Cisco Cisco

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Cisco product.

RSS Feeds for Cisco security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Cisco products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Cisco Sorted by Most Security Vulnerabilities since 2018

Cisco IOS XE335 vulnerabilities
Newer version of Cisco IOS Operating System built on linux.

Cisco Internetwork Operating System (IOS)212 vulnerabilities
Cisco Internetwork Operating System (IOS) is a family of network operating systems used on many Cisco Systems routers and current Cisco network switches.

Cisco Firepower Threat Defense194 vulnerabilities

Cisco Identity Services Engine142 vulnerabilities

Cisco Catalyst Sd Wan Manager99 vulnerabilities

Cisco Nx Os85 vulnerabilities

Cisco Sd Wan Vmanage77 vulnerabilities

Cisco Ios Xr64 vulnerabilities

Cisco Sd Wan63 vulnerabilities

Cisco Webex Meetings60 vulnerabilities

Cisco Prime Infrastructure54 vulnerabilities

Cisco Unified Computing System50 vulnerabilities

Cisco Unity Connection40 vulnerabilities

Cisco Email Security Appliance33 vulnerabilities

Cisco Roomos32 vulnerabilities

Cisco Dna Center27 vulnerabilities

Cisco Secure Endpoint27 vulnerabilities

Cisco Asyncos25 vulnerabilities

Cisco Web Security Appliance25 vulnerabilities

Cisco Catalyst Center25 vulnerabilities

Cisco Nexus Dashboard25 vulnerabilities

Cisco Jabber23 vulnerabilities

Cisco Sd Wan Manager19 vulnerabilities

Cisco Finesse17 vulnerabilities

Cisco Expressway16 vulnerabilities

Cisco Webex Business Suite15 vulnerabilities

Cisco Webex Teams15 vulnerabilities

Cisco Cyber Vision15 vulnerabilities

Cisco Clamav13 vulnerabilities

Cisco Ios Xe Sd Wan10 vulnerabilities

Cisco Emergency Responder10 vulnerabilities

Cisco Broadworks9 vulnerabilities

Cisco Secure Client9 vulnerabilities

Recent Cisco Security Advisories

Advisory Title Published
2026-08-12 Cisco Advance Notification for Publication of August 19, 2026, Security Advisories August 12, 2026
2026-08-11 Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability August 11, 2026
2026-08-07 ClamAV Vulnerabilities Affecting Cisco Products: August 2026 August 7, 2026
2026-08-05 Cisco Integrated Management Controller Argument Injection Vulnerabilities August 5, 2026
2026-08-05 Cisco IOS XE Software Blocks Extensible Exchange Protocol Denial of Service Vulnerability August 5, 2026
2026-08-05 Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability August 5, 2026
2026-08-05 Cisco RoomOS Logging Subsystem Information Disclosure Vulnerability August 5, 2026
2026-08-05 Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerability August 5, 2026
2026-08-05 Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerability August 5, 2026
2026-08-05 Cisco Integrated Management Controller Cross-Site Scripting Vulnerability August 5, 2026

Known Exploited Cisco Vulnerabilities

The following Cisco vulnerabilities have recently been marked by CISA as Known to be Exploited by threat actors.

