Cisco has released patches addressing a critical vulnerability in its Identity Services Engine (ISE) that affects cloud deployments on Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI). The flaw, identified as CVE-2025-20286, carries a CVSS score of 9.9 to 10.0, indicating it is both easy to exploit and has severe consequences. The vulnerability involves static credential reuse across systems, enabling unauthenticated attackers to access configurations, data, and other sensitive information. Proof of concept exploits are publicly available, increasing the urgency for organizations to apply the patches. Separately, cybersecurity experts have highlighted a critical zero-click vulnerability in RoundCube, a webmail software, which went undetected for a decade. This flaw allows attackers to take control of entire servers and spy on sensitive emails, posing a threat to national security across governments and major institutions. Security firms are urging immediate updates to mitigate these risks.
.@Cisco released patches for a flaw in cloud deployments of the Cisco Identity Services Engine (ISE) that affects @AWS, @Azure, and the @Oracle Cloud Infrastructure (OCI). #cybersecurity #infosec #ITsecurity #cloudsecurity https://t.co/ANW3ivpINa
Marwan Hachem, COO of FearsOff Cybersecurity, warns that a critical #RoundCube vulnerability threatens national security across governments and major institutions, urging urgent updates as exploits are now publicly available. #GNT https://t.co/NqlcqknCyO
Marwan Hachem, COO of FearsOff Cybersecurity, says his team uncovered a zero-click bug in #RoundCube that went undetected for 10 years—allowing attackers to take over entire servers and spy on sensitive emails. #GNT https://t.co/e8hxLZZFFc