Skip to content
[vulnfeed] 34 critical CVEs — 2026-09-16 20:00 UTC

[vulnfeed] 34 critical CVEs — 2026-09-16 20:00 UTC

Buttondown September 17, 2026

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attac

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication.

This vulnerability is due to insufficient authentication

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services E

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), engineering teams have con

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services E

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have cond

A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker

A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to gain administrative access to an affected device.

A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Ser

A server-side request forgery (SSRF) vulnerability exists in the UnifiedLogin service of Altium Enterprise Server. An unauthenticated network attacker can cause the server to issue outbound HTTP reque

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard&nbs

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review res

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary command

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard&nbs

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review res

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Sec

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure F

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Sec

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure F

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Sec

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure F

A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Softw

A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary commands as

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard eng

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted

Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenti

Covenant through 0.6 registers the CovenantHub SignalR hub without an Authorize attribute, allowing unauthenticated callers to invoke CreateHttpListener and receive a signed JWT token. Attackers can u

Kubero through 3.1.1 fails to apply authentication guards to the notifications API endpoints, allowing unauthe

Kubero through 3.1.1 fails to apply authentication guards to the notifications API endpoints, allowing unauthenticated attackers to read webhook secrets and service URLs. Attackers can retrieve stored