Cisco
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any Cisco product.
RSS Feeds for Cisco security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in Cisco products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by Cisco Sorted by Most Security Vulnerabilities since 2018
Cisco Internetwork Operating System (IOS)219 vulnerabilities
Cisco Internetwork Operating System (IOS) is a family of network operating systems used on many Cisco Systems routers and current Cisco network switches.
Recent Cisco Security Advisories
| Advisory | Title | Published |
|---|---|---|
| 2026-09-16 | Cisco Secure Firewall Threat Defense Software TLS 1.3 Denial of Service Vulnerability | September 16, 2026 |
| 2026-09-16 | Cisco Identity Services Engine Authenticated Remote Code Execution and API Vulnerabilities | September 16, 2026 |
| 2026-09-16 | Cisco Secure Firewall Management Center and Secure Firewall Threat Defense Software sftunnel Vulnerabilities | September 16, 2026 |
| 2026-09-16 | Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Secure Firewall 3100 and 4200 Series DTLS Denial of Service Vulnerability | September 16, 2026 |
| 2026-09-16 | Cisco Identity Services Engine Vulnerabilities | September 16, 2026 |
| 2026-09-16 | Cisco Secure Firewall Management Center Software Vulnerabilities | September 16, 2026 |
| 2026-09-16 | Cisco Identity Services Engine 802.1X Session Hijack and Information Disclosure Vulnerabilities | September 16, 2026 |
| 2026-09-16 | Cisco Identity Services Engine RADIUS Denial of Service Vulnerability | September 16, 2026 |
| 2026-09-16 | Cisco Identity Services Engine Remote Code Execution Vulnerabilities | September 16, 2026 |
| 2026-09-16 | Cisco Identity Services Engine Information Disclosure Vulnerability | September 16, 2026 |
Known Exploited Cisco Vulnerabilities
The following Cisco vulnerabilities have recently been marked by CISA as Known to be Exploited by threat actors.
| Title | Description | Added |
|---|---|---|
| Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability |
Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs vulnerability that could allow an unauthenticated, remote attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. CVE-2026-76460 |
September 16, 2026 |
| Cisco Secure Email Gateway SQL Injection Vulnerability |
Cisco AsyncOS software for Cisco Secure Email Gateway (SEG) contains a SQL injection vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. CVE-2026-76461 |
September 14, 2026 |
| Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerabil |
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. CVE-2026-20079 Exploit Probability: 38.7% |
September 9, 2026 |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Hea |
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. CVE-2026-20349 |
August 11, 2026 |
| Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability |
Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. CVE-2026-20316 |
July 29, 2026 |
| Cisco IOS Cross-Site Request Forgery Vulnerability |
Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. CVE-2008-4128 Exploit Probability: 33.9% |
July 13, 2026 |
| Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability |
Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root. CVE-2026-20230 Exploit Probability: 80.9% |
June 25, 2026 |
| Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability |
Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. CVE-2026-20262 Exploit Probability: 28.2% |
June 15, 2026 |
| Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability |
Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. CVE-2026-20245 Exploit Probability: 25.3% |
June 9, 2026 |
| Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability |
Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. CVE-2026-20182 Exploit Probability: 90.3% |
May 14, 2026 |
| Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerabili |
Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems. CVE-2026-20133 Exploit Probability: 31.4% |
April 20, 2026 |
| Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability |
Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges. CVE-2026-20122 Exploit Probability: 24.6% |
April 20, 2026 |
| Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability |
Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file for the DCA user on the filesystem as a low-privileged user. CVE-2026-20128 Exploit Probability: 6.9% |
April 20, 2026 |
| Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewa |
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. CVE-2026-20131 Exploit Probability: 27.6% |
March 19, 2026 |
| Cisco SD-WAN Path Traversal Vulnerability |
Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain elevated privileges via improper access controls on commands within the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user. CVE-2022-20775 Exploit Probability: 12.5% |
February 25, 2026 |
| Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability |
Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypass vulnerability could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affec CVE-2026-20127 Exploit Probability: 88.2% |
February 25, 2026 |
| Cisco Unified Communications Products Code Injection Vulnerability |
Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance contain a code injection vulnerability that could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root. CVE-2026-20045 Exploit Probability: 4.3% |
January 21, 2026 |
| Cisco Multiple Products Improper Input Validation Vulnerability |
Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability that allows threat actors to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance. CVE-2025-20393 Exploit Probability: 32.4% |
December 17, 2025 |
| Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability |
Cisco IOS and IOS XE contains a stack-based buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) subsystem that could allow for denial of service or remote code execution. A successful exploit could allow a low-privileged attacker to cause the affected system to reload, resulting in a DoS condition, or allow a high-privileged attacker to execute arbitrary code as the root user and obtain full control of the affected system. CVE-2025-20352 Exploit Probability: 39.4% |
September 29, 2025 |
| Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Mis |
Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a missing authorization vulnerability. This vulnerability could be chained with CVE-2025-20333. CVE-2025-20362 Exploit Probability: 87.1% |
September 25, 2025 |
Of the known exploited vulnerabilities above, 4 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. 10 known exploited Cisco vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.
