Fortinet All Blogs

Sovereign AI Meets Quantum-Ready Defense with FortiNDR

Tue, 22 Sep 2026 15:00:00 +0000

Explore new FortiNDR capabilities for quantum readiness, dynamic deception, agentic investigation, and sovereign AI across cloud and on-premises deployments.

FortiEndpoint Earns Certified Leader Status in the 2026 AV-Comparatives EPR Test

Wed, 16 Sep 2026 15:00:00 +0000

FortiEndpoint with EDR earns Certified Leader status in the 2026 AV-Comparatives EPR Test after detecting all 50 attack scenarios in the first stage.

From Intelligence to Disruption: Strengthening the Fight Against Cybercrime in Latin America

Tue, 15 Sep 2026 13:00:00 +0000

Fortinet joined INTERPOL, the World Economic Forum, and Paraguayan authorities to turn cyberthreat intelligence into coordinated action.

FortiSOAR 8.0 Unites Agentic AI and Automation to Revolutionize Security Operations

Mon, 14 Sep 2026 15:00:00 +0000

FortiSOAR 8.0 unites agentic AI, expert agents, and automation playbooks with built-in governance to accelerate secure, transparent security operations.

The Cybersecurity Hiring Challenge

Fri, 11 Sep 2026 15:00:00 +0000

Learn more about how your organization can develop a workforce that can continuously learn, adapt, and respond to an increasingly dangerous threat landscape.

Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers

Thu, 10 Sep 2026 13:00:00 +0000

FortiGuard Labs examines how a new Casbaneiro campaign targeting Latin America uses geofencing and distributed servers to evade analysis and detection

FortiManagement Cloud: Centralized Network and Security Control for Distributed SMB Operations

Wed, 9 Sep 2026 15:00:00 +0000

Learn how FortiManagement Cloud unifies cloud management and analytics for FortiGate, FortiSwitch, FortiAP, and FortiExtender across distributed secure networks.

Fortinet Joins Project Watershed 250 to Strengthen National Water Cybersecurity Infrastructure

Fri, 4 Sep 2026 15:00:00 +0000

Learn how Fortinet is helping Project Watershed 250 bring government and industry together to strengthen the cybersecurity and resilience of U.S. water systems

Fortinet and FIRST: Strengthening Cyber Resilience through Global Collaboration

Thu, 3 Sep 2026 15:00:00 +0000

Fortinet and FIRST CORE are strengthening global cyber resilience through trusted collaboration, training, and incident response capacity building.

Someone Else Is Using Your AI

Thu, 3 Sep 2026 13:00:00 +0000

FortiCNAPP analyzes an AWS LLMjacking incident involving a leaked administrator key and unauthorized access to Amazon Bedrock.

  


  

Microsoft Security Blog

Unmasking EvilTokens: Getting to the root of device code phishing

Tue, 22 Sep 2026 15:00:00 +0000

EvilTokens has quickly become one of the top PhaaS platforms, enabling device code phishing attacks through AI-assisted lures, automated infrastructure, and token theft. In collaboration with partners, Microsoft Digital Crimes Unit (DCU) facilitated a disruption of EvilTokens infrastructure and operations.

The post Unmasking EvilTokens: Getting to the root of device code phishing appeared first on Microsoft Security Blog.

From guidance to action: Security fundamentals that materially reduce risk 

Thu, 17 Sep 2026 17:00:00 +0000

AI has made fundamental changes to the operating environment for cybersecurity. Explore exposure management guidance on recommended controls and take action and stay ahead of cyberthreats.

The post From guidance to action: Security fundamentals that materially reduce risk  appeared first on Microsoft Security Blog.

Improving email security outcomes with real-world Microsoft Defender insights

Thu, 17 Sep 2026 16:00:00 +0000

The latest email security benchmarking reports show strong Microsoft Defender performance across pre-delivery and post-delivery scenarios and reveal where threats and defenses continue to evolve.

The post Improving email security outcomes with real-world Microsoft Defender insights appeared first on Microsoft Security Blog.

Protecting organizations from AI-assisted executive impersonation and invoice fraud

Thu, 10 Sep 2026 17:23:05 +0000

Microsoft examines an AI-assisted business email compromise campaign that used executive impersonation and fake invoices to target finance teams with ACH payment fraud.

The post Protecting organizations from AI-assisted executive impersonation and invoice fraud appeared first on Microsoft Security Blog.

Detect and disrupt AI-themed attacks with Microsoft Defender

Thu, 10 Sep 2026 16:00:00 +0000

See how Microsoft Defender detects and disrupts AI-themed phishing, malware, and multi-stage attacks across the attack chain.

The post Detect and disrupt AI-themed attacks with Microsoft Defender appeared first on Microsoft Security Blog.

Threat matrix: Mapping threats across cloud web applications

Wed, 09 Sep 2026 21:30:00 +0000

Microsoft introduces the Cloud Web Applications Threat Matrix, a MITRE ATT&CK-aligned framework that helps defenders understand, prioritize, and mitigate threats to cloud-hosted web apps and serverless platforms.

