Cisco
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Cisco product.
RSS Feeds for Cisco security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Cisco products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Cisco Sorted by Most Security Vulnerabilities since 2018
Cisco Internetwork Operating System (IOS)219 vulnerabilities
Cisco Internetwork Operating System (IOS) is a family of network operating systems used on many Cisco Systems routers and current Cisco network switches.
Recent Cisco Security Advisories
| Advisory | Title | Published |
|---|---|---|
| 2026-10-07 | Cisco Application Policy Infrastructure Controller Security Hardening Release: October 2026 | October 7, 2026 |
| 2026-10-07 | Cisco License (Smart Software Manager) On-Prem Security Hardening Release: October 2026 | October 7, 2026 |
| 2026-10-07 | Cisco NX-OS Software Python Sandbox Escape Vulnerability | October 7, 2026 |
| 2026-10-07 | Cisco Meraki Security Hardening Release: October 2026 | October 7, 2026 |
| 2026-10-07 | Cisco Application Policy Infrastructure Controller API Command Injection Vulnerability | October 7, 2026 |
| 2026-10-07 | Cisco Nexus 9000 Series Fabric Switches in ACI Mode Endpoint Group Contract Bypass Vulnerability | October 7, 2026 |
| 2026-10-07 | Cisco Nexus 3000 and 9000 Series Switches NGOAM Remote Code Execution Vulnerabilities | October 7, 2026 |
| 2026-10-07 | Cisco Application Policy Infrastructure Controller Unauthorized File Access Vulnerability | October 7, 2026 |
| 2026-10-07 | Cisco Finesse Server-Side Request Forgery Vulnerability | October 7, 2026 |
| 2026-10-07 | Cisco NX-OS Software Security Hardening Release: October 2026 | October 7, 2026 |
Known Exploited Cisco Vulnerabilities
The following Cisco vulnerabilities have recently been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability |
Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request. CVE-2026-76504 |
September 30, 2026 |
| Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability |
Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. CVE-2026-76460 |
September 16, 2026 |
| Cisco Secure Email Gateway SQL Injection Vulnerability |
Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. CVE-2026-76461 |
September 14, 2026 |
| Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerabil |
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. CVE-2026-20079 Exploit Probability: 88.2% |
September 9, 2026 |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Hea |
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. CVE-2026-20349 Exploit Probability: 1.0% |
August 11, 2026 |
| Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability |
Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. CVE-2026-20316 Exploit Probability: 35.1% |
July 29, 2026 |
| Cisco IOS Cross-Site Request Forgery Vulnerability |
Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. CVE-2008-4128 Exploit Probability: 33.9% |
July 13, 2026 |
| Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability |
Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root. CVE-2026-20230 Exploit Probability: 88.2% |
June 25, 2026 |
| Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability |
Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. CVE-2026-20262 Exploit Probability: 28.2% |
June 15, 2026 |
| Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability |
Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. CVE-2026-20245 Exploit Probability: 25.3% |
June 9, 2026 |
| Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability |
Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. CVE-2026-20182 Exploit Probability: 91.5% |
May 14, 2026 |
| Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerabili |
Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems. CVE-2026-20133 Exploit Probability: 31.8% |
April 20, 2026 |
| Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability |
Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges. CVE-2026-20122 Exploit Probability: 25.0% |
April 20, 2026 |
| Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability |
Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file for the DCA user on the filesystem as a low-privileged user. CVE-2026-20128 Exploit Probability: 7.8% |
April 20, 2026 |
| Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewa |
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. CVE-2026-20131 Exploit Probability: 42.7% |
March 19, 2026 |
| Cisco SD-WAN Path Traversal Vulnerability |
Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain elevated privileges via improper access controls on commands within the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user. CVE-2022-20775 Exploit Probability: 12.5% |
February 25, 2026 |
| Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability |
Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypass vulnerability could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affec CVE-2026-20127 Exploit Probability: 88.5% |
February 25, 2026 |
| Cisco Unified Communications Products Code Injection Vulnerability |
Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance contain a code injection vulnerability that could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root. CVE-2026-20045 Exploit Probability: 4.5% |
January 21, 2026 |
| Cisco Multiple Products Improper Input Validation Vulnerability |
Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability that allows threat actors to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance. CVE-2025-20393 Exploit Probability: 32.4% |
December 17, 2025 |
| Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability |
Cisco IOS and IOS XE contains a stack-based buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) subsystem that could allow for denial of service or remote code execution. A successful exploit could allow a low-privileged attacker to cause the affected system to reload, resulting in a DoS condition, or allow a high-privileged attacker to execute arbitrary code as the root user and obtain full control of the affected system. CVE-2025-20352 Exploit Probability: 39.4% |
September 29, 2025 |
Of the known exploited vulnerabilities above, 4 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. 10 known exploited Cisco vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.
