fragmented ecosystems into a unified, high-impact connectivity framework. This powerful synergy empowers our dedicated heroes to navigate complex challenges with unparalleled precision and rapid deployment, ultimately amplifying our collective mission to save lives and drive meaningful societal growth. 🚀🤝

More RSS Feeds: https://newsroom.cisco.com/c/r/newsroom/en/us/rss-feeds.html (https://newsroom.cisco.com/c/r/newsroom/en/us/rss-feeds.html?source=rss)
Cisco Smart Software Manager On-Prem Arbitrary Command Execution Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ssm-cli-execution-cHUcWuNr?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Smart%20Software%20Manager%20On-Prem%20Arbitrary%20Command%20Execution%20Vulnerability%26vs_k=1

A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host.
This vulnerability is due to the unintentional exposure of an internal service. An attacker could exploit this vulnerability by sending a crafted request to the API of the exposed service. A successful exploit could allow the attacker to execute commands on the underlying operating system with root-level privileges.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ssm-cli-execution-cHUcWuNr

Security Impact Rating: Critical


CVE: CVE-2026-20160
Cisco Nexus Dashboard Configuration Backup REST API Unauthorized Access Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nd-cbid-5YqkOSHu?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Nexus%20Dashboard%20Configuration%20Backup%20REST%20API%20Unauthorized%20Access%20Vulnerability%26vs_k=1

A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encryption password and access to Full or Config-only backup files to access sensitive information.
This vulnerability exists because authentication details are included in the encrypted backup files. An attacker with a valid backup file and encryption password from an affected device could decrypt the backup file. The attacker could then use the authentication details in the backup file to access internal-only APIs on the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nd-cbid-5YqkOSHu

Security Impact Rating: Medium


CVE: CVE-2026-20042
Cisco Nexus Dashboard and Nexus Dashboard Insights Server-Side Request Forgery Vulnerability
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nd-ssrf-NAen4O7r?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Nexus%20Dashboard%20and%20Nexus%20Dashboard%20Insights%20Server-Side%20Request%20Forgery%20Vulnerability%26vs_k=1

A vulnerability in Cisco Nexus Dashboard and Cisco Nexus Dashboard Insights could allow an unauthenticated, remote attacker to conduct a server-side request forgery (SSRF) attack through an affected device.
This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by persuading an authenticated user of the device management interface to click a crafted link. A successful exploit could allow the attacker to send arbitrary network requests that are sourced from the affected device to an attacker-controlled server. The attacker could then execute arbitrary script code in the context of the affected interface or access sensitive browser-based information.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-nd-ssrf-NAen4O7r

Security Impact Rating: Medium


CVE: CVE-2026-20041
1
Cisco Integrated Management Controller Command Injection and Remote Code Execution Vulnerabilities
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-cmd-inj-3hKN3bVt?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Integrated%20Management%20Controller%20Command%20Injection%20and%20Remote%20Code%20Execution%20Vulnerabilities%26vs_k=1

Multiple vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to execute arbitrary code or commands on the underlying operating system of an affected system and elevate privileges to root.
For more information about these vulnerabilities, see the Details (https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-cmd-inj-3hKN3bVt?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Integrated%20Management%20Controller%20Command%20Injection%20and%20Remote%20Code%20Execution%20Vulnerabilities%26vs_k=1#details) section of this advisory.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-cmd-inj-3hKN3bVt

Security Impact Rating: High


CVE: CVE-2026-20094,CVE-2026-20095,CVE-2026-20096,CVE-2026-20097
In 2026, the AI era demands advanced wireless infrastructure to resolve the AI paradox, support massive workloads, and secure your digital perimeter.
More RSS Feeds: https://newsroom.cisco.com/c/r/newsroom/en/us/rss-feeds.html (https://newsroom.cisco.com/c/r/newsroom/en/us/rss-feeds.html?source=rss)
Cisco released its inaugural State of Wireless Report, revealing that Wi-Fi has evolved into a strategic growth engine capable of delivering a multiplier effect
More RSS Feeds: https://newsroom.cisco.com/c/r/newsroom/en/us/rss-feeds.html (https://newsroom.cisco.com/c/r/newsroom/en/us/rss-feeds.html?source=rss)
Dear Iranians!

DO NOT form human chains around power plants! if Iran refuses to make a deal today, the U.S. will be taking them out! You have been warned! STAY AWAY FROM THE POWER PLANTS!!



ایرانیان عزیز!

از تشکیل زنجیره‌های انسانی در اطراف نیروگاه‌ها خودداری کنید! اگر ایران امروز از انجام توافق خودداری کند، آمریکا آن‌ها را هدف قرار خواهد داد! به شما هشدار داده شده است! از نیروگاه‌ها دوری کنید!!
11👍1
Сisсо Сhаnnеl pinned «Dear Iranians! DO NOT form human chains around power plants! if Iran refuses to make a deal today, the U.S. will be taking them out! You have been warned! STAY AWAY FROM THE POWER PLANTS!! ایرانیان عزیز! از تشکیل زنجیره‌های انسانی در اطراف نیروگاه‌ها…»
Stay away from bridges, and trains!

از پل‌ها و قطارها دوری کنید!
👌1
Сisсо Сhаnnеl pinned «Stay away from bridges, and trains! از پل‌ها و قطارها دوری کنید!»