The post Threat matrix: Mapping threats across cloud web applications appeared first on Microsoft Security Blog.

Passkey-themed social engineering leads to identity and cloud compromise

Wed, 09 Sep 2026 17:41:18 +0000

Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA persistence, abuse Microsoft Graph for reconnaissance, and access SharePoint, OneDrive, and email data, along with key detection and mitigation guidance.

The post Passkey-themed social engineering leads to identity and cloud compromise appeared first on Microsoft Security Blog.

How to secure edge AI in customer-owned environments

Fri, 04 Sep 2026 19:10:10 +0000

As AI moves into customer-owned environments, organizations need new ways to verify the systems, software, and AI assets they trust before releasing sensitive data, credentials, and models.

The post How to secure edge AI in customer-owned environments appeared first on Microsoft Security Blog.

ASCII smuggling crosses over from AI prompt injection to phishing evasion

Thu, 03 Sep 2026 16:00:00 +0000

Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them.

The post ASCII smuggling crosses over from AI prompt injection to phishing evasion appeared first on Microsoft Security Blog.

Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

Wed, 02 Sep 2026 22:51:18 +0000

Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based implant. Learn how attackers move from social engineering to lateral movement using legitimate tools, and how Microsoft Defender helps detect and disrupt the activity.

The post Impersonating IT support: how threat actors turn a remote session into enterprise-wide access appeared first on Microsoft Security Blog.

  


  

HPE - Aruba
Networking articles

HPE Aruba Networking and Eleven transform mission-critical hotel Wi-Fi

Fri, 18 Sep 2026 15:09:47 GMT

Securing the future of public service: Building government WAN for the AI era

Wed, 16 Sep 2026 17:42:48 GMT

HPE Juniper Networking QFX Switches qualified with VAST CNode, DBox, & EBox clusters

Fri, 11 Sep 2026 12:41:32 GMT

Bringing AI-native operations to HPE Networking EdgeConnect with SASE Copilot

Thu, 10 Sep 2026 07:51:36 GMT

The self-driving network: Transforming hospitality through AI-native operations

Thu, 10 Sep 2026 07:07:09 GMT

Your segmentation strategy is obsolete in a cloud and identity-first world

Thu, 27 Aug 2026 15:21:45 GMT

Identity has outgrown the network: Why access must move beyond VPN

Wed, 19 Aug 2026 14:55:36 GMT

Network fabrics for AI inference using HPE Juniper Networking QFX5140 Switches

Thu, 13 Aug 2026 18:22:20 GMT

Designing AI inferencing network fabrics for tomorrow’s unpredictable network demands

Thu, 13 Aug 2026 18:11:16 GMT

HPE Networking expands private 5G solution with powerful new small cell radios

Thu, 13 Aug 2026 12:06:35 GMT

The five key benefits of a unified secure access service edge (SASE) solution

Thu, 13 Aug 2026 11:40:49 GMT

HPE Networking expands private 5G solution with powerful new small cell radios

Wed, 12 Aug 2026 10:06:53 GMT

Hybrid mesh firewalls: A CISO framework for evaluation

Wed, 12 Aug 2026 01:04:22 GMT

Unleashing AI with AMD Pollara Packet Spraying on HPE Juniper Networking QFX Switches

Thu, 06 Aug 2026 13:02:52 GMT

Compliance is increasing the risk of real-world attacks, not reducing it

Fri, 24 Jul 2026 17:18:30 GMT

Announcing AOS 8 support for HPE Aruba Networking Wi-Fi 7 Access Points

Tue, 14 Jul 2026 20:40:57 GMT

What HITEC 2026 revealed about the future of hospitality technology

Tue, 14 Jul 2026 16:49:35 GMT

The network engineer's next evolution: 5 skills for an AI-powered world

Wed, 08 Jul 2026 09:23:58 GMT

What’s new in HPE Networking EdgeConnect release 9.7 to simplify SD-WAN and SASE

Tue, 14 Jul 2026 05:47:01 GMT

Juniper SRX firewalls recognized by CyberRatings.org and NSS Labs—again

Tue, 07 Jul 2026 12:17:29 GMT

  


  

Cisco Security Advisory

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Logging Denial of Service Vulnerability

2026-09-18 15:50:56.0

A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a denial of service (DoS) condition.

This vulnerability is due to improper rate limiting for syslog message 419002. An attacker could exploit this vulnerability by sending a flood of TCP synchronization (SYN) packets to an affected device. A successful exploit could allow the attacker to cause high CPU utilization, resulting in performance degradation. 

Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asa-ftd-logging-dos-ZXXNesfN

This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026.

<br/>Security Impact Rating: High <br/>CVE: CVE-2026-20154

Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026

2026-09-18 15:50:33.0

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software and Cisco Secure Firewall Management Center (FMC) Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.  