Top 10 Riskiest Cisco Vulnerabilities
Based on the current exploit probability, these Cisco vulnerabilities are on CISA's Known Exploited vulnerabilities list (KEV) and are ranked by the current EPSS exploit probability.
| Rank | CVE | EPSS | Vulnerability |
|---|---|---|---|
| 1 | CVE-2021-1498 | 100.0% | Cisco HyperFlex HX Command Injection Vulnerabilities |
| 2 | CVE-2020-3452 | 100.0% | Cisco Adaptive Security Appliance and Cisco Fire Power Threat Defense directory traversal sensitive |
| 3 | CVE-2021-1497 | 99.9% | Cisco HyperFlex HX Command Injection Vulnerabilities |
| 4 | CVE-2018-0296 | 99.9% | Cisco Adaptive Security Appliance Firepower Threat Defense Denial-of-Service/Directory Traversal vul |
| 5 | CVE-2019-1653 | 99.9% | Cisco RV320 and RV325 Routers Improper Access Control Vulnerability (COVID-19-CTI list) |
| 6 | CVE-2023-20198 | 99.6% | Cisco IOS XE Web UI Privilege Escalation Vulnerability |
| 7 | CVE-2018-0171 | 99.5% | Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability |
| 8 | CVE-2017-3881 | 99.0% | Cisco IOS and IOS XE Remote Code Execution Vulnerability |
| 9 | CVE-2025-20281 | 97.6% | Cisco Identity Services Engine Injection Vulnerability |
| 10 | CVE-2024-20439 | 97.1% | Cisco Smart Licensing Utility Static Credential Vulnerability |
By the Year
In 2026 there have been 350 vulnerabilities in Cisco with an average score of 7.3 out of ten. Last year, in 2025 Cisco had 218 security vulnerabilities published. That is, 132 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.59.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 350 | 7.28 |
| 2025 | 218 | 6.69 |
| 2024 | 366 | 6.75 |
| 2023 | 271 | 6.83 |
| 2022 | 323 | 6.91 |
| 2021 | 620 | 6.84 |
| 2020 | 354 | 6.85 |
| 2019 | 524 | 6.78 |
| 2018 | 373 | 7.51 |
It may take a day or so for new Cisco vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Cisco Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-76472 | Oct 07, 2026 |
CWE-74 XSS Vulnerability in Cisco IOSAs part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-76472 are related to issues with improper neutralization of special elements that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-74. |
|
| CVE-2026-76467 | Oct 07, 2026 |
Improper Resource Control (CWE-664) in Cisco Networking DevicesAs part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76467 are related to issues concerning improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664. |
|
| CVE-2026-76470 | Oct 07, 2026 |
Cisco Network SW Calc Error (CWE-682) CVE-2026-76470As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76470 are related to incorrect calculation issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-682. |
|
| CVE-2026-76469 | Oct 07, 2026 |
Cisco Networking Devices: CWE-691 Control Flow Management Flaw (CVE-2026-76469)As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76469 are related to insufficient control flow management issues that are grouped under the Common Weakness Enumeration (CWE) CWE-691. |
|
| CVE-2026-76468 | Oct 07, 2026 |
Cisco IOS Improper Input Validation (CVE-2026-76468)As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76468 are related to improper input validation that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-20. |
|
| CVE-2026-76464 | Oct 07, 2026 |
Cisco IOS buffer manage CVE-2026-76464As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by this CVE-2026-76464 are related to buffer management issues that are grouped under the Common Weakness Enumeration (CWE) CWE-119. |
|
| CVE-2026-76463 | Oct 07, 2026 |
Cisco Improper Access Control in Networking Software (CWE-284)As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco networking engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76463 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284. |
|
| CVE-2026-76500 | Oct 07, 2026 |
CWE-664 Resource Lifetime Control CVE-2026-76500 in Cisco APICAs part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76500 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664. |
|
| CVE-2026-76501 | Oct 07, 2026 |
CVE-2026-76501: Remote Code Exec via SRv6 NGOAM in Cisco NX-OSA vulnerability in the Segment Routing over IPv6 (SRv6) Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) on an affected device. This vulnerability is due to improper input validation of IP traffic when the NGOAM and SRv6 features are enabled. An attacker could exploit this vulnerability by sending crafted packets to an IP interface on an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes resulting in a reload and DoS condition. |
|
| CVE-2026-76499 | Oct 07, 2026 |
Improper Neutralization (CWE-707) in Cisco APICAs part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76499 are related to improper neutralization issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-707. |
|
| CVE-2026-76498 | Oct 07, 2026 |
Cisco APIC Improper Access Control (CWE-284)As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76498 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284. |
|
| CVE-2026-76488 | Oct 07, 2026 |
APIC Export Policies Access Control Bypass Exposes Sensitive FilesA vulnerability in the export policies functionality of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to access sensitive files on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient access control to file system resources. An attacker could exploit this vulnerability by submitting crafted values in specific UI fields. A successful exploit could allow the attacker to access sensitive files from the underlying file system of an affected device, including key materials that could be used to elevate privileges to root on the affected APIC and on managed switches. |
|
| CVE-2026-76486 | Oct 07, 2026 |
Root-CVE in Cisco NX-OS NGOAM via Crafted OAM PacketsA vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a Denial-of-Service (DoS) on an affected device. This vulnerability is due to improper input validation of IP traffic when the NGOAM feature is enabled. An attacker could exploit this vulnerability by sending crafted packets to an IP interface on an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes resulting in a reload and DoS condition. |
|
| CVE-2026-76485 | Oct 07, 2026 |
Cisco NX-OS NGOAM Remote Code Execution via Improper IP ValidationA vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as NGOAM, could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a Denial-of-Service (DoS) on an affected device. This vulnerability is due to improper input validation of IP traffic when the NGOAM feature is enabled. An attacker could exploit this vulnerability by sending crafted packets to an IP interface on an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes resulting in a reload and DoS condition. |
|
| CVE-2026-76484 | Oct 07, 2026 |
Cisco License On-Prem: Code Injection via CWE-94 (CVE-2026-76484)As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76484 are related to issues with insufficient protection against code injection that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-94. |
|
| CVE-2026-76483 | Oct 07, 2026 |
Cisco License On-Prem Credentials Exposure (CWE-522)As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76483 are related to issues with insufficiently protected credentials that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-522. |
|
| CVE-2026-76482 | Oct 07, 2026 |
Cisco License On-Prem Improper Input Verification (CWE-347)As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76482 are related to issues with improper input verification that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-347. |
|
| CVE-2026-76480 | Oct 07, 2026 |
Cisco License On-Prem Improper Auth (CWE-306) CVE-2026-76480As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76480 are related to issues with improper authentication that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-306. |
|
| CVE-2026-76458 | Oct 07, 2026 |
Cisco NX-OS Improper Exception Handling (CWE-703)As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76458 are related to improper handling of exceptional conditions issues that are grouped under the Common Weakness Enumeration (CWE) CWE-703. |
|
| CVE-2026-76459 | Oct 07, 2026 |
NX-OS OOB Write (CWE-787) VulnerabilityAs part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76459 are related to out-of-bounds write issues that are grouped under the Common Weakness Enumeration (CWE) CWE-787. |
|
| CVE-2026-76471 | Oct 07, 2026 |
Cisco NX-OS NX-API Remote Code Execution (RCE)A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input validation of data that is sent to the NX-API. An attacker could exploit this vulnerability by sending a crafted HTTP request to the NX-API of an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes, which could result in a reload of the device and a DoS condition. |
|
| CVE-2026-76455 | Oct 07, 2026 |
CVE-2026-76455: Improper Access Control in Cisco NX-OSAs part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76455 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284. |
|
| CVE-2026-76457 | Oct 07, 2026 |
OOB Read in Cisco NX-OS (CWE-125)As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76457 are related to out-of-bounds read issues that are grouped under the Common Weakness Enumeration (CWE) CWE-125. |
|
| CVE-2026-76456 | Oct 07, 2026 |
Cisco NX-OS Improper Input Validation (CWE-20)As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76456 are related to improper input validation of special elements used in a command issue that are grouped under the Common Weakness Enumeration (CWE) CWE-20. |
|
| CVE-2026-76465 | Oct 07, 2026 |
