Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Security Updates Released by Cisco and F5

Critical Security Updates Released by Cisco and F5

Posted on February 5, 2026 By CWS

Cisco and F5 have taken significant steps this week to bolster cybersecurity defenses by releasing patches for multiple vulnerabilities in their products. These updates address several high-severity issues that could potentially lead to denial-of-service (DoS) conditions, unauthorized command execution, and privilege escalation.

Cisco Addresses Critical Flaws

In its latest security update, Cisco has patched five vulnerabilities, two of which are deemed high-severity. These vulnerabilities were found in the TelePresence Collaboration Endpoint (CE), RoomOS software, and Meeting Management solutions. The first of these, identified as CVE-2026-20119, can be exploited remotely without requiring user interaction. This flaw allows attackers to cause a DoS condition by sending a specially crafted meeting invitation to compromised devices.

Cisco has resolved this issue in the TelePresence CE Software and RoomOS versions 11.27.5.0 and 11.32.3.0. The second vulnerability, labeled CVE-2026-20098, involves the web management interface of Meeting Management, which fails to validate user inputs correctly. This enables attackers with video operator privileges to upload arbitrary files, potentially allowing command execution with root-level access. The fix for this vulnerability is included in Meeting Management version 3.12.1 MR.

Additionally, Cisco has addressed three medium-severity vulnerabilities affecting AsyncOS for Secure Web Appliance, Prime Infrastructure, and Evolved Programmable Network Manager (EPNM). Notably, Cisco has reported that none of these vulnerabilities are known to have been exploited in the wild.

F5’s February Security Notification

F5 has also released its quarterly security notification, detailing patches for five vulnerabilities in BIG-IP and NGINX. Two of these vulnerabilities are rated as high-severity under the CVSS 4.0 scoring system. The first, CVE-2026-22548, pertains to BIG-IP and could lead to a DoS condition by causing the bd process to restart, thus disrupting traffic. This occurs when specific security policies are configured on a virtual server.

The second high-severity issue, CVE-2026-1642, affects NGINX OSS and NGINX Plus. This vulnerability could allow a man-in-the-middle (MitM) attacker to inject responses sent to clients, posing security risks. F5 has also addressed a medium-severity flaw in BIG-IP container ingress services for Kubernetes and OpenShift and low-severity issues in BIG-IP Edge Client and browser VPN clients on Windows.

F5 confirms that there is no evidence of these vulnerabilities being exploited in the wild, providing additional details in their security notification.

Future Outlook and Importance

These updates from Cisco and F5 underscore the ongoing need for vigilance in cybersecurity practices. Organizations using these technologies are advised to apply these patches promptly to mitigate potential risks. As cyber threats evolve, regular updates and security patches remain crucial in protecting sensitive data from unauthorized access and exploitation.

For further information, Cisco and F5 have detailed their security advisories on their respective websites, offering a comprehensive overview of the vulnerabilities and their resolutions.

Security Week News Tags:Cisco, command execution, Cybersecurity, DoS, F5, IT security, privilege escalation, security patches, software updates, Vulnerabilities

Post navigation

Previous Post: DesckVB RAT 2.9: Advanced Threat with Modular Plugins
Next Post: Remote File Upload Vulnerability in Cisco Meeting Management

Related Posts

Cyberattack on JLR Prompts £1.5 Billion UK Government Intervention Cyberattack on JLR Prompts £1.5 Billion UK Government Intervention Security Week News
New XCSSET macOS Malware Variant Hijacks Cryptocurrency Transactions New XCSSET macOS Malware Variant Hijacks Cryptocurrency Transactions Security Week News
Fortinet Confirms FortiCloud SSO Exploitation Against Patched Devices Fortinet Confirms FortiCloud SSO Exploitation Against Patched Devices Security Week News
Google Says Android pKVM Earns Highest Level of Security Assurance Google Says Android pKVM Earns Highest Level of Security Assurance Security Week News
Four Arrested in UK Over M&S, Co-op Cyberattacks Four Arrested in UK Over M&S, Co-op Cyberattacks Security Week News
Kosovar Administrator of Cybercrime Marketplace Extradited to US Kosovar Administrator of Cybercrime Marketplace Extradited to US Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Iranian Infy Hackers Reactivate C2 Servers After Internet Blackout
  • Cyberattackers Penetrate Networks Using SonicWall SSLVPN Credentials
  • Nullify Gains $12.5M to Enhance AI Cybersecurity Solutions
  • Guide to Managing AI Usage in Enterprises
  • Windows 11 to Integrate Sysmon for Enhanced Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Iranian Infy Hackers Reactivate C2 Servers After Internet Blackout
  • Cyberattackers Penetrate Networks Using SonicWall SSLVPN Credentials
  • Nullify Gains $12.5M to Enhance AI Cybersecurity Solutions
  • Guide to Managing AI Usage in Enterprises
  • Windows 11 to Integrate Sysmon for Enhanced Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark