Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryinternet-facing-service-vulnerabilityperimeter-device-exposure

Cisco Discloses XSS in Catalyst SD-WAN Manager and SSRF in Nexus Dashboard

Updated 3mo agoFirst seen Mar 25, 20264 sources

Cisco published security advisories for two enterprise management platforms: a cross-site scripting (XSS) flaw in Cisco Catalyst SD-WAN Manager and a server-side request forgery (SSRF) flaw affecting Cisco Nexus Dashboard and Cisco Nexus Dashboard Insights. The issues affect products used to centrally manage networking infrastructure, raising the risk that attackers could target administrative interfaces and backend request handling in high-value environments.

The advisories identify separate web-application security weaknesses in Cisco's network management stack, with one issue tied to malicious script execution in the SD-WAN management interface and the other to unauthorized server-side requests from Nexus Dashboard components. Organizations using these platforms should review Cisco's product advisories, determine affected deployments, and prioritize remediation or mitigations for exposed management systems.

Share:
Cisco Discloses XSS in Catalyst SD-WAN Manager and SSRF in Nexus Dashboard
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Jan 4, 20266mo ago

Cisco discloses Nexus Dashboard Insights arbitrary file write vulnerability

Cisco published a security advisory for an arbitrary file write vulnerability affecting Cisco Nexus Dashboard Insights. No additional technical details or remediation timeline are provided in the reference content.

Cisco Nexus Dashboard Insights Arbitrary File Write Vulnerability

Cisco discloses Nexus Dashboard SSRF vulnerability

Cisco published a security advisory for a server-side request forgery vulnerability affecting Cisco Nexus Dashboard and Cisco Nexus Dashboard Insights. No further event details are included in the reference content.

Jan 1, 20266mo ago

Cisco discloses Catalyst SD-WAN Manager XSS vulnerability

Cisco published a security advisory for a cross-site scripting vulnerability affecting Cisco Catalyst SD-WAN Manager. No additional technical details or remediation timeline are provided in the reference content.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

1 LINKEDOpen in app
Organizations
1 linked
Cisco Systems
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Cisco Discloses XSS in Catalyst SD-WAN Manager and SSRF in Nexus Dashboard | Mallory