Cisco updated its advisory regarding critical vulnerabilities in Identity Services Engine, acknowledging active exploitation. Some vulnerabilities were attempted to be exploited in the wild as of July 2025.
Cisco has released patches for a maximum-severity security flaw in Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME). The vulnerability, CVE-2025-20309, carries a CVSS score of 10.0, allowing an attacker to log in using the root account with static credentials that cannot be changed. Cisco advises users to upgrade to the latest version or apply the CSCwp27755 patch as there are no workarounds.
"Just a short time ago, we could only achieve 3,000 km distances using traditional module-based transponders, and the links were limited to 100 Gbps. Now, in collaboration with Cisco, Internet2 has demonstrated 400 Gbps at those same distances using coherent optics."
Patel emphasized the need for a reshaped portfolio, stating, 'Cisco has grown over the years. What happens then is that within the organization someone is responsible for the networking component, someone for compute, someone for security, someone for observability and so on.' This division led to underutilization of Cisco's capabilities, limiting their structural advantages.
"With NTT DATA, we strongly believe we can enable a faster, simpler, and more convenient way for enterprises to securely connect their organizations through an enhanced setup and provisioning process," said Masum Mir, SVP/GM, Cisco Provider Mobility. He sees the collaboration as a "game-changer" for organizations.