Title Description Added
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Hea Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.
CVE-2026-20349
August 11, 2026
Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.
CVE-2026-20316
July 29, 2026
Cisco IOS Cross-Site Request Forgery Vulnerability Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI.
CVE-2008-4128 Exploit Probability: 33.0%
July 13, 2026
Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root.
CVE-2026-20230 Exploit Probability: 80.9%
June 25, 2026
Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system.
CVE-2026-20262 Exploit Probability: 28.2%
June 15, 2026
Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system.
CVE-2026-20245 Exploit Probability: 25.3%
June 9, 2026
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system.
CVE-2026-20182 Exploit Probability: 90.3%
May 14, 2026
Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerabili Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems.
CVE-2026-20133 Exploit Probability: 31.4%
April 20, 2026
Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file for the DCA user on the filesystem as a low-privileged user.
CVE-2026-20128 Exploit Probability: 6.9%
April 20, 2026
Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges.
CVE-2026-20122 Exploit Probability: 24.6%
April 20, 2026
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewa Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.
CVE-2026-20131 Exploit Probability: 27.6%
March 19, 2026
Cisco SD-WAN Path Traversal Vulnerability Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain elevated privileges via improper access controls on commands within the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user.
CVE-2022-20775 Exploit Probability: 12.5%
February 25, 2026
Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypass vulnerability could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affec
CVE-2026-20127 Exploit Probability: 88.2%
February 25, 2026
Cisco Unified Communications Products Code Injection Vulnerability Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance contain a code injection vulnerability that could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root.
CVE-2026-20045 Exploit Probability: 4.3%
January 21, 2026
Cisco Multiple Products Improper Input Validation Vulnerability Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability that allows threat actors to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance.
CVE-2025-20393 Exploit Probability: 29.5%
December 17, 2025
Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability Cisco IOS and IOS XE contains a stack-based buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) subsystem that could allow for denial of service or remote code execution. A successful exploit could allow a low-privileged attacker to cause the affected system to reload, resulting in a DoS condition, or allow a high-privileged attacker to execute arbitrary code as the root user and obtain full control of the affected system.
CVE-2025-20352 Exploit Probability: 38.8%
September 29, 2025
Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Mis Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a missing authorization vulnerability. This vulnerability could be chained with CVE-2025-20333.
CVE-2025-20362 Exploit Probability: 85.5%
September 25, 2025
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buf Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a buffer overflow vulnerability that allows for remote code execution. This vulnerability could be chained with CVE-2025-20362.
CVE-2025-20333 Exploit Probability: 40.4%
September 25, 2025
Cisco Identity Services Engine Injection Vulnerability Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device.
CVE-2025-20337 Exploit Probability: 66.3%
July 28, 2025
Cisco Identity Services Engine Injection Vulnerability Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device.
CVE-2025-20281 Exploit Probability: 97.1%
July 28, 2025

Of the known exploited vulnerabilities above, 6 are in the top 1%, or the 99th percentile of the EPSS exploit probability rankings. 10 known exploited Cisco vulnerabilities are in the top 5% (95th percentile or greater) of the EPSS exploit probability rankings.

Top 10 Riskiest Cisco Vulnerabilities

Based on the current exploit probability, these Cisco vulnerabilities are on CISA's Known Exploited vulnerabilities list (KEV) and are ranked by the current EPSS exploit probability.

Rank CVE EPSS Vulnerability
1 CVE-2021-1498 100.0% Cisco HyperFlex HX Command Injection Vulnerabilities
2 CVE-2020-3452 100.0% Cisco Adaptive Security Appliance and Cisco Fire Power Threat Defense directory traversal sensitive
3 CVE-2021-1497 99.9% Cisco HyperFlex HX Command Injection Vulnerabilities
4 CVE-2018-0296 99.9% Cisco Adaptive Security Appliance Firepower Threat Defense Denial-of-Service/Directory Traversal vul
5 CVE-2019-1653 99.9% Cisco RV320 and RV325 Routers Improper Access Control Vulnerability (COVID-19-CTI list)
6 CVE-2023-20198 99.6% Cisco IOS XE Web UI Privilege Escalation Vulnerability
7 CVE-2018-0171 99.5% Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability
8 CVE-2017-3881 99.0% Cisco IOS and IOS XE Remote Code Execution Vulnerability
9 CVE-2025-20281 97.1% Cisco Identity Services Engine Injection Vulnerability
10 CVE-2019-1652 95.9% Cisco Small Business Routers Improper Input Validation Vulnerability

By the Year

In 2026 there have been 202 vulnerabilities in Cisco with an average score of 6.8 out of ten. Last year, in 2025 Cisco had 218 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Cisco in 2026 could surpass last years number. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.11.