These vulnerabilities were found during internal testing. Two of them are known to be actively exploited. For more information, see the following advisories: Cisco Secure Firewall Management Center Software Static Credential Vulnerability and Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability. To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures Identifier (CVE ID) to each CWE grouping.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-asaftdfmc-uvpPROhN

This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories

<br/>Security Impact Rating: Critical <br/>CVE: CVE-2026-20329,CVE-2026-20330,CVE-2026-20331,CVE-2026-20332,CVE-2026-20333,CVE-2026-20334,CVE-2026-20335,CVE-2026-20336

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Secure Firewall 3100 and 4200 Series DTLS Denial of Service Vulnerability

2026-09-18 15:50:31.0

A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Secure Firewall 3100 Series and 4200 Series devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

This vulnerability is due to improper resource management when processing certain DTLS messages. An attacker could exploit this vulnerability by sending a crafted stream of DTLS traffic to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition.

Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-dtls-dos-Kp57HkyO

This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026.

<br/>Security Impact Rating: High <br/>CVE: CVE-2026-20250

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Certificate Authentication Denial of Service Vulnerability

2026-09-18 15:50:30.0

A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2) for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly.

This vulnerability is due to a logic error during the certificate authentication phase of the IKEv2 connection setup. An attacker could exploit this vulnerability by attempting to establish an IKEv2 VPN connection with a crafted certificate. A successful exploit could allow the attacker to cause the IKEv2 process to crash, causing a denial of service (DoS) condition.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-ikev2cert-dos-uWyc2xtv

This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026.

<br/>Security Impact Rating: High <br/>CVE: CVE-2026-20249

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Object Group Access Control List Bypass Vulnerabilities

2026-09-18 15:50:30.0

Multiple vulnerabilities in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access controls.

These vulnerabilities are due to a logic error in populating group access control policies (ACPs) with OGS configured. An attacker could exploit these vulnerabilities by sending traffic that should be blocked through the device. A successful exploit could allow the attacker to bypass access controls and reach devices in protected networks.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-acl-bypass-8p6vFvw

This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026.

<br/>Security Impact Rating: Medium <br/>CVE: CVE-2026-20120,CVE-2026-20121

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software TCP DNS Denial of Service Vulnerability

2026-09-18 15:50:29.0

A vulnerability in the DNS over TCP implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the TCP DNS response handler to unexpectedly restart, causing the device to reload.

This vulnerability is due to a logic error when parsing a DNS query and tracking the size of the incoming buffers. An attacker could exploit this vulnerability by formatting a crafted reply to a DNS query sent from the targeted device. A successful exploit could allow the attacker to cause the device to reload, causing a denial of service (DoS) condition.

Note: The attacker must be able to respond to DNS queries from the device, either by controlling the DNS service or through a machine-in-the-middle attack.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-tcpdns-dos-p6dUnjr5

This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026.

<br/>Security Impact Rating: Medium <br/>CVE: CVE-2026-20248

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software EIGRP Denial of Service Vulnerability

2026-09-18 15:50:28.0

A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.

This vulnerability is due to improper resource management when handling EIGRP update messages. An attacker could exploit this vulnerability by sending crafted EIGRP updates at a high rate to an affected device. A successful exploit could allow the attacker to trigger a memory leak that will eventually cause the affected device to reload unexpectedly.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-eigrp-dos-GOhNejSj

This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026.

<br/>Security Impact Rating: High <br/>CVE: CVE-2026-20222

Cisco IOS XR Software Security Hardening Release: September 2026

2026-09-17 21:13:28.0

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.  

These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures identifier (CVE ID) to each CWE grouping.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM

<br/>Security Impact Rating: Critical <br/>CVE: CVE-2026-20274,CVE-2026-20275,CVE-2026-20276,CVE-2026-20277,CVE-2026-20278,CVE-2026-20279,CVE-2026-20280

Cisco Secure Email Gateway SQL Injection Vulnerability

2026-09-17 16:47:12.0

A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.

This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-inj-2bLVGmhX

<br/>Security Impact Rating: Critical <br/>CVE: CVE-2026-76461

Cisco Advance Notification for Publication of September 16, 2026, Security Advisories

2026-09-16 16:07:26.0

On September 16, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the advisories that are listed in the following tables. 

To remediate these vulnerabilities, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories.

For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the Foundation: A Predictable, Customer-Focused Response to AI-Accelerated Vulnerability Discovery.

Cisco Identity Services Engine

Title CVE ID SIR Base Score
Cisco Identity Services Engine Hardening Release: September 2026 CVE-2026-20130
CVE-2026-20192
CVE-2026-20194
CVE-2026-20234
CVE-2026-20237
CVE-2026-20287
Critical 10.0
Cisco Identity Services Engine Vulnerabilities CVE-2026-76423
CVE-2026-76425
CVE-2026-76426
CVE-2026-76427
CVE-2026-76428
CVE-2026-76424
Critical 10.0
Cisco Identity Services Engine Authentication Bypass Vulnerability CVE-2026-76460 Critical 10.0
Cisco Identity Services Engine Remote Code Execution Vulnerabilities CVE-2026-20211
CVE-2026-20176
CVE-2026-20307
Critical 9.9
Cisco Identity Services Engine Authenticated Remote Code Execution and API Vulnerabilities CVE-2026-20282
CVE-2026-20283
CVE-2026-20284
Critical 9.1
Cisco Identity Services Engine Command Injection Vulnerabilities CVE-2026-20306
CVE-2026-20305
Critical 9.1
Cisco Identity Services Engine RADIUS Denial of Service Vulnerability CVE-2026-20352 High 8.6
Cisco Identity Services Engine SQL Injection Vulnerabilities CVE-2026-20247
CVE-2026-20300
High 7.5
Cisco Identity Services Engine Cross-Site Scripting Vulnerability

