Cisco released a bunch of security updates on Wednesday, which you should install as soon as possible.
There are a total of 17 advisories, including revised versions of previous advisories. The most critical patch concerns granting root access to a local attacker, followed by another that allows access to the compromised system to any remote malicious user without permission.

Here is a summary of the critical security flaws:
CVE-2018-15380: Cisco HyperFlex Software Command Vulnerability
A logged-in user could execute commands as the root superuser without authentication. “An attacker could exploit this vulnerability by logging in to the cluster service manager and issuing commands,” Cisco said. “A successful exploit could allow the hacker to execute commands on the affected host as the root user.”
CVE-2019-1664: Cisco HyperFlex Software Unauthenticated Root Access Vulnerability
A logged-in user could gain root privileges on a Cisco HyperFlex Software cluster without authentication. An attacker could exploit this vulnerability by logging in to the hxterm service as an unprivileged local user. A successful exploitation could allow the attacker to gain root privileges on all member nodes of the HyperFlex cluster.
CVE-2019-5736: Privilege Escalation Affecting Cisco Products.
This is a vulnerability patch that affects Cisco products. Essentially, it is version 1.2 of an older advisory, with more Switchzilla tools now listed as vulnerable to Privilege Escalation.
CVE -2019-1659: Cisco Prime Infrastructure Certificate Validation Vulnerability
An unauthorized man-in-the-middle attacker can intercept, decrypt , and monitor an SSL-encrypted tunnel between the ISE (Identity Services Engine) and Cisco Prime Infrastructure.
CVE-2019-1662: vulnerability Unrecognized access Prime Collaboration.
An unauthorized remote attacker can access Cisco Quality of Voice Reporting (QOVR) services as a valid user.
CVE-2019-1681: Cisco Network Convergence System 1000 Series TFTP Directory Traversal Vulnerability
An unauthorized, remote attacker can download arbitrary files from the TFTP service of the Cisco Network Convergence System 1000 Series software, possibly resulting in the disclosure of potentially sensitive information.
