advisories
20 articles
Reconstructing AI Agent Activity: Two New Scripts for Forensic Review, (Thu, Oct 8th)
We just did a major update to FOR577 and added a lot of new material on day 5 about investigating AI usage in incident response. In the new material we dicsu...
Red Lion Controls N-Tron 700 Series
View CSAF Summary Successful exploitation of these vulnerabilities could allow a malicious user to access the device and gain administrative access. This acc...
Satel Netco Design
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary scripts in a user's browser, consume excessiv...
Grid Protection Alliance openPDC and openHistorian
View CSAF Summary The following versions of Grid Protection Alliance openPDC and openHistorian are affected: openPDC <2.9.
ISC Stormcast For Thursday, October 8th, 2026 https://isc.sans.edu/podcastdetail/10128, (Thu, Oct 8th)
Cisco NX-OS Software Python Sandbox Escape Vulnerability
A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, local attacker with low privileges to escape the Python sandb...
Cisco Finesse Server-Side Request Forgery Vulnerability
A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct server-side request forgery...
Cisco Nexus 3000 and 9000 Series Switches MPLS OAM Remote Code Execution Vulnerability
A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco N...
Cisco Application Policy Infrastructure Controller Unauthorized File Access Vulnerability
A vulnerability in the export policies functionality of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attack...
Cisco Application Policy Infrastructure Controller API Command Injection Vulnerability
A vulnerability in the web-based management API for Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker t...
Cisco License (Smart Software Manager) On-Prem Security Hardening Release: October 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Softwar...
Cisco Nexus 9000 Series Fabric Switches in ACI Mode Endpoint Group Contract Bypass Vulnerability
A vulnerability in the endpoint group (EPG) contract functionality of Cisco Nexus 9000 Series Fabric Switches in ACI Mode could allow an unauthenticated, rem...
Cisco Meraki Security Hardening Release: October 2026
As part of Cisco's ongoing commitment to proactive security and product quality, engineering teams conducted a comprehensive internal security review. This r...
Cisco Nexus 3000 and 9000 Series Switches NGOAM Remote Code Execution Vulnerabilities
Multiple vulnerabilities in the Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as Next Generation OAM (NGOAM), could...
Cisco Application Policy Infrastructure Controller Security Hardening Release: October 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering te...
Cisco NX-OS Software NX-API Remote Code Execution Vulnerability
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges ...
Cisco NX-OS Software Control Plane Denial of Service Vulnerability
A vulnerability in Cisco NX-OS Software could allow an unauthenticated, remote attacker to exhaust system resources, causing a denial of service (DoS) condit...
Cisco License (Smart Software Manager) On-Prem Vulnerabilities
Multiple vulnerabilities in the web-based management interface and API endpoints of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM...
Cisco NX-OS Software Security Hardening Release: October 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS Software engineering team has conducted a comprehensive inte...