rootpwn

Advisories

Cisco PSIRT Issues July 1, 2026 Advisories: Catalyst Center File Read & Multiple ClamAV Flaws

Cisco’s Product Security Incident Response Team released a batch of advisories on July 1, 2026. The alerts cover a high‑severity arbitrary file‑read vulnerability in Cisco Catalyst Center (CVE‑2026‑20191) and a group of high‑impact ClamAV bugs (CVE‑2026‑20213 through CVE‑2026‑20244) that compromise several Cisco products. Cisco urges all customers to apply the available patches immediately and notes updates to its vulnerability disclosure framework.

On July 1, 2026 Cisco PSIRT published a set of security advisories that pose a significant risk to many organizations relying on Cisco infrastructure. The notices highlight two main categories of flaws: an arbitrary file‑read vulnerability in the Cisco Catalyst Center and a cluster of high‑score ClamAV vulnerabilities that affect a range of Cisco products.

Key Vulnerabilities

  • Arbitrary File Read – Catalyst Center
    CVE‑2026‑20191 – High severity (CVSS 7.5). The flaw allows attackers to read any file on the system, potentially exposing sensitive configuration data or credentials.
  • ClamAV Vulnerabilities – Cisco Products
    CVE‑2026‑20213, CVE‑2026‑20214, CVE‑2026‑20215, CVE‑2026‑20216, CVE‑2026‑20217, CVE‑2026‑20243, CVE‑2026‑20244 – All rated High (CVSS 7.5). These bugs can lead to remote code execution or denial‑of‑service conditions when processing malicious files.

All affected devices must be upgraded to the patched software versions listed in the advisories. Cisco stresses that failure to remediate could expose critical data and disrupt operations.

"To fully remediate the vulnerabilities that were disclosed on July 1, 2026, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories," the PSIRT team advised.

In addition to the technical details, Cisco’s PSIRT released a note on its evolving disclosure methodology. The organization announced a shift toward a more predictable, customer‑focused response to AI‑accelerated vulnerability discovery, aiming to streamline communication and accelerate patch deployment.

Security Impact Rating: Informational. However, the high CVSS scores and potential for exploitation warrant immediate action.

Cisco PSIRT CVE Vulnerability Remediation Security Advisory

← All news