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL VPN Denial of Service Vulnerability

2026-09-16 16:05:50.0

Update for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv) models. However, it was later found that this vulnerability affects all Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software platforms. 

A vulnerability in the VPN and management web servers of the Cisco Secure Firewall ASA Software and Cisco Secure FTD Software platforms could allow an unauthenticated, remote attacker to cause an affected device to run out of system memory or buffer blocks, which in turn could cause SSL VPN connection processing to slow down and eventually cease altogether.

This vulnerability is due to a lack of proper memory management for new incoming SSL/TLS connections. An attacker could exploit this vulnerability by sending a large number of new incoming SSL/TLS connections to the targeted device. A successful exploit could allow the attacker to deplete system memory or buffers, resulting in a denial of service (DoS) condition. The memory or buffers could be reclaimed slowly if the attack traffic is stopped, but a manual reload may be required to restore operations quickly. 

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftdvirtual-dos-MuenGnYR

This advisory is part of the October 2024 release of the Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: October 2024 Semiannual Cisco ASA, FMC, and FTD Software Security Advisory Bundled Publication.

<br/>Security Impact Rating: High <br/>CVE: CVE-2024-20260

Cisco Secure Firewall Management Center Software Static Credential Vulnerability

2026-09-16 16:05:47.0

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.

This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user. 

Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.  

Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. 

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh

This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026.

<br/>Security Impact Rating: High <br/>CVE: CVE-2026-20316

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability

2026-09-16 16:05:42.0

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. 

This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-vpn-dos-dzv4mQFF

This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026.

<br/>Security Impact Rating: High <br/>CVE: CVE-2026-20349

Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability

2026-09-16 16:03:19.0

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. 

This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device. 

Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2

This advisory is part of the March 2026 release of the Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication. For a complete list of the advisories and links to them, see Cisco Event Response: March 2026 Semiannual Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication.

<br/>Security Impact Rating: Critical <br/>CVE: CVE-2026-20079

Cisco Identity Services Engine Information Disclosure Vulnerability

2026-09-16 16:00:00.0

A vulnerability in the API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.

This vulnerability is due to insufficient validation of user-supplied parameters in API requests. An attacker could exploit this vulnerability by sending a crafted API request to an affected device. A successful exploit could allow the attacker to gain access to sensitive information, including hashed credentials that could be used in future attacks.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-inf-disc-LFWvcCu

This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Identity Services Engine, see Cisco Identity Services Engine Security Hardening Release: September 2026.

<br/>Security Impact Rating: Medium <br/>CVE: CVE-2026-20235

Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Execution Vulnerability

2026-09-16 16:00:00.0

A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary commands as root on an affected device.

This vulnerability is due to insecure deserialization of a user-supplied Java byte stream from a host that is configured in the external database access list. An attacker could exploit this vulnerability by sending a crafted, serialized Java byte stream to a specific TCP port of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the device and elevate privileges to root.

Notes:

  • This vulnerability can be exploited only by an attacker who has control of a host in the external database access list.
  • If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. 

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-javarce-y2NypXwk

This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026.

<br/>Security Impact Rating: Critical <br/>CVE: CVE-2026-20242

Cisco Identity Services Engine Remote Code Execution Vulnerabilities

2026-09-16 16:00:00.0

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit these vulnerabilities, the attacker must have valid administrative credentials.

For more information about these vulnerabilities, see the Details section of this advisory.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-rce-se7bYU57

This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Identity Services Engine, see Cisco Identity Services Engine Security Hardening Release: September 2026.

<br/>Security Impact Rating: Critical <br/>CVE: CVE-2026-20176,CVE-2026-20211,CVE-2026-20307

Cisco Identity Services Engine Authenticated Remote Code Execution and API Vulnerabilities

2026-09-16 16:00:00.0

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct SQL injections, modify data, or execute arbitrary commands on the underlying operating system on an affected device.

For more information about these vulnerabilities, see the Details section of this advisory.

Note: For CVE-2026-20282 and CVE-2026-20283, Cisco has assigned a Security Impact Rating (SIR) of High rather than Medium as the scores indicate. The reason is that it is easy to get to root from the achieved privilege level.

Cisco has released software updates that address these vulnerabilities. There are workarounds that address one of these vulnerabilities.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-mult-vul-ymSsTLCc

This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Identity Services Engine, see Cisco Identity Services Engine Security Hardening Release: September 2026.

