vulnerability Cisco Unified CM Flaw Exploited After PoC Reveals File-Write Path to Root Threat actors have begun to exploit a recently disclosed critical security flaw impacting Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME). The vulnerability, tracked as CVE-2026-20230 (CVSS score: 8.6), is a case of improper input validati The Hacker News · Jun 24, 2026 Medium CVE-2026-20230CVE-2026-20262
threat-intel ⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More This week’s cybersecurity news highlights a significant Fortinet vulnerability dubbed ‘FortiBleed,’ where over 80,000 FortiGate devices have been compromised by suspected Russian-speaking threat actors. Simultaneously, t… The Hacker News · Jun 22, 2026 Critical CVE-2026-24858CVE-2025-59718CVE-2025-59719RUcredential_reuseedrransomware
vulnerability Cisco Patches Another SD-WAN Zero-Day Exploited in Attacks Cisco recently became aware of the exploitation of CVE-2026-20262, a Catalyst SD-WAN Manager zero-day that allows arbitrary file write. The post Cisco Patches Another SD-WAN Zero-Day Exploited in Attacks appeared first o… SecurityWeek · Jun 16, 2026 Critical CVE-2026-20262CVE-2026-20182CVE-2026-20127
vulnerability Cisco Releases Security Updates for Actively Exploited SD-WAN Manager Flaw A vulnerability (CVE-2026-20262) in Cisco Catalyst SD-WAN Manager has been actively exploited in the wild, allowing authenticated attackers to overwrite files on affected systems. The flaw stems from inadequate input val… The Hacker News · Jun 16, 2026 High CVE-2026-20262CVE-2026-20245CVE-2026-20182USsd-wancvefile-upload
vulnerability Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks Cisco has released a security update to address a critical zero-day vulnerability (CVE-2026-20262) in its SD-WAN vManage software, allowing attackers to gain root privileges. The flaw stems from improper input validation… BleepingComputer · Jun 15, 2026 Critical CVE-2026-20262CVE-2026-20133CVE-2026-20128zero-dayroot privilegefile upload