Cisco NX-OS MPLS OAM Echo-Request RCEA vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper validation when an affected device is processing an MPLS echo-request packet. An attacker could exploit this vulnerability by sending a crafted MPLS echo-request to an IP address on an affected device. A successful exploit could allow the attacker to execute arbitrary code with root privileges and could cause process crashes, which could result in a device reload and a DoS condition. |
|
| CVE-2026-76454 | Oct 07, 2026 |
Unauth Rmt File Write & DoS via Cisco Smart Licensing Utility APIA vulnerability in the Cisco Smart Licensing Utility API of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an unauthenticated, remote attacker to write arbitrary files to the system or cause a DoS condition on an affected application. This vulnerability is due to improper input validation and a lack of authentication in the management API. An attacker could exploit this vulnerability by sending a crafted request to the affected API. A successful exploit could allow the attacker to modify system files or cause a DoS condition. |
|
| CVE-2026-76453 | Oct 07, 2026 |
Cisco NX-OS Improper Neutralization (CWE-707) VulnerabilityAs part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-76453 are related to improper neutralization issues that are grouped under the Common Weakness Enumeration (CWE) CWE-707. |
|
| CVE-2026-76437 | Oct 07, 2026 |
Cisco License OnPrem: Authenticated RCE via Web UIA vulnerability in the web-based user interface of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. This vulnerability is due to improper validation of user-supplied content within configurations that are submitted to the web-based management interface. An attacker could exploit this vulnerability by updating configurations within the web-based management interface. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with root privileges. To exploit this vulnerability, the attacker must have valid administrative credentials. Because only an attacker who already holds system administrator privileges can exploit the vulnerability, the only additional privileges gained include the ability to turn off the system, which an administrative user could not normally do. |
|
| CVE-2026-20362 | Oct 07, 2026 |
Cisco Finesse SSRF via Unauthenticated Remote Request ForgeryA vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerability is due to improper input validation for specific HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain limited sensitive information for services that are associated with the affected device. |
|
| CVE-2026-76452 | Oct 07, 2026 |
Cisco License On-Prem SQL Injection via Authenticated Web UIA vulnerability in the web-based management interface of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an authenticated, remote attacker to conduct SQL injection attacks against an affected application. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface. A successful exploit could allow the attacker to read additional contents of the internal database of an affected application that should not normally be accessible to administrative users, thus impacting system confidentiality. To exploit this vulnerability, the attacker must have valid administrative user credentials on the affected application. |
|
| CVE-2026-20173 | Oct 07, 2026 |
DoS via UDP/TCP Flood in Cisco NX-OSA vulnerability in Cisco NX-OS Software could allow an unauthenticated, remote attacker to exhaust system resources, causing a denial of service (DoS) condition. This vulnerability exists because rate limiting was improperly applied to some protocols. An attacker could exploit this vulnerability by sending a high rate of UDP or TCP connections to a data plane interface on an affected device. A successful exploit could allow the attacker to cause instability to various routing and control plane protocols through some packet loss and temporary disruptions, causing a DoS condition. This DoS condition will clear without manual intervention soon after the high rate of traffic is stopped. |
|
| CVE-2026-20328 | Oct 07, 2026 |
Cisco License On-Prem Unauth Remote Password Reset CVE-2026-20328A vulnerability in the web-based management interface of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow an unauthenticated, remote attacker to gain unauthorized access to an affected application. This vulnerability is due to improper checks during the password reset process. An attacker could exploit this vulnerability by sending a malicious request to the web-based management interface. A successful exploit could allow the attacker to reset the password of an arbitrary account, including high-privileged administrative user accounts, possibly allowing the attacker to gain unauthorized access to the application as any user. |
|
| CVE-2026-20321 | Oct 07, 2026 |