<br/>Security Impact Rating: Critical <br/>CVE: CVE-2026-20282,CVE-2026-20283,CVE-2026-20284

Cisco Identity Services Engine Vulnerabilities

2026-09-16 16:00:00.0

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to bypass authentication to the REST API, achieve remote code execution, perform SQL injection, and conduct XML External Entity injection attacks on an affected device.

For more information about these vulnerabilities, see the Details section of this advisory.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-hrP9jQSQ

This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Identity Services Engine, see Cisco Identity Services Engine Security Hardening Release: September 2026.

<br/>Security Impact Rating: Critical <br/>CVE: CVE-2026-76423,CVE-2026-76424,CVE-2026-76425,CVE-2026-76426,CVE-2026-76427,CVE-2026-76428

Cisco Identity Services Engine RADIUS Denial of Service Vulnerability

2026-09-16 16:00:00.0

A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

This vulnerability is due to improper handling of certain RADIUS requests. An attacker could exploit this vulnerability by sending a crafted RADIUS request directly to an affected device. A successful exploit could allow the attacker to cause the ISE node to become unavailable. For single node deployments in that condition, endpoints that have not already authenticated would be unable to access the network until the node comes back up on its own.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-RADIUS-dos-wR3hYPMw

This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Identity Services Engine, see Cisco Identity Services Engine Security Hardening Release: September 2026.

<br/>Security Impact Rating: High <br/>CVE: CVE-2026-20352

Cisco Secure Firewall Management Center and Secure Firewall Threat Defense Software sftunnel Vulnerabilities

2026-09-16 16:00:00.0

Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated attacker to perform an sftunnel authentication bypass or sftunnel denial of service (DoS) attack.

For more information about these vulnerabilities, see the Details section of this advisory.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmcftd-sftun-multivulns-WGVHOrN3

This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026.

<br/>Security Impact Rating: High <br/>CVE: CVE-2026-20295,CVE-2026-20323

Cisco Secure Firewall Threat Defense Software TLS 1.3 Denial of Service Vulnerability

2026-09-16 16:00:00.0

A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.

This vulnerability is due to improper buffer management during the TLS 1.3 connection. An attacker could exploit this vulnerability by sending a crafted TLS 1.3 packet to an affected system through a TLS 1.3-enabled listening socket. A successful exploit could allow the attacker to cause the LINA process to crash, which would cause the device to reload. The reload can happen before or after authentication of the connection.

Note: TLS 1.3 connections include both data traffic and user-management traffic.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-tls1.3-dos-dLxwFWgF

This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026.

<br/>Security Impact Rating: High <br/>CVE: CVE-2026-20135

Cisco Identity Services Engine 802.1X Session Hijack and Information Disclosure Vulnerabilities

2026-09-16 16:00:00.0

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an unauthenticated, local attacker to either conduct an authentication bypass or disclose sensitive information.

For more information about these vulnerabilities, see the Details section of this advisory.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-vuln-kWLeNnRD

This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Identity Services Engine, see Cisco Identity Services Engine Security Hardening Release: September 2026.

<br/>Security Impact Rating: Medium <br/>CVE: CVE-2026-20071,CVE-2026-20072

Cisco Secure Firewall Management Center Software Vulnerabilities

2026-09-16 16:00:00.0

Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software could allow a remote attacker to gain root access, download sensitive files, perform a SQL injection attack, or cause a denial of service (DoS) condition.

For more information about these vulnerabilities, see the Details section of this advisory.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-mulivulns-4PsnFwvx

This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026.

<br/>Security Impact Rating: Critical <br/>CVE: CVE-2026-20340,CVE-2026-20341,CVE-2026-20342,CVE-2026-20343,CVE-2026-20344

Cisco ThousandEyes Virtual Appliance Authenticated Web Interface Command Injection Vulnerability

2026-09-16 16:00:00.0

A vulnerability in the web-based management interface of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to inject arbitrary operating system commands.

This vulnerability is due to improper validation of user-supplied input to the web-based management interface. An attacker could exploit this vulnerability by saving configuration details that contain malicious values. A successful exploit could allow the attacker to execute arbitrary operating system commands with root privileges. To exploit this vulnerability, the attacker must have valid administrative credentials.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-teva-os-command-W4GAO6jp

<br/>Security Impact Rating: Medium <br/>CVE: CVE-2026-20350

Cisco Secure Firewall Threat Defense Software Snort 2 SSL/TLS Denial of Service Vulnerability

2026-09-16 16:00:00.0

A vulnerability in SSL/TLS certificate parsing in the Snort 2 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 2 Detection Engine to restart.

This vulnerability is due to incomplete validation of the SSL certificate. An attacker could exploit this vulnerability by sending a crafted SSL connection setup request to be parsed by Snort 2. A successful exploit could allow the attacker to cause the Snort 2 Detection Engine to restart unexpectedly, resulting in a denial of service (DoS) condition.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ftd-snort2-ssldos-Mw7WYX9c

This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026.

<br/>Security Impact Rating: Medium <br/>CVE: CVE-2026-20290

Cisco Identity Services Engine Hardening Release: September 2026

2026-09-16 16:00:00.0

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.  

