Friday , October 2 2026

Cisco AsyncOS Software Flaw Let Remote Hackers Launch XSS Attack

Cisco AsyncOS Software, used by Cisco Secure Email and Web Manager, Cisco Secure Email Gateway (previously Cisco Email Security Appliance; ESA), and Cisco Secure Web Appliance (WSA), has multiple flaws in its web-based management interface.

The vulnerabilities could allow a remote attacker to launch cross-site scripting (XSS) attack against a user of the interface.

Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Nearly 100,000 Bee Cheng Hiang customers had their email addresses leaked when an employee used an AI tool to generate...
Read More
Nearly 100,000 email addresses exposed in first AI-related data breach in Singapore

Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Hackers to exploit a flaw in Zimbra mail servers that are connected to the Internet. They send special emails that...
Read More
Hackers Exploit Zimbra Mail Servers: TeamViewer patched 5 critical flaws

Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

Google has said that hackers are using two serious Citrix NetScaler security holes to get root access, set up hidden...
Read More
Google Warns of Hackers Actively Exploiting Citrix 0-Day Flaws

CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is alerting people about a major flaw in MikroTik RouterOS. This could...
Read More
CISA Warns Critical MikroTik RouterOS Flaw While Cisco SD-WAN Zero-Day Exploited in Attacks

Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

Apple has launched iOS 26.7.1 and iPadOS 26.7.1 to fix a serious zero-day flaw that it believes might have been...
Read More
Apple Zero-Day Exploited: Pentagon Data Breach Reportedly Exposes Sensitive Data of 3 Million People

JadePuffer Agentic AI targets and destroys Azure’s cloud resources

The JadePuffer ransomware group is attacking Azure users with agent-based attacks that gather information, steal passwords, and damage key components. The...
Read More
JadePuffer Agentic AI targets and destroys Azure’s cloud resources

“InfoSecCon-2026: Bangladesh’s Cybersecurity Leaders Unite to Shape a Safer Digital Future”

The 5th Edition of InfoSecCon-2026, a premier cybersecurity-focused event, has been successfully completed with the participation of cybersecurity professionals, technology...
Read More
“InfoSecCon-2026: Bangladesh’s Cybersecurity Leaders Unite to Shape a Safer Digital Future”

Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

Microsoft has fixed a serious security flaw in Azure AI Foundry that could let bad actors gain privilege escalation. The...
Read More
Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Amazon Web Services cannot restore access to its cloud-computing facility in Bahrain and ‌one of three data-hosting zones in the...
Read More
AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

A threat actor is allegedly offering a private remote code execution exploit for Fortinet FortiGate SSL VPN appliances, claiming that...
Read More
Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

What is XSS Attack?

Cross-site scripting (XSS) is an attack that lets hackers inject malicious javascript into the application or the website code.

When user input is not properly sanitized before being used in the generated output, a web page or web app becomes vulnerable to cross-site scripting attacks.

Cisco AsyncOS Software Flaw

Cisco said that “the vulnerabilities are independent of one another, exploiting one of the vulnerabilities is unnecessary before attempting to exploit another. “

Also, “a software release that is vulnerable to one of the vulnerabilities may not be vulnerable to the others,” Cisco added.

ALSO READ:

Fortinet Patches Critical RCE Vulnerability in FortiNAC

Products Affected

CVE-2023-20119: Cisco Secure Email and Web Manager – Reflected XSS

CVE-2023-20120: Cisco Secure Email and Web Manager, Cisco Secure Email Gateway, and Cisco Secure Web Appliance – Stored XSS.

CVE-2023-20028: Cisco Secure Email and Web Manager and Cisco Secure Web Appliance – Stored XSS.

CVE-2023-20119: Cisco Secure Email and Web Manager

An unauthenticated, remote attacker could execute an XSS attack against a user of the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager due to a vulnerability.

Insufficient user input validation is the cause of this vulnerability. A user of a vulnerable interface could be tricked into clicking a forged link by an attacker.

A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

CVE-2023-20120: Cisco Secure Email, Web Manager & Web Appliance

This vulnerability could allow an authenticated remote attacker to conduct an XSS attack against a user of the interface.

It is also an insufficient user input validation. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link.

If the exploit is effective, the attacker may be able to access private browser-based data or run arbitrary script code in the context of the exploited interface.

CVE-2023-20028: Cisco Secure Email, Web Manager, & Web Appliance

This vulnerability could also be able to allow an authenticated remote attacker to conduct an XSS attack against a user of the interface due to insufficient user input validation.

A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

Updates & Workarounds

Cisco said there are no workarounds available to address these vulnerabilities, and users are recommended to consider software updates. According to PSIRT, there is no active exploitation of the vulnerability recorded.

Patches Released

Cisco released patches to fix the vulnerability;

Check Also

HOOKEDGE

New HOOKEDGE Backdoor Deployed by Hackers in European Espionage

Russian-backed hacker group BlueDelta, also known as APT28, Fancy Bear, and Forest Blizzard, has used …