Cisco APIC API Command Injection Enabling root ExecutionA vulnerability in the web-based management API for Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to execute arbitrary commands as the root user. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient input validation of user-controlled command arguments. An attacker could exploit this vulnerability by authenticating using the API and sending crafted input. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system of an affected device with root-level privileges. |
|
| CVE-2026-20038 | Oct 07, 2026 |
Nexus 9000 ACI EPG Contract Bypass VulnerabilityA vulnerability in the endpoint group (EPG) contract functionality of Cisco Nexus 9000 Series Fabric Switches in ACI Mode could allow an unauthenticated, remote attacker to bypass configured EPG contracts. This vulnerability is due to an improper control with EPG contracts. An attacker could exploit this vulnerability by sending IPv4 or IPv6 packets using UDP source and destination ports that are assigned to DHCP traffic through an affected device. A successful exploit could allow the attacker to bypass EPG contracts on the affected device. |
|
| CVE-2026-20032 | Oct 07, 2026 |
Python Sandbox Escape in Cisco NX-OS via Low-Privilege Local AccessA vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, local attacker with low privileges to escape the Python sandbox and gain unauthorized access to the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by manipulating specific functions within the Python interpreter. A successful exploit could allow an attacker to escape the Python sandbox and execute arbitrary commands on the underlying operating system with the privileges of the authenticated user. |
|
| CVE-2026-76504 | Sep 30, 2026 |
Cisco Catalyst SD-WAN Manager Auth Bypass via URI EncodingA vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user. This vulnerability is due to improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API of the affected system. A successful exploit could allow the attacker to bypass authentication and gain access to the API as the admin user. |
|
| CVE-2026-76426 | Sep 16, 2026 |
SQLi in Cisco ISE REST API monitoring DBA vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection attacks against the monitoring database. This vulnerability is due to insufficient validation of specific parameters that are then concatenated into an SQL statement. An attacker could exploit this vulnerability by sending a crafted request that contains SQL statements in one of the affected parameters. A successful exploit could allow the attacker to read information from the monitoring database. To exploit this vulnerability, the attacker must have valid administrative credentials. |
|
| CVE-2026-20121 | Sep 16, 2026 |
Cisco ASA/FTD ACL OGS Bypass (CVE202620121)A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access controls. This vulnerability is due to a logic error in populating group access control policies (ACPs) with OGS configured. An attacker could exploit this vulnerability by sending traffic that should be blocked through the device. A successful exploit could allow the attacker to bypass access controls and reach devices in protected networks. |
|
| CVE-2026-76431 | Sep 16, 2026 |
Cisco ISE Directory Traversal Deletion Vulnerability (CVE-2026-76431)A vulnerability in the file management function of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to delete arbitrary files and directories on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of directory traversal character sequences in a user-supplied file path before the request is validated. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface of an affected device. A successful exploit could allow the attacker to delete arbitrary files and directories on the underlying operating system of the affected device. |
|
| CVE-2026-76427 | Sep 16, 2026 |
Cisco ISE Offline Profiler XML External Entity Read Arbitrary FileA vulnerability in the offline profiler feed service of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files that are stored on an affected device. This vulnerability is due to the parsing of attacker-controlled feed metadata with an XML parser that does not disable external entity resolution. An attacker could exploit this vulnerability by uploading a crafted offline feed package through the administrative interface. A successful exploit could allow the attacker to read arbitrary files from the file system and issue requests to internal systems from the affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. |
|
| CVE-2026-76447 | Sep 16, 2026 |
