<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cisco on CuraSec</title><link>https://curasec.metacog.co.kr/tags/cisco/</link><description>Recent content in Cisco on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 21 Aug 2026 11:38:25 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/cisco/index.xml" rel="self" type="application/rss+xml"/><item><title>Cisco Patches Five CVSS 10.0 Flaws in Crosswork and Secure Workload</title><link>https://curasec.metacog.co.kr/insights/2026-08-21-cisco-patches-nine-crosswork-and-secure-workload-flaws-five/</link><pubDate>Fri, 21 Aug 2026 11:38:25 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-21-cisco-patches-nine-crosswork-and-secure-workload-flaws-five/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Five CVSS 10.0 flaws are severe on paper, but no KEV listing, PoC, or active exploitation is signaled — schedule patching of Crosswork Data Gateway, Crosswork Network Controller, Crosswork Planning, and Secure Workload this cycle rather than as emergency response.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>Cisco ASA and FTD Remote DoS Flaw Exploited in the Wild (CVE-2026-20349)</title><link>https://curasec.metacog.co.kr/insights/2026-08-12-cisco-asa-and-ftd-flaw-exploited-in-the-wild-can-trigger-rem/</link><pubDate>Wed, 12 Aug 2026 11:57:00 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-12-cisco-asa-and-ftd-flaw-exploited-in-the-wild-can-trigger-rem/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> CISA KEV listed, actively exploited in the wild, and a public PoC exists — patch Cisco ASA and FTD software immediately per Cisco&amp;rsquo;s advisory for CVE-2026-20349; perimeter firewall availability is at direct risk from unauthenticated remote attackers.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active exploitation of an edge security appliance warrants an assume-breach sweep — hunt for anomalous or malformed HTTP requests targeting ASA/FTD management interfaces and investigate any unexplained firewall availability incidents since this KEV listing date.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> A CISA KEV-confirmed flaw in widely deployed perimeter firewalls is a priority patching event — confirm your engineering team has this on the sprint and assess whether any availability SLAs tied to ASA/FTD deployments are at risk; DoS scope limits board-level urgency but warrants direct follow-up with the team.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-20349 — CISA KEV: listed, EPSS n/a, public PoC on GitHub&lt;/li>
&lt;/ul></description></item><item><title>Cisco ASA and FTD VPN DoS flaw actively exploited in the wild</title><link>https://curasec.metacog.co.kr/insights/2026-08-12-cisco-warns-of-asa-and-ftd-vpn-flaw-exploited-to-crash-devic/</link><pubDate>Wed, 12 Aug 2026 11:57:00 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-12-cisco-warns-of-asa-and-ftd-vpn-flaw-exploited-to-crash-devic/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Cisco ASA and FTD are cornerstone edge appliances in most enterprise environments; active exploitation confirmed by the vendor makes this urgent — apply available patches or workarounds immediately and verify your ASA/FTD version is not in the affected range.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active exploitation of edge VPN appliances means you should hunt for unexpected device crashes or reboots on your ASA/FTD fleet and monitor for anomalous inbound traffic targeting VPN endpoints consistent with DoS attempts since the disclosure date.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> A DoS against widely deployed VPN appliances carries real business-continuity risk; confirm your team is treating patching as priority-one this week and identify contingency plans (backup access paths) if appliances are targeted before patches are applied.&lt;/li>
&lt;/ul></description></item><item><title>Cisco Patches 12 SD-WAN and IOS XE Flaws Including Three CVSS 9.8 Bugs</title><link>https://curasec.metacog.co.kr/insights/2026-08-07-cisco-patches-12-sd-wan-and-ios-xe-flaws-including-three-9-8/</link><pubDate>Fri, 07 Aug 2026 00:21:58 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-07-cisco-patches-12-sd-wan-and-ios-xe-flaws-including-three-9-8/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Three CVSS 9.8 flaws in widely deployed Cisco Catalyst SD-WAN and IOS XE warrant prioritized patching, but no KEV listing, public PoC, or active exploitation is reported. Schedule patching to the latest Cisco-recommended releases this sprint, prioritizing any internet-exposed SD-WAN or IOS XE autonomous-mode devices.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item></channel></rss>