Year Vulnerabilities Average Score
2026 202 6.80
2025 218 6.69
2024 366 6.74
2023 271 6.83
2022 323 6.91
2021 620 6.83
2020 354 6.85
2019 524 6.78
2018 373 7.51

It may take a day or so for new Cisco vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Cisco Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2026-20349 Aug 11, 2026
Cisco ASA/FTD SSL VPN DoS via crafted HTTP request A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition.  This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.
Adaptive Security Appliance
CVE-2026-20348 Aug 07, 2026
ClamAV XAR Parser DoS via Memory Corruption A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in XAR files during scanning. An attacker could exploit this vulnerability by submitting a crafted file that contains XAR content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Secure Endpoint
CVE-2026-20345 Aug 07, 2026
ClamAV GPT Parser OOB Buffer Write leading to DoS A vulnerability in the GPT file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper handling of an endian conversion operation, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted GPT file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Secure Endpoint
CVE-2026-20339 Aug 07, 2026
ClamAV PESpin Parser Integer Overflow Causing DoS A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PESpin files during scanning, which may result in an integer overflow. An attacker could exploit this vulnerability by submitting a crafted file that contains PESpin content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Secure Endpoint
CVE-2026-20347 Aug 07, 2026
DoS via OOB read in ClamAV Mach-O parser A vulnerability in the Mach-O file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in Mach-O files during scanning, which may result in an out-of-bounds buffer read. An attacker could exploit this vulnerability by submitting a crafted Mach-O file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Secure Endpoint
CVE-2026-20346 Aug 07, 2026
DoS via OOB Buffer Read in ClamAV PDF Parser A vulnerability in the PDF file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PDF files during scanning, which may result in an out-of-bounds buffer read. An attacker could exploit this vulnerability by submitting a crafted PDF file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Secure Endpoint
CVE-2026-20338 Aug 07, 2026
DoS via zip doublefree in ClamAV archive parser A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate as a result of a memory double-free, resulting in a DoS condition on the affected software.
Secure Endpoint
CVE-2026-20337 Aug 07, 2026
ClamAV zip parser DoS via OOB write A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an out-of-bounds write condition. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Secure Endpoint
CVE-2026-20313 Aug 05, 2026
Cisco Catalyst SDWAN Improper Link Resolution Before File Access (CWE1284) As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20313 are related to Improper link resolution before file access issues that are grouped under the Common Weakness Enumeration (CWE) CWE-1284.
Sd Wan
Catalyst Sd Wan Manager
CVE-2026-20311 Aug 05, 2026
DoS via malformed cert in Cisco IOS XE Web mgmt A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient error handling in the web-based management interface. An attacker could exploit this vulnerability by authenticating with a malformed certificate. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition.
IOS XE
CVE-2026-20289 Aug 05, 2026
RoomOS Logging Data Leakage via Local Authenticated User A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive information. This vulnerability is due to the logging of sensitive information. An attacker could exploit this vulnerability by enabling a specific logging level and then collecting the system logs. A successful exploit could allow the attacker to view sensitive information like user login credentials.
Roomos
CVE-2026-20312 Aug 05, 2026
Cisco Catalyst SDWAN CWE312 Cleartext Data Leak As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20312 are related to Cleartext storage of sensitive information issues that are grouped under the Common Weakness Enumeration (CWE) CWE-312.
Sd Wan
Catalyst Sd Wan Manager
CVE-2026-20310 Aug 05, 2026
Cisco Catalyst SD-WAN improper link resolution causing file access flaw As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20310 are related to improper link resolution before file access issues that are grouped under the Common Weakness Enumeration (CWE) CWE-59.
Sd Wan
Catalyst Sd Wan Manager
CVE-2026-20303 Aug 05, 2026
Improper Input Validation in Cisco Catalyst SD-WAN (CWE-20) As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20303 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) CWE-20.
Sd Wan
Catalyst Sd Wan Manager
CVE-2026-20294 Aug 05, 2026
Remote Authenticated UI Credentials Disclosure in Cisco SD-WAN Manager A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficient access control enforcement for specific template types that are not included in the encryption allowlist. A low-privileged attacker could exploit this vulnerability by viewing logs on the local system or on a remote logging server. A successful exploit could allow the attacker to view sensitive authentication credentials, which could lead to further compromise of network infrastructure and connected services.
Catalyst Sd Wan Manager
CVE-2026-20301 Aug 05, 2026
Cisco IOS / IOS-XE XMCP Packet DoS via Malformed XMCP A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of malformed XMCP packets. An attacker could exploit this vulnerability by sending a malformed XMCP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to reload unexpectedly, resulting in a DoS condition. The attacker does not need the XMCP client username to exploit this vulnerability.
IOS XE
Internetwork Operating System (IOS)