Top 10 Riskiest Cisco Vulnerabilities
Based on the current exploit probability, these Cisco vulnerabilities are on CISA's Known Exploited vulnerabilities list (KEV) and are ranked by the current EPSS exploit probability.
| Rank | CVE | EPSS | Vulnerability |
|---|---|---|---|
| 1 | CVE-2021-1498 | 100.0% | Cisco HyperFlex HX Command Injection Vulnerabilities |
| 2 | CVE-2020-3452 | 100.0% | Cisco Adaptive Security Appliance and Cisco Fire Power Threat Defense directory traversal sensitive |
| 3 | CVE-2021-1497 | 99.9% | Cisco HyperFlex HX Command Injection Vulnerabilities |
| 4 | CVE-2018-0296 | 99.9% | Cisco Adaptive Security Appliance Firepower Threat Defense Denial-of-Service/Directory Traversal vul |
| 5 | CVE-2019-1653 | 99.9% | Cisco RV320 and RV325 Routers Improper Access Control Vulnerability (COVID-19-CTI list) |
| 6 | CVE-2023-20198 | 99.6% | Cisco IOS XE Web UI Privilege Escalation Vulnerability |
| 7 | CVE-2018-0171 | 99.5% | Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability |
| 8 | CVE-2017-3881 | 99.0% | Cisco IOS and IOS XE Remote Code Execution Vulnerability |
| 9 | CVE-2025-20281 | 97.2% | Cisco Identity Services Engine Injection Vulnerability |
| 10 | CVE-2024-20439 | 97.1% | Cisco Smart Licensing Utility Static Credential Vulnerability |
By the Year
In 2026 there have been 314 vulnerabilities in Cisco with an average score of 7.1 out of ten. Last year, in 2025 Cisco had 218 security vulnerabilities published. That is, 96 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.46.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 314 | 7.15 |
| 2025 | 218 | 6.69 |
| 2024 | 366 | 6.75 |
| 2023 | 271 | 6.83 |
| 2022 | 323 | 6.91 |
| 2021 | 620 | 6.83 |
| 2020 | 354 | 6.85 |
| 2019 | 524 | 6.78 |
| 2018 | 373 | 7.51 |
It may take a day or so for new Cisco vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Cisco Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-76426 | Sep 16, 2026 |
SQLi in Cisco ISE REST API monitoring DBA vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection attacks against the monitoring database. This vulnerability is due to insufficient validation of specific parameters that are then concatenated into an SQL statement. An attacker could exploit this vulnerability by sending a crafted request that contains SQL statements in one of the affected parameters. A successful exploit could allow the attacker to read information from the monitoring database. To exploit this vulnerability, the attacker must have valid administrative credentials. |
|
| CVE-2026-20121 | Sep 16, 2026 |
Cisco ASA/FTD ACL OGS Bypass (CVE202620121)A vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access controls. This vulnerability is due to a logic error in populating group access control policies (ACPs) with OGS configured. An attacker could exploit this vulnerability by sending traffic that should be blocked through the device. A successful exploit could allow the attacker to bypass access controls and reach devices in protected networks. |
|
| CVE-2026-76431 | Sep 16, 2026 |
Cisco ISE Directory Traversal Deletion Vulnerability (CVE-2026-76431)A vulnerability in the file management function of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to delete arbitrary files and directories on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of directory traversal character sequences in a user-supplied file path before the request is validated. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface of an affected device. A successful exploit could allow the attacker to delete arbitrary files and directories on the underlying operating system of the affected device. |
|
| CVE-2026-76427 | Sep 16, 2026 |
Cisco ISE Offline Profiler XML External Entity Read Arbitrary FileA vulnerability in the offline profiler feed service of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files that are stored on an affected device. This vulnerability is due to the parsing of attacker-controlled feed metadata with an XML parser that does not disable external entity resolution. An attacker could exploit this vulnerability by uploading a crafted offline feed package through the administrative interface. A successful exploit could allow the attacker to read arbitrary files from the file system and issue requests to internal systems from the affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. |
|
| CVE-2026-76447 | Sep 16, 2026 |
Cisco ISE OCSP Responder Unauth Reload VulnerabilityA vulnerability in the Online Certificate Status Protocol (OCSP) responder of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to cause an administrative reload of the OCSP responder certificate and key material. This vulnerability is due to missing authentication on a function of the OCSP responder. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to cause the OCSP responder to reload certificate and key material on demand. |
|