These vulnerabilities were found during internal testing. One of them is known to be actively exploited. For more information, see Cisco Identity Services Engine Authentication Bypass Vulnerability. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures identifier (CVE ID) to each CWE grouping.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ise-XU5EwX5T

This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories

<br/>Security Impact Rating: Critical <br/>CVE: CVE-2026-20130,CVE-2026-20192,CVE-2026-20194,CVE-2026-20234,CVE-2026-20237,CVE-2026-20287

Cisco Identity Services Engine Multiple Path Traversal Vulnerabilities

2026-09-16 16:00:00.0

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to conduct path traversal attacks on an affected device.

For more information about these vulnerabilities, see the Details section of this advisory.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multi-traversal-WDTgYCdn

This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Identity Services Engine, see Cisco Identity Services Engine Security Hardening Release: September 2026.

<br/>Security Impact Rating: Medium <br/>CVE: CVE-2026-76431,CVE-2026-76432,CVE-2026-76433,CVE-2026-76434

Cisco Identity Services Engine Cross-Site Scripting Vulnerability

2026-09-16 16:00:00.0

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface.

This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-xss-Uz9VWRQ

This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Identity Services Engine, see Cisco Identity Services Engine Security Hardening Release: September 2026.

<br/>Security Impact Rating: Medium <br/>CVE: CVE-2026-20309

Cisco Identity Services Engine Command Injection Vulnerabilities

2026-09-16 16:00:00.0

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform command injection attacks on an affected device and execute arbitrary commands as the root user. To exploit these vulnerabilities, the attacker must have valid administrative credentials.

For more information about these vulnerabilities, see the Details section of this advisory.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-cmd-inj-e2CuZCYZ

This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Identity Services Engine, see Cisco Identity Services Engine Security Hardening Release: September 2026.

<br/>Security Impact Rating: Critical <br/>CVE: CVE-2026-20305,CVE-2026-20306

Cisco Identity Services Engine Authentication Bypass Vulnerability

2026-09-16 16:00:00.0

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication.

This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5

This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Identity Services Engine, see Cisco Identity Services Engine Security Hardening Release: September 2026.

<br/>Security Impact Rating: Critical <br/>CVE: CVE-2026-76460

Cisco Identity Services Engine Authorization Bypass Vulnerabilities

2026-09-16 16:00:00.0

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device.

These vulnerabilities are due to the lack of server-side validation of Administrator permissions. An attacker could exploit these vulnerabilities by submitting a crafted HTTP request to an affected system. A successful exploit could allow the attacker to modify descriptions of files on specific pages. To exploit these vulnerabilities, an attacker would need valid Administrator credentials.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-auth-bypass-1-MxcTNgwx

This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Identity Services Engine, see Cisco Identity Services Engine Security Hardening Release: September 2026.

<br/>Security Impact Rating: Medium <br/>CVE: CVE-2026-20285,CVE-2026-20286

Cisco Secure Firewall Management Center Software Vulnerabilities

2026-09-16 16:00:00.0

Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software could allow a remote attacker to gain root access and perform session forgery or session impersonation.

For more information about these vulnerabilities, see the Details section of this advisory.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc2-multivulns-HXgcqRG

This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026.

<br/>Security Impact Rating: Critical <br/>CVE: CVE-2026-76412,CVE-2026-76413,CVE-2026-76420

Cisco Nexus Dashboard Software Security Hardening Release: September 2026

2026-09-16 16:00:00.0

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.

These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures identifier (CVE ID).

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.  

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ndw1-psFvnrg

<br/>Security Impact Rating: Critical <br/>CVE: CVE-2026-20322,CVE-2026-20325,CVE-2026-20326,CVE-2026-20360,CVE-2026-20361,CVE-2026-76409

Cisco BroadWorks CommPilot Application Software Authorization Bypass Vulnerability

2026-09-16 16:00:00.0

A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker with low privileges to alter configurations on an affected device.

This vulnerability is due to missing authorization checks. An attacker could exploit this vulnerability by sending a crafted HTTP request. A successful exploit could allow the attacker to alter configurations on select pages.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-auth-bypass-broadwor-57m9dmm5

<br/>Security Impact Rating: Medium <br/>CVE: CVE-2026-76438

Cisco Identity Services Engine Authentication Bypass Vulnerabilities

2026-09-16 16:00:00.0

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to access or manipulate data, obtain sensitive information, or cause a reload of certificate and key material on an affected device.

For more information about these vulnerabilities, see the Details section of this advisory.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multiauth-bypass-sgD2HbL4

This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Identity Services Engine, see Cisco Identity Services Engine Security Hardening Release: September 2026.

<br/>Security Impact Rating: Medium <br/>CVE: CVE-2026-76439,CVE-2026-76444,CVE-2026-76446,CVE-2026-76447

Cisco Identity Services Engine SQL and HQL Injection Vulnerabilities

2026-09-16 16:00:00.0

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct SQL or HQL injection attacks on an affected device.