CVE-2026-20288 Aug 05, 2026
Cisco IMC Web UI Command Injection Allowing OS Root Privilege Escalation A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with Admin privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root.  This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user.  Cisco has assigned this vulnerability a SIR of High rather than Medium as the score indicates because additional security implications could occur when the attacker becomes root.
Unified Computing System
CVE-2026-20308 Aug 05, 2026
DoS via Web-Mgmt in Cisco IOS XE A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the web-based management interface to become unresponsive.
IOS XE
CVE-2026-20304 Aug 05, 2026
Improper Access Control in Cisco Catalyst SDWAN (CWE-284) As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20304 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284.
Sd Wan
Catalyst Sd Wan Manager
CVE-2026-20273 Aug 05, 2026
Cisco IOS XE Improper Input Validation (CWE-20) As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20273 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-20.
IOS XE
CVE-2026-20272 Aug 05, 2026
Cisco IOS XE Improper Neutralization of Special Elements (CWE-74) As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20272 are related to issues with improper neutralization of special elements that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-74.
IOS XE
CVE-2026-20271 Aug 05, 2026
Cisco IOS XE: Control Flow Management Vulnerability (CWE691) As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20271 are related to insufficient control flow management issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-691.  
IOS XE
CVE-2026-20270 Aug 05, 2026
CVE-2026-20270: Incorrect Calculation (CWE-682) in Cisco IOS XE As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20270 are related to incorrect calculation issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-682.
IOS XE
CVE-2026-20269 Aug 05, 2026
Improper resource control in Cisco IOS XE (CWE-664) As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20269 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.
IOS XE
CVE-2026-20268 Aug 05, 2026
Cisco IOS XE CVE-2026-20268: Buffer Overflow (CWE-119) As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20268 are related to issues with improper restriction of operations within the bounds of a memory buffer that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-119.
IOS XE
CVE-2026-20267 Aug 05, 2026
Cisco IOS XE: Improper Access Control CVE-2026-20267 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20267 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.
IOS XE
CVE-2026-20263 Aug 05, 2026
Cisco IOS XE BEEP SOAP DoS Vulnerability A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling when parsing a specific BEEP SOAP request. An attacker could exploit this vulnerability by sending a specific BEEP SOAP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition.
IOS XE
CVE-2026-20200 Aug 05, 2026
Remote Cmd Exec & PLE via Cisco IMC Web UI A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root.  This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by entering crafted inputs to the web-based management interface of the affected software. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system as the root user. 
Unified Computing System
CVE-2026-20198 Aug 05, 2026
Cisco IMC XSS via Insufficient Input Validation A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of an affected interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the browser of the targeted user or access sensitive, browser-based information.
Enterprise Nfv Infrastructure Software
Unified Computing System
CVE-2026-20124 Aug 05, 2026
CVE-2026-20124: SNMP DoS via malformed request on Cisco IOS XE A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to improper error handling when parsing SNMP requests. This vulnerability affects all versions of SNMP — Versions 1, 2c, and 3. An attacker could exploit this vulnerability by sending a malformed SNMP request to an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly. The attacker must have the SNMPv1 or v2c read-only or read-write community string or valid SNMPv3 user credentials on the affected device.
IOS XE
CVE-2026-20028 Aug 05, 2026
Net Driver CVE-2026-20028: Auth Bypass of FW Rules in Cisco TS Agent A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker to bypass firewall rules that are associated with the account of the attacker. This vulnerability is due to an incorrect mapping of network connections to user accounts. An attacker with at least user-level credentials could exploit this vulnerability by sending crafted network traffic to an affected device. A successful exploit could allow the attacker to inherit the firewall rules associated with a different user in the system.
CVE-2026-20316 Jul 29, 2026
Cisco FMC static creds in web UI allow remote login A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user.  Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced.   Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges.
Secure Firewall Management Center
CVE-2026-20187 Jul 15, 2026
Cisco RoomOS Improper Exception Handling CVE-2026-20187 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20187 are related to improper handling of exceptional conditions that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-703.
Roomos
CVE-2026-20158 Jul 15, 2026
Cisco RoomOS Improper Resource Control (CWE-664) Vulnerability As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20158 are related to improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664.
Roomos
CVE-2026-20153 Jul 15, 2026
Cisco RoomOS Improper Input Validation (CWE-20) As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20153 are related to improper input validation that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-20.
