CISCO released security updates for two critical security flaws impacting its smart Licensing Utility that
could allow unauthenticated, remote attackers to elevate their privileges.
A brief description of the two vulnerabilities is below –
By infosecbulletin
/ Friday , August 21 2026
Central Asian government agencies have been attacked in a cyber spy operation that used a small but different range of...
Read More
By infosecbulletin
/ Friday , August 21 2026
T-Mobile’s cybersecurity team reportedly physically cut a network cable connecting compromised infrastructure to the outside world. According to Bloomberg, the move...
Read More
By infosecbulletin
/ Friday , August 21 2026
Splunk has issued security fixes for 17 weaknesses in different apps and add-ons, such as Splunk MCP Server, Splunk AI...
Read More
By infosecbulletin
/ Friday , August 21 2026
Security experts have shown that expired credit cards can still be used. A study from the University of Massachusetts Amherst,...
Read More
By infosecbulletin
/ Thursday , August 20 2026
CERT Polska has alerted that bad actors are actively exploiting a security flaw in Zimbra Collaboration Suite to execute code...
Read More
By infosecbulletin
/ Thursday , August 20 2026
Operation CameraSwarm compromised 14,500+ Dahua IP cameras mostly in Ukraine and Russia. The operation lasted for at least 35 days...
Read More
By infosecbulletin
/ Thursday , August 20 2026
The Cl0p ransomware group has listed over 40 organizations that they say they targeted in a recent attack. This attack...
Read More
By infosecbulletin
/ Thursday , August 20 2026
Oracle has put out 943 new security updates in its August 2026 Critical Security Patch Update. These updates fix problems...
Read More
By infosecbulletin
/ Wednesday , August 19 2026
Medusa ransomware hit over 500 critical infrastructure. The Cybersecurity and Infrastructure Security Agency (CISA) said on Tuesday that the Medusa...
Read More
By infosecbulletin
/ Tuesday , August 18 2026
A big security flaw in the Forminator Forms WordPress plugin might let unapproved users upload harmful PHP files. This could...
Read More
CVE-2024-20439 (CVSS score: 9.8): The presence of an undisclosed static user credential that an attacker could use to login to an affected system.
CVE-2024-20440 (CVSS score: 9.8): A vulnerability arising due to excessive logging that an attacker could exploit to access and obtain credentials from debug log files by crafting an HTTP request.
The flaws, which were discovered during internal security testing, also do not affect Smart Software Manager On-Prem and Smart Software Manager Satellite products.
Users are advised to update Cisco Smart License Utility to version 2.3.0 to fix the bug.
Cisco has also released updates to fix a command injection vulnerability in its identity services engine (ISE). This vulnerability could allow a local attacker wity authentication to run unauthenticated commands on the operating system and gain root privilege’s.
It impacts the following versions:
Cisco ISE 3.2 (3.2P7 – Sep 2024)
Cisco ISE 3.3 (3.3P4 – Oct 2024)
The company has also cautioned that there is a PoC exploit code available, although it hasn’t detected any malicious utilization of the flaw.