Cisco ISE OCSP Responder Unauth Reload VulnerabilityA vulnerability in the Online Certificate Status Protocol (OCSP) responder of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to cause an administrative reload of the OCSP responder certificate and key material. This vulnerability is due to missing authentication on a function of the OCSP responder. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to cause the OCSP responder to reload certificate and key material on demand. |
|
| CVE-2026-20287 | Sep 16, 2026 |
Cisco ISE Improper Privilege Management (CWE-269)As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20287 are related to improper privilege managment issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-269. |
|
| CVE-2026-20285 | Sep 16, 2026 |
Auth Bypass in Cisco ISE Admin InterfaceA vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. This vulnerability is due to the lack of server-side validation of Administrator permissions. An attacker could exploit this vulnerability by submitting a crafted HTTP request to an affected system. A successful exploit could allow the attacker to modify descriptions of files on a specific page. To exploit this vulnerability, an attacker would need valid Administrator credentials. |
|
| CVE-2026-20286 | Sep 16, 2026 |
Cisco ISE Web Interface Authenticated Remote Config ModificationA vulnerability in the web-based management interface of Cisco Identify Services Engine (ISE) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. This vulnerability is due to the lack of server-side validation of Administrator permissions. An attacker could exploit this vulnerability by submitting a crafted HTTP request to an affected system. A successful exploit could allow the attacker to modify descriptions of files on a specific page. To exploit this vulnerability, an attacker would need valid Administrator credentials. |
|
| CVE-2026-76438 | Sep 16, 2026 |
Cisco BroadWorks CommPilot Auth Bypass in Web UI (Low Privilege)A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker with low privileges to alter configurations on an affected device. This vulnerability is due to missing authorization checks. An attacker could exploit this vulnerability by sending a crafted HTTP request. A successful exploit could allow the attacker to alter configurations on select pages. |
|
| CVE-2026-20072 | Sep 16, 2026 |
Cisco ISE Web UI Auth Bypass Exposing User PasswordsA vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive information from network users that are outside the security group that the attacker is assigned to. This vulnerability exists because certain files lack proper authorization enforcement. An attacker with administrative privileges and management rights over network users could exploit this vulnerability by exporting the users. A successful exploit could allow the attacker to view passwords that are normally not visible to administrators. |
|
| CVE-2026-76446 | Sep 16, 2026 |
Cisco ISE API XXE Remote File ReadA vulnerability in an API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to read specific files on the underlying operating system of an affected device. This vulnerability is due to improper restriction of XML external entity references. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to read specific files on the affected system that the underlying process has permission to access. |
|
| CVE-2026-20071 | Sep 16, 2026 |
Cisco ISE SSID BYOD Hijack Vulnerability (Unauthenticated Session Takeover)A vulnerability in the SSID bring-your-own-device (BYOD) onboarding workflow of Cisco ISE could allow an unauthenticated, adjacent attacker to hijack the onboarding session of another user and access protected 802.1X networks. This vulnerability is due to insufficient authentication checks that are performed while a user is being onboarded. An attacker could exploit this vulnerability by spoofing the legitimate user and triggering a redirection to the guest web portal. A successful exploit could allow the attacker to take over the user session and gain access to the protected 802.1X network. |
|
| CVE-2026-76432 | Sep 16, 2026 |
Cisco ISE Arbitrary File Write via Directory TraversalA vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker with administrative-level privileges to write arbitrary files on an affected device. This vulnerability exists because the affected software does not properly validate directory traversal character sequences in a user-supplied file path during the upload process. An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A successful exploit could allow the attacker to write files to an arbitrary location on the affected system. |
|
| CVE-2026-20300 | Sep 16, 2026 |
Cisco ISE SQL Injection via Authenticated Remote AttackerA vulnerability in Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected device. To exploit this vulnerability, the attacker must have at least low-privileged administrative credentials. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to read or modify data in the underlying database. |
|