These vulnerabilities are due to insufficient validation of user-supplied input to the affected APIs before it is used to build database queries. An attacker could exploit these vulnerabilities by sending a crafted request to an affected device. A successful exploit could allow the attacker to execute arbitrary SQL or HQL queries against the underlying database, which could allow the attacker to view or modify data that they are not authorized to access. To exploit these vulnerabilities, the attacker must have valid administrative credentials. 

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-multisql-inject-JnHK54Rq

This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Identity Services Engine, see Cisco Identity Services Engine Security Hardening Release: September 2026.

<br/>Security Impact Rating: Medium <br/>CVE: CVE-2026-76448,CVE-2026-76449,CVE-2026-76450,CVE-2026-76451

Cisco Identity Services Engine SQL Injection Vulnerabilities

2026-09-16 16:00:00.0

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow a remote attacker to conduct SQL injection attacks on an affected device.

For more information about these vulnerabilities, see the Details section of this advisory.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ise-sql-inj-3QTKR947

This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Identity Services Engine, see Cisco Identity Services Engine Security Hardening Release: September 2026.

<br/>Security Impact Rating: High <br/>CVE: CVE-2026-20247,CVE-2026-20300

Cisco Secure Firewall Management Center Software sftunnel Root Arbitrary Code Execution Vulnerability

2026-09-16 16:00:00.0

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands as root.

This vulnerability exists because a registered sftunnel peer has incorrect permissions to write an arbitrary file to any location on the device. An attacker could exploit this vulnerability by hijacking the sftunnel communication connection or being a valid registered sftunnel peer and sending an sftunnel command to write a malicious file to the disk of an affected device. A successful exploit could allow the attacker to write a file to the device that is executed with root privileges. To exploit this vulnerability, the attacker must have valid user credentials on the affected device.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-sftunn-codex-c3O4Jft2

This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026.

<br/>Security Impact Rating: Critical <br/>CVE: CVE-2026-20324

Cisco Integrated Management Controller Argument Injection Vulnerabilities

2026-09-15 20:36:48.0

Multiple vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root

For more information about these vulnerabilities, see the Details section of this advisory.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-cimc-arg-inject-upSHdMfU

<br/>Security Impact Rating: High <br/>CVE: CVE-2026-20200,CVE-2026-20288

Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability

2026-09-15 20:34:44.0

A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin or an unauthenticated attacker with physical access to an affected device to bypass UEFI Secure Boot validation checks and execute unauthorized software.

This vulnerability is due to the availability of memory write commands in the UEFI Shell while UEFI Secure Boot is enabled on a device. An attacker could exploit this vulnerability by selecting the UEFI Shell boot option at boot time and using available shell commands to modify UEFI memory variables. A successful exploit could allow the attacker to manipulate the preboot environment, overwrite UEFI Secure Boot-related memory values, and execute unauthorized software on the affected device.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucs-uefi-sb-bypass-eb6xC5GW

<br/>Security Impact Rating: High <br/>CVE: CVE-2026-20293

Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026

2026-09-14 16:00:00.0

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.

These vulnerabilities were found during internal testing. One of them is known to be actively exploited. For more information, see Cisco Secure Email Gateway SQL Injection Vulnerability. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures identifier (CVE ID) to each CWE grouping.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-esa-dfCrfXkm

<br/>Security Impact Rating: Critical <br/>CVE: CVE-2026-20353,CVE-2026-76440,CVE-2026-76441,CVE-2026-76442,CVE-2026-76443

Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities

2026-09-08 11:22:17.0

Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages.

These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the attacker to obtain plaintext content from the encrypted communication.

There are no workarounds that address these vulnerabilities.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-esa-smime-disc-dzw4rEdY

<br/>Security Impact Rating: Medium <br/>CVE: CVE-2026-20354,CVE-2026-20355

Cisco Advance Notification for Publication of September 2, 2026, Security Advisories

2026-09-02 16:02:37.0

On September 2, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories:

Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score
Cisco IOS XR Software Security Hardening Release: September 2026 CVE-2026-20277
CVE-2026-20278
CVE-2026-20280
CVE-2026-20279
CVE-2026-20276
CVE-2026-20275
CVE-2026-20274
Critical 9.8
Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability CVE-2026-20212 Critical  9.8
Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability CVE-2026-20281 High 7.5
Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities CVE-2026-20355
CVE-2026-20354
Medium 5.9

To remediate the vulnerabilities that were disclosed on September 2, 2026, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories.

For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the Foundation: A Predictable, Customer-Focused Response to AI-Accelerated Vulnerability Discovery.

<br/>Security Impact Rating: Informational

Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability

2026-09-02 16:00:00.0

A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session Initiation Protocol (SIP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.

This vulnerability is due to improper memory management when an affected device processes HTTP packets. An attacker could exploit this vulnerability by sending a continuous stream of crafted HTTP packets to the device. A successful exploit could allow the attacker to cause the affected device to continuously consume memory, resulting in a DoS condition. A manual reboot of the device is required to recover from this condition.