| CVE-2026-20287 | Sep 16, 2026 |
Cisco ISE Improper Privilege Management (CWE-269)As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20287 are related to improper privilege managment issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-269. |
|
| CVE-2026-20285 | Sep 16, 2026 |
Auth Bypass in Cisco ISE Admin InterfaceA vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. This vulnerability is due to the lack of server-side validation of Administrator permissions. An attacker could exploit this vulnerability by submitting a crafted HTTP request to an affected system. A successful exploit could allow the attacker to modify descriptions of files on a specific page. To exploit this vulnerability, an attacker would need valid Administrator credentials. |
|
| CVE-2026-20286 | Sep 16, 2026 |
Cisco ISE Web Interface Authenticated Remote Config ModificationA vulnerability in the web-based management interface of Cisco Identify Services Engine (ISE) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. This vulnerability is due to the lack of server-side validation of Administrator permissions. An attacker could exploit this vulnerability by submitting a crafted HTTP request to an affected system. A successful exploit could allow the attacker to modify descriptions of files on a specific page. To exploit this vulnerability, an attacker would need valid Administrator credentials. |
|
| CVE-2026-76438 | Sep 16, 2026 |
Cisco BroadWorks CommPilot Auth Bypass in Web UI (Low Privilege)A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker with low privileges to alter configurations on an affected device. This vulnerability is due to missing authorization checks. An attacker could exploit this vulnerability by sending a crafted HTTP request. A successful exploit could allow the attacker to alter configurations on select pages. |
|
| CVE-2026-20072 | Sep 16, 2026 |
Cisco ISE Web UI Auth Bypass Exposing User PasswordsA vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obtain sensitive information from network users that are outside the security group that the attacker is assigned to. This vulnerability exists because certain files lack proper authorization enforcement. An attacker with administrative privileges and management rights over network users could exploit this vulnerability by exporting the users. A successful exploit could allow the attacker to view passwords that are normally not visible to administrators. |
|
| CVE-2026-76446 | Sep 16, 2026 |
Cisco ISE API XXE Remote File ReadA vulnerability in an API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to read specific files on the underlying operating system of an affected device. This vulnerability is due to improper restriction of XML external entity references. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to read specific files on the affected system that the underlying process has permission to access. |
|
| CVE-2026-20071 | Sep 16, 2026 |
Cisco ISE SSID BYOD Hijack Vulnerability (Unauthenticated Session Takeover)A vulnerability in the SSID bring-your-own-device (BYOD) onboarding workflow of Cisco ISE could allow an unauthenticated, adjacent attacker to hijack the onboarding session of another user and access protected 802.1X networks. This vulnerability is due to insufficient authentication checks that are performed while a user is being onboarded. An attacker could exploit this vulnerability by spoofing the legitimate user and triggering a redirection to the guest web portal. A successful exploit could allow the attacker to take over the user session and gain access to the protected 802.1X network. |
|
| CVE-2026-76432 | Sep 16, 2026 |
Cisco ISE Arbitrary File Write via Directory TraversalA vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker with administrative-level privileges to write arbitrary files on an affected device. This vulnerability exists because the affected software does not properly validate directory traversal character sequences in a user-supplied file path during the upload process. An attacker could exploit this vulnerability by uploading a crafted file to the affected system. A successful exploit could allow the attacker to write files to an arbitrary location on the affected system. |
|
| CVE-2026-20300 | Sep 16, 2026 |
Cisco ISE SQL Injection via Authenticated Remote AttackerA vulnerability in Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected device. To exploit this vulnerability, the attacker must have at least low-privileged administrative credentials. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to read or modify data in the underlying database. |
|
| CVE-2026-76448 | Sep 16, 2026 |