Roomos
CVE-2026-20157 Jul 15, 2026
Cisco RoomOS Encryption Deficiency (CWE311) As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20157 are related to missing encryption that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-311.
Roomos
CVE-2026-20156 Jul 15, 2026
Cisco RoomOS Buffer Overflow (CWE-119) CVE-2026-20156 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20156 are related to improper restriction of operations within the bounds of a memory buffer that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-119.
Roomos
CVE-2026-20146 Jul 15, 2026
Cisco ISE Path Traversal via Authenticated HTTP Request A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials.  This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system.
Identity Services Engine Software
CVE-2026-20150 Jul 15, 2026
Cisco RoomOS Improper Access Control (CWE-284) CVE-2026-20150 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20150 are related to improper access control that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284.
Roomos
CVE-2026-20243 Jul 01, 2026
CLAMAV ALZ Parser OOB Buffer Write -> DoS A vulnerability in the ALZ file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in ALZ files during scanning, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted file that contains ALZ content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Secure Endpoint
CVE-2026-20244 Jul 01, 2026
DoS via DMG parser in ClamAV A vulnerability in the DMG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in DMG files during scanning, which may result in an integer overflow on 32-bit platforms only. An attacker could exploit this vulnerability by submitting a crafted file that contains DMG content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Secure Endpoint
CVE-2026-20215 Jul 01, 2026
ClamAV 7z Parser DoS via Mem Corrupt A vulnerability in the 7z file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in 7z files during scanning, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted file that contains 7z content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Secure Endpoint
CVE-2026-20217 Jul 01, 2026
ClamAV PESpin Parser Overflow: DoS via crafted file A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PESpin files during scanning, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted file that contains PESpin content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Secure Endpoint
CVE-2026-20216 Jul 01, 2026
ClamAV InstallShield Parser DoS via Resource Abuse A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper handling of temporary resources during file scanning. An attacker could exploit this vulnerability by submitting a crafted InstallShield file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process and temporarily consume available system resources, resulting in a DoS condition on the affected software.
Secure Endpoint
CVE-2026-20213 Jul 01, 2026
ClamAV PE Parser OOB Buffer Write DoS A vulnerability in the PE file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PE files during scanning, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted file that contains PE content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Secure Endpoint
CVE-2026-20214 Jul 01, 2026
FSG Parsing Buffer Overflow Causes DoS in ClamAV A vulnerability in the FSG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in FSG files during scanning, which may result in an out-of-bounds buffer write. An attacker could exploit this vulnerability by submitting a crafted file that contains portable executable content compressed with FSG to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software.
Secure Endpoint
CVE-2026-20191 Jul 01, 2026
Unauth. Remote File Read in Cisco Catalyst Center A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container.  This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to read arbitrary files from a restricted container of the affected device.
Catalyst Center
CVE-2026-20178 Jun 17, 2026
Cisco Webex App Browser Open Redirect via URL Param A vulnerability in the browser-based version of Cisco Webex App could have allowed an unauthenticated, remote attacker to redirect users to a malicious webpage. Cisco has addressed this vulnerability in the Cisco Webex App, and no customer action is needed. This vulnerability existed due to improper input validation of URL parameters in an HTTP request. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by persuading a user to click a crafted URL. A successful exploit could have allowed the attacker to redirect a user to a malicious website.
CVE-2026-20246 Jun 17, 2026
Privilege Escalation via CLI Injection in Cisco Umbrella Virtual Appliance A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of user-supplied commands. An attacker with vmadmin privileges could exploit this vulnerability by using certain commands at the CLI. A successful exploit could allow the attacker to elevate privileges to root.
CVE-2026-20220 Jun 17, 2026
Cisco Crosswork NC: Auth Cmd Exec via Web Template A vulnerability in the web-based management interface of Cisco Crosswork Network Controller could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vulnerability is due to insufficient input validation in the configuration template engine of the web-based management interface. An attacker could exploit this vulnerability by sending a crafted request to the affected device. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system in limited areas of the file system. This vulnerability affects only areas of the operating system for which the template user has write permissions.  To exploit this vulnerability, the attacker must have valid template user credentials with write permissions. Template users with read permissions cannot exploit this vulnerability. 
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.