In another major security update, Cisco announced the release of security updates for multiple vulnerabilities affecting its enterprise portfolio, with five of them rated as high severity. The fixes target critical networking, telephony, IoT management, and enterprise orchestration platforms, confirming that infrastructure security remains an ongoing battle even for the industry’s largest vendors.

The vulnerabilities, according to the company's official announcement, could under certain conditions allow attacks such as Server-Side Request Forgery (SSRF), denial-of-service (DoS), information disclosure , and execution of unauthorized actions in corporate environments.
Although Cisco emphasizes that there is no evidence of widespread exploitation of these flaws, organizations using the affected products are urged to immediately apply the available patches.
See also: Gemini CLI: Critical vulnerability allowed supply chain attacks
Critical vulnerabilities in Cisco Unity Connection
Two of the most serious vulnerabilities were found in Cisco Unity Connection, the company's enterprise messaging and unified communications platform. The flaws, listed as CVE-2026-20034 and CVE-2026-20035, relate to insufficient user-supplied input in certain HTTP requests.
This vulnerability could allow remote authenticated attackers to perform SSRF attacks, exploiting the device itself to send network requests to internal or external resources.
Even more worrying is that in certain cases, the exploit can lead to arbitrary code execution with root privileges, potentially allowing complete control of the system.
For enterprise environments that rely on Unity Connection for voice services and corporate communications, this threat is considered particularly serious.
DoS attacks on popular enterprise switches
Cisco also patched the CVE-2026-20185 vulnerability , which affects the Simple Network Management Protocol (SNMP) subsystem in the SG350 and SG350X switches .
The issue is due to incorrect error handling when processing certain SNMP responses. An attacker could exploit the vulnerability and cause a forced reboot of the device, leading to a system outage.
See also: Serious vulnerabilities in Salesforce Marketing Cloud
The vulnerability affects SNMPv1, SNMPv2c and SNMPv3 versions , but requires knowledge of community strings or valid credentials, depending on the protocol version.
This reduces the risk of mass exploitation, but does not eliminate it, especially in environments where default or weak SNMP settings remain active.

Crosswork and NSO in the crosshairs
Also of significant interest is the vulnerability CVE-2026-20188, which affects the Cisco Crosswork Network Controller (CNC) and Network Services Orchestrator (NSO).
The flaw results from incorrect rate limiting implementation on incoming network connections. As a result, an unauthorized remote attacker could flood the system with connection requests, exhausting critical resources.
Successful exploitation leads to a resource exhaustion, rendering services unavailable.
Since these tools are used to automate and manage large-scale network infrastructures , their downtime can have significant operational consequences.
Vulnerability also in IoT Field Network Director
The fifth serious vulnerability, CVE-2026-20167, concerns IoT Field Network Director, a platform for managing industrial and IoT networks.
See also: vm2 Node.js: 12 critical vulnerabilities allow sandbox escape
Due to improper error handling in the web interface, an attacker can submit specially crafted data and cause the router or device to reboot.
In industrial environments, even a temporary outage can create serious impacts, especially when it concerns operational technology infrastructure.
This particular fix is considered critical for organizations operating large-scale IoT deployments.

Additional fixes and broader impact
In addition to the five high-severity vulnerabilities, Cisco patched seven moderate-severity flaws in products such as Slido, Prime Infrastructure, Identity Services Engine (ISE) , and Enterprise Chat and Email (ECE).
These vulnerabilities include file reading capabilities, information disclosure, command execution, log capture, and browser-based attacks.
Although they are considered less critical, their combined use in complex attacks cannot be ruled out.
Why updates are critical
The new patch set reminds us that cybersecurity in enterprise networks depends not only on firewalls and monitoring, but also on the continuous application of updates.
As attackers increasingly quickly exploit newly disclosed vulnerabilities, the window of safe response narrows significantly.
For IT administrators, the message is clear: promptly installing Cisco updates is a necessary step to maintain the resilience of corporate infrastructures against modern threats.