Cisco ISE Authenticated SQL/HQL Injection VulnerabilityA vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL or HQL injection attack on an affected device. This vulnerability is due to insufficient validation of user-supplied input to the affected APIs before it is used to build database queries. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to execute arbitrary SQL or HQL queries against the underlying database, which could allow the attacker to view or modify data that they are not authorized to access. To exploit this vulnerability, the attacker must have valid administrative credentials. |
|
| CVE-2026-76434 | Sep 16, 2026 |
Cisco ISE/PIC Authenticated Web UI File Read via Cert ImportA vulnerability in the certificate import functionality of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to read arbitrary files from the affected system. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of user-supplied input by the affected feature. An attacker could exploit this vulnerability by sending a crafted request to the web-based management interface of an affected device. A successful exploit could allow the attacker to read arbitrary files from the affected device, which could contain sensitive information. |
|
| CVE-2026-20120 | Sep 16, 2026 |
ACL Bypass via OGS in Cisco Secure Firewall ASA/FTDA vulnerability in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured access controls. This vulnerability is due to a logic error in populating group access control policies (ACPs) with OGS configured. An attacker could exploit this vulnerability by sending traffic that should be blocked through the device. A successful exploit could allow the attacker to bypass access controls and reach devices in protected networks. |
|
| CVE-2026-76444 | Sep 16, 2026 |
Cisco ISE: Unauth Remote Retrieval of Sensitive Config via PRRTA vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive configuration information from an affected device. This vulnerability is due to missing authentication on the Policy Runtime Repository Table (PRRT) service. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to obtain sensitive configuration information from the affected device. |
|
| CVE-2026-20235 | Sep 16, 2026 |
CVE-2026-20235: Cisco ISE API Auth Data DisclosureA vulnerability in the API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of user-supplied parameters in API requests. An attacker could exploit this vulnerability by sending a crafted API request to an affected device. A successful exploit could allow the attacker to gain access to sensitive information, including hashed credentials that could be used in future attacks. |
|
| CVE-2026-20290 | Sep 16, 2026 |
CVE-2026-20290: SSL Cert Parsing In Snort 2 Engine Enables DoS RestartA vulnerability in SSL/TLS certificate parsing in the Snort 2 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 2 Detection Engine to restart. This vulnerability is due to incomplete validation of the SSL certificate. An attacker could exploit this vulnerability by sending a crafted SSL connection setup request to be parsed by Snort 2. A successful exploit could allow the attacker to cause the Snort 2 Detection Engine to restart unexpectedly, resulting in a denial of service (DoS) condition. |
|
| CVE-2026-76451 | Sep 16, 2026 |
Cisco ISE SQL/HQL Injection via Authenticated APIA vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL or HQL injection attack on an affected device. This vulnerability is due to insufficient validation of user-supplied input to the affected APIs before it is used to build database queries. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to execute arbitrary SQL or HQL queries against the underlying database, which could allow the attacker to view or modify data that they are not authorized to access. To exploit this vulnerability, the attacker must have valid administrative credentials. |
|
| CVE-2026-76449 | Sep 16, 2026 |
Cisco ISE SQL/HQL Injection via Authenticated APIA vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL or HQL injection attack on an affected device. This vulnerability is due to insufficient validation of user-supplied input to the affected APIs before it is used to build database queries. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to execute arbitrary SQL or HQL queries against the underlying database, which could allow the attacker to view or modify data that they are not authorized to access. To exploit this vulnerability, the attacker must have valid administrative credentials. |
|
| CVE-2026-76450 | Sep 16, 2026 |
Auth SQL Injection in Cisco ISE/ISE-PIC APIs (CVE-2026-76450)A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct an SQL or HQL injection attack on an affected device. This vulnerability is due to insufficient validation of user-supplied input to the affected APIs before it is used to build database queries. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to execute arbitrary SQL or HQL queries against the underlying database, which could allow the attacker to view or modify data that they are not authorized to access. To exploit this vulnerability, the attacker must have valid administrative credentials. |
