Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-26057: Cisco Skill Scanner API server unauthenticated DoS and arbitrary file upload

A vulnerability in the optional API Server of Cisco AI Defense's Skill Scanner, caused by erroneous binding to multiple interfaces, allowed unauthenticated remote attackers to exhaust memory or upload files to arbitrary folders. It affects Skill-scanner 1.0.1 and earlier and is fixed in release 1.0.2.

Disclosed 19 February 2026 · Record updated 13 September 2026

Impact

An unauthenticated remote attacker could trigger a denial of service through memory starvation or upload files to arbitrary folders on affected devices where the non-default API Server was enabled.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-26057