Cisco patches confidentiality, DoS flaws across products
Multiple vulnerabilities in Cisco Catalyst Center, Secure Endpoint Connector, and Private Cloud allow remote denial of service and unauthorized data disclosure.
The French CERT has issued an advisory covering multiple vulnerabilities discovered in Cisco products. The affected products include Catalyst Center versions prior to 2.3.7.11-VA GSMU100 and 3.1.6 GSMU200, Secure Endpoint Connector for Mac (prior to 1.27.21), Linux (prior to 1.29.01), and Windows (prior to 8.6.21), as well as Secure Endpoint Private Cloud versions before 4.2.8.
The vulnerabilities enable attackers to conduct remote denial-of-service attacks and compromise data confidentiality. Eight CVEs have been assigned to these issues, spanning from CVE-2026-20191 through CVE-2026-20244. Cisco has released security bulletins addressing arbitrary file read vulnerabilities in Catalyst Center and multiple issues in ClamAV-based components.
Organizations running affected Cisco products should consult the vendor's security advisories and apply available patches immediately to mitigate these risks.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0825
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free