|
| CVE-2026-20309 | Sep 16, 2026 |
Cisco ISE Web UI Reflected XSS via Unvalidated InputA vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. |
|
| CVE-2026-76428 | Sep 16, 2026 |
SQLi in Cisco ISE REST API (cve-2026-76428)A vulnerability in the REST APIs of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection attacks against the session database. This vulnerability is due to certain parameters being concatenated directly into SQL clauses without parameterization. An attacker could exploit this vulnerability by sending a crafted request that contains SQL statements in one of the affected parameters. A successful exploit could allow the attacker to read information from the session database. To exploit this vulnerability, the attacker must have valid administrative credentials. |
|
| CVE-2026-76433 | Sep 16, 2026 |
Cisco ISE Provisioning Download Directory TraversalA vulnerability in the client provisioning download feature of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to access protected files on an affected device. This vulnerability is due to insufficient validation of directory traversal character sequences in a user-supplied path when the software processes provisioning resource requests. An attacker could exploit this vulnerability by sending a crafted request to the provisioning download service. A successful exploit could allow the attacker to access protected files without authentication, potentially exposing sensitive information. |
|
| CVE-2026-76439 | Sep 16, 2026 |
Unauthenticated Remote Forged Posture Events in Cisco ISE Guest PortalA vulnerability in the endpoint posture status reporting functionality of the guest portal web application of Cisco ISE could allow an unauthenticated, remote attacker to submit forged posture status events into the endpoint posture pipeline. This vulnerability is due to insufficient authentication on an internal interface that is exposed through the guest portal. An attacker could exploit this vulnerability by sending a crafted request to an affected system. A successful exploit could allow the attacker to manipulate the posture status on the affected system. |
|
| CVE-2026-20248 | Sep 16, 2026 |
DoS via TCP DNS Response Restart in Cisco Secure Firewall ASA/FTDA vulnerability in the DNS over TCP implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the TCP DNS response handler to unexpectedly restart, causing the device to reload. This vulnerability is due to a logic error when parsing a DNS query and tracking the size of the incoming buffers. An attacker could exploit this vulnerability by formatting a crafted reply to a DNS query sent from the targeted device. A successful exploit could allow the attacker to cause the device to reload, causing a denial of service (DoS) condition. Note: The attacker must be able to respond to DNS queries from the device, either by controlling the DNS service or through a machine-in-the-middle attack. |
|
| CVE-2026-20342 | Sep 16, 2026 |
Cisco Secure FMC Authenticated Remote File Download via Unsanitized APIA vulnerability in a specific file download API of Cisco Secure FMC Software could allow an authenticated, remote attacker to download arbitrary files from an affected system. This vulnerability exists because user input is not being sanitized. An attacker could exploit this vulnerability by sending a crafted HTTPS request. A successful exploit could allow the attacker to download arbitrary files from the affected system. To exploit this vulnerability, the attacker must have valid credentials for a user account with at least the role of Security Analyst (read-only). |
|
| CVE-2026-20282 | Sep 16, 2026 |
Authenticated OS Write Elevation in Cisco ISE via HTTP RequestA vulnerability in Cisco ISE could allow an authenticated, remote attacker to obtain write access on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain write access to the underlying operating system. To exploit this vulnerability, the attacker must have valid administrative credentials. Note: For CVE-2026-20282, Cisco has assigned a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that it is easy to get to root from the achieved privilege level. |
|
| CVE-2026-20323 | Sep 16, 2026 |
Cisco Secure FMC/FTD sftunnel TLS cert flaw allows root impersonationA vulnerability in the sftunnel inter-device communication protocol of Cisco Secure FMC Software and Cisco Secure FTD Software could allow an unauthenticated, adjacent attacker to impersonate the peer device and obtain access at the level of the manager role, which is equivalent to root. This vulnerability is due to improper management of the TLS certificate for the sftunnel management connection. An attacker could exploit this vulnerability by connecting to the sftunnel port using a crafted TLS certificate. A successful exploit could allow the attacker to become a registered sftunnel peer with root access. Note: The attack is successful only if the sftunnel connection is down or the attack can disrupt the sftunnel connection long enough to execute the attack. |
