Cisco's identity appliance is being hit through an API endpoint that never checked who was asking.
Firewall and proxy rules that allow the old addresses will need updating before early October.
Three exploited networking flaws now carry a three-day federal patch deadline.
CERT Polska warns that MikroTik routers with SSH exposed to the internet are being hijacked without any authentication.
HPE's AOS-CX updates close 34 CVEs including a 9.8-rated unauthenticated RCE cluster.
A critical Nexus 9000 flaw leaves two TCP ports reachable and hands unauthenticated attackers root privileges.
Ubiquiti shipped fixes for 22 UniFi vulnerabilities, three of them perfect-10 access control flaws.
OS-wide Encrypted Client Hello in Android 17 hides visited domains from carriers and Wi-Fi snoops.