Note: For this vulnerability to be exploitable, the phone must be registered to Cisco Unified Communications Manager (Unified CM) and have Web Access enabled. Web Access is disabled by default.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-phone-dos-txMYNRzv

<br/>Security Impact Rating: High <br/>CVE: CVE-2026-20281

Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability

2026-09-02 16:00:00.0

A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges.

This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device and send crafted input that could be executed as code with root privileges. The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload.

Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-n9k-s1-rce-EH8dEtr

<br/>Security Impact Rating: Critical <br/>CVE: CVE-2026-20212

Cisco Crosswork Security Hardening Release: August 2026

2026-08-21 16:54:40.0

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. 

These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures Identifier (CVE ID) to each CWE grouping.

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. 

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-crosswork-UzDTU9Vh

<br/>Security Impact Rating: Critical <br/>CVE: CVE-2026-20030,CVE-2026-20357,CVE-2026-20358,CVE-2026-20359

Cisco Advance Notification for Publication of August 19, 2026, Security Advisories

2026-08-19 16:00:40.0

On August 19, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories:

Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score
Cisco Crosswork Security Hardening Release: August 2026 CVE-2026-20030
CVE-2026-20357
CVE-2026-20358
CVE-2026-20359
Critical 10.0
Cisco Secure Workload Software Security Hardening Release: August 2026 CVE-2026-20231
CVE-2026-20315
CVE-2026-20317
CVE-2026-20318
CVE-2026-20319
Critical 10.0
Cisco BroadWorks Out-of-Band Blind XML External Entity Injection Vulnerability CVE-2026-20320 High 7.5
Cisco Unified Intelligence Center SQL Injection Vulnerability CVE-2026-20327 Medium 6.5
Cisco RoomOS Stack Overflow Vulnerability CVE-2026-20302 Medium 6.1
Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerability CVE-2026-20232 Medium 5.4
Cisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability CVE-2026-20177 Medium 5.3
Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Server-Side Request Forgery Vulnerability CVE-2026-20314 Medium 5.0

To fully remediate the vulnerabilities that were disclosed on August 19, 2026, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories.

For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the Foundation: A Predictable, Customer-Focused Response to AI-Accelerated Vulnerability Discovery.

<br/>Security Impact Rating: Informational

Cisco Secure Workload Software Security Hardening Release: August 2026

2026-08-19 16:00:00.0

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. 

These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures identifier (CVE ID).

Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-csw1-shSvndWP

<br/>Security Impact Rating: Critical <br/>CVE: CVE-2026-20231,CVE-2026-20315,CVE-2026-20317,CVE-2026-20318,CVE-2026-20319

Cisco BroadWorks Out-of-Band Blind XML External Entity Injection Vulnerability

2026-08-19 16:00:00.0

A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system.

This vulnerability exists because XML entries are improperly parsed due to external entity resolution being allowed by default. An attacker could exploit this vulnerability by sending a crafted XML message to the Open Client Interface – Provisioning (OCI-P) service. A successful exploit could allow the attacker to view sensitive files from the filesystem with the privileges of the Cisco BroadWorks user.

Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.

This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bworks-xxe-uwUd7CEt

<br/>Security Impact Rating: High <br/>CVE: CVE-2026-20320

  


  

Google Actualités - cyber sécurité

Cyber-sécurité et économie numérique : la protection des données, pilier de la croissance des entreprises - lessentieldeleco.fr

Mon, 14 Sep 2026 17:14:40 GMT

Cyber Resilience Act : l’Europe impose de nouvelles règles de sécurité numérique - lopinion.fr

Thu, 10 Sep 2026 07:00:00 GMT

Cyber Resilience Act : l’UE renforce la sécurité des objets connectés - lecourrier.vn

Sun, 13 Sep 2026 09:30:00 GMT

AlerteCyber : Faille de sécurité critique dans SPIP - Cybermalveillance.gouv.fr

Thu, 27 Aug 2026 07:00:00 GMT

Incident de sécurité affectant les données de certains élèves de l'Éducation nationale - Ministère de l'Éducation nationale

Tue, 14 Apr 2026 07:00:00 GMT

Cyber Resilience Act : Pourquoi la sécurité “by design” n’est viable que si elle est positionnée au cœur de la conception du matériel informatique - usine-digitale.fr

Sun, 16 Aug 2026 07:00:00 GMT

Cyber-sécurité : l’État fiche mais ne protège pas 1/4 - l'Avant-Garde.fr

Thu, 27 Aug 2026 07:00:00 GMT

PME : et si le chemin vers la résilience cyber commençait par la préparation ? - WeLiveSecurity

Mon, 24 Aug 2026 07:00:00 GMT

Cybersécurité | Les Rencontres Défenses et Cyber au cœur de la sécurité numérique - defense.gouv.fr

Fri, 10 Apr 2026 07:00:00 GMT

Cyberattaques au fisc : comment Bercy compte renforcer sa sécurité ? - Capital.fr

Wed, 19 Aug 2026 07:00:00 GMT