|
| CVE-2026-20283 | Sep 16, 2026 |
Cisco ISE IPsec Open API OS Command Injection (CVE-2026-20283)A vulnerability in the IPsec Open API endpoint of Cisco ISE could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system. This vulnerability is due to insufficient validation of user-supplied input in IPsec Open API calls. An attacker could exploit this vulnerability by sending crafted input to the IPsec Open API endpoint on an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system. To exploit this vulnerability, the attacker must have valid administrative credentials and the node must have more than one network interface, one of which must be configured as an active IPsec tunnel. Note: For CVE-2026-20283, Cisco has assigned a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that it is easy to get to root from the achieved privilege level. |
|
| CVE-2026-76412 | Sep 16, 2026 |
Cisco Secure FMC Remote Debugger Elevates PrivilegesA vulnerability in the remote diagnostics debugger of Cisco Secure FMC Software could allow an authenticated, remote attacker to enable the remote diagnostics debugger service. This vulnerability is due to an error when checking the privilege level of a user who is invoking remote diagnostics. An attacker could exploit this vulnerability by authenticating to the device, either through the web-based management interface or the REST API, and using the remote diagnostics debugger to grant a user elevated privileges. A successful exploit could allow the attacker to elevate privileges to root. Notes: To exploit this vulnerability, the attacker must have valid user credentials on the affected device. The CVSSv3.1 Attack Complexity is High due to the multistage process required to fully exploit this vulnerability. |
|
| CVE-2026-20333 | Sep 16, 2026 |
Cisco Secure Firewall CWE-697 Condition Check VulnerabilityAs part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20333 are related to incorrect comparison conditions that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-697. |
|
| CVE-2026-76425 | Sep 16, 2026 |
SQLi in Cisco ISE API enabling data exfil & SSRFA vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks against the backend database. This vulnerability is due to insufficient validation of certain parameters that are concatenated directly into an SQL query. An attacker could exploit this vulnerability by sending a crafted request that contains SQL statements to an affected endpoint. A successful exploit could allow the attacker to read arbitrary content from the SQL database and conduct server-side request forgery (SSRF) attacks. To exploit this vulnerability, the attacker must have valid administrative credentials. |
|
| CVE-2026-20334 | Sep 16, 2026 |
Cisco Secure Firewall: CWE710 Coding Standards VulnerabilitiesAs part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20334 are related to issues concerning improper adherence to coding standards that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-710. |
|
| CVE-2026-20284 | Sep 16, 2026 |
Cisco ISE SXP REST API SQL Injection (Authenticated Remote)A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks. This vulnerability is due to insufficient validation of user-supplied input in REST API calls. An attacker could exploit this vulnerability by sending crafted input to an affected device. A successful exploit could allow the attacker to view or modify data on the underlying database for the affected device. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a DoS condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored. To exploit this vulnerability, the attacker must have valid administrative credentials, have the SXP service enabled, and have at least one SXP connection configured. |
|
| CVE-2026-76424 | Sep 16, 2026 |
Authenticated Remote File Upload & Exec via Cisco ISE REST APIA vulnerability in the REST API of Cisco ISE could allow an authenticated, remote attacker to upload or copy arbitrary files on an affected device. This vulnerability is due to insufficient validation in file operations. An attacker could exploit this vulnerability by uploading a file with a crafted path. A successful exploit could allow the attacker to upload files to arbitrary locations and execute arbitrary commands as root on the affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. |
|
| CVE-2026-20332 | Sep 16, 2026 |
Cisco Secure Firewall Improper Access Control (CWE-284)As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20332 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284. |
|
| CVE-2026-20344 | Sep 16, 2026 |
Authenticated SQLi in Cisco Secure FMC Web UIA vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, remote attacker to perform a SQL injection attack against an affected device. To exploit this vulnerability, the attacker must have a valid account on the device with the role of Security Approver, Access Admin, or Network Admin. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface of an affected device. A successful exploit could allow the attacker to obtain any data from the database, obtain the session credentials of an authenticated Administrator, and take actions with administrative privileges on the affected device. |
|
| CVE-2026-20360 | Sep 16, 2026 |
CVE-2026-20360: Cisco Nexus Dashboard info exposure via CWE-200As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20360 are related to information exposure and insecure handling issues that are grouped under the Common Weakness Enumeration (CWE) CWE-200. |
|
| CVE-2026-20154 | Sep 16, 2026 |
Cisco ASA/FTD DoS via Syslog RateLimiting ExploitA vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected device, resulting in a denial of service (DoS) condition. This vulnerability is due to improper rate limiting for syslog message 419002. An attacker could exploit this vulnerability by sending a flood of TCP synchronization (SYN) packets to an affected device. A successful exploit could allow the attacker to cause high CPU utilization, resulting in performance degradation. |
|
| CVE-2026-20343 | Sep 16, 2026 |
Unauthorized Download & Disk DoS in Cisco Secure FMC APIA vulnerability in a critical API for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to download sensitive files and use unbounded disk space. This vulnerability exists because a critical API lacks authentication. An attacker could exploit this vulnerability by repeatedly invoking the API. A successful exploit could allow the attacker to download sensitive files that should be restricted and consume disk space so the device could become unresponsive, causing a DoS condition. |
|
| CVE-2026-20222 | Sep 16, 2026 |
Cisco ASA/FTD EIGRP DoS via Unauthenticated Adjacent AttackerA vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper resource management when handling EIGRP update messages. An attacker could exploit this vulnerability by sending crafted EIGRP updates at a high rate to an affected device. A successful exploit could allow the attacker to trigger a memory leak that will eventually cause the affected device to reload unexpectedly. |
|
| CVE-2026-20247 | Sep 16, 2026 |
Cisco ISE SQL Injection Vulnerability (CVE-2026-20247)A vulnerability in Cisco ISE could allow an unauthenticated, remote attacker to conduct SQL injection attacks on an affected device. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to modify data in the underlying database. |
|
| CVE-2026-20135 | Sep 16, 2026 |
Cisco Secure FTD TLS1.3 Buffer Overflow Causing Device Reload (DoS)A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper buffer management during the TLS 1.3 connection. An attacker could exploit this vulnerability by sending a crafted TLS 1.3 packet to an affected system through a TLS 1.3-enabled listening socket. A successful exploit could allow the attacker to cause the LINA process to crash, which would cause the device to reload. The reload can happen before or after authentication of the connection.Note: TLS 1.3 connections include both data traffic and user-management traffic. |
|
| CVE-2026-76460 | Sep 16, 2026 |
Cisco ISE API Auth Bypass via Insufficient ControlA vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. |
|
| CVE-2026-20352 | Sep 16, 2026 |
Cisco ISE RADIUS DoS via Crafted RequestsA vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain RADIUS requests. An attacker could exploit this vulnerability by sending a crafted RADIUS request directly to an affected device. A successful exploit could allow the attacker to cause the ISE node to become unavailable. For single node deployments in that condition, endpoints that have not already authenticated would be unable to access the network until the node comes back up on its own. |
|
| CVE-2026-76413 | Sep 16, 2026 |
Cisco ASDM SSO Token Forgery Enables Admin Privilege EscalationA vulnerability in Cisco Adaptive Security Device Manager (ASDM) single sign-on (SSO) handler for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to log in as the Cisco ASDM administrator user. This vulnerability is due to improper management of the Cisco ASDM SSO token. An attacker could exploit this vulnerability by performing session token forgery techniques. A successful exploit could allow the attacker to log in as the administrator user and, by repeating this action, keep legitimate administrators locked out of the ASDM indefinitely. |
|
| CVE-2026-20336 | Sep 16, 2026 |
CWE-664 Resource Mismanagement in Cisco Secure FirewallAs part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20336 are related to issues concerning improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664. |
|