Netzwerksicherheit

Schwachstellen bei Cisco Security: jede Meldung, die die Register seinen Produkten zuordnen

Kurz gesagt

82 Schwachstellenmeldungen in diesem Bestand sind Produkten von Cisco Security zugeordnet. Sie reichen von November 2021 bis Juli 2026. 18 davon stehen im CISA-Katalog bekannt ausgenutzter Schwachstellen. Weitere 2 Registereinträge nennen Cisco Security, ohne eines seiner Produkte als betroffen zu benennen, und bleiben deshalb außen vor, statt mitgezählt zu werden. Jeder Eintrag unten verlinkt auf das Register, das ihn veröffentlicht hat.

Zugeordnet

82

an ein benanntes Produkt gebunden

Aktiv ausgenutzt

18

im CISA-Katalog geführt

Als kritisch eingestuft

22

Einstufung des Registers

Zuletzt geprüft

17. Juli 2026

Quellen neu abgefragt

Warum diese Liste kürzer ist als ein CVE-Spiegel

Die Register werden über Stichworte durchsucht, also liefert die Suche nach einem Firmennamen auch Meldungen zurück, die diesen Namen nur erwähnen. Ein Spiegel veröffentlicht sie mit. Diese Seite nicht: Ein Eintrag erscheint erst, wenn das Register selbst ihn an ein Produkt von Cisco Security bindet, über einen Verweis auf eine Adresse des Anbieters, über Cisco Security als die Stelle, die die CVE-Nummer vergeben hat, oder über die Liste der betroffenen Produkte.

2 Einträge haben diese Hürde nicht genommen und werden nicht angezeigt. Das ist der Unterschied, und er ist gewollt: Eine Seite, die die Schwachstelle eines anderen Unternehmens unter dieser Überschrift führt, ist auf die Art falsch, die am meisten kostet.

65 der 82 Einträge tragen einen CVSS-Basiswert aus dem Register. Wo keiner veröffentlicht ist, steht keiner, und geschätzt wird nichts.

Die vollständige Liste, bekannt ausgenutzte und neueste zuerst

Führen mehrere Register dieselbe Meldung, steht sie einmal da, mit einem Link auf jedes. So wird dieselbe Schwachstelle nicht doppelt gezählt. Einträge aus dem CISA-Katalog bekannt ausgenutzter Schwachstellen stehen oben, weil das der eine Hinweis auf dieser Seite ist, der ändert, was als Nächstes zu tun ist.

  • CVE-2026-20230criticalCVSS 8.6Aktiv ausgenutzt25. Juni 2026

    Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability

  • CVE-2026-20182criticalCVSS 10.0Aktiv ausgenutzt14. Mai 2026

    Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

  • CVE-2026-20045criticalAktiv ausgenutzt21. Jan. 2026

    Cisco Unified Communications Products Code Injection Vulnerability

  • CVE-2025-20362criticalAktiv ausgenutzt25. Sept. 2025

    Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability

  • CVE-2025-20333criticalAktiv ausgenutzt25. Sept. 2025

    Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability

  • CVE-2014-2120criticalAktiv ausgenutzt12. Nov. 2024

    Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability

  • CVE-2024-20481criticalAktiv ausgenutzt24. Okt. 2024

    Cisco ASA and FTD Denial-of-Service Vulnerability

  • CVE-2024-20359criticalAktiv ausgenutzt24. Apr. 2024

    Cisco ASA and FTD Privilege Escalation Vulnerability

  • CVE-2024-20353criticalAktiv ausgenutzt24. Apr. 2024

    Cisco ASA and FTD Denial of Service Vulnerability

  • CVE-2020-3259criticalAktiv ausgenutzt15. Feb. 2024

    Cisco ASA and FTD Information Disclosure Vulnerability

  • CVE-2023-20269criticalAktiv ausgenutzt13. Sept. 2023

    Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability

  • CVE-2016-6415criticalAktiv ausgenutzt19. Mai 2023

    Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability

  • CVE-2016-6367criticalAktiv ausgenutzt24. Mai 2022

    Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability

  • CVE-2016-6366criticalAktiv ausgenutzt24. Mai 2022

    Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability

  • CVE-2017-12237criticalAktiv ausgenutzt03. März 2022

    Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability

  • CVE-2018-0296criticalAktiv ausgenutzt03. Nov. 2021

    Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability

  • CVE-2020-3580criticalAktiv ausgenutzt03. Nov. 2021

    Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability

  • CVE-2020-3452criticalAktiv ausgenutzt03. Nov. 2021

    Cisco ASA and FTD Read-Only Path Traversal Vulnerability

  • WID-SEC-2026-2374mediumCVSS 5.516. Juli 2026

    Affected products: Cisco Identity Services Engine (ISE)

  • CVE-2026-20187highCVSS 7.515. Juli 2026

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review.

  • CVE-2026-20158highCVSS 7.515. Juli 2026

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review.

  • CVE-2026-20153highCVSS 7.515. Juli 2026

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review.

  • CVE-2026-20157highCVSS 7.515. Juli 2026

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review.

  • CVE-2026-20156highCVSS 8.115. Juli 2026

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review.

  • CVE-2026-20150highCVSS 8.815. Juli 2026

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review.

  • WID-SEC-2026-2174mediumCVSS 7.503. Juli 2026

    Affected products: Cisco Catalyst

  • WID-SEC-2026-1988lowCVSS 4.318. Juni 2026

    Affected products: Cisco WebEx

  • WID-SEC-2026-1989highCVSS 9.118. Juni 2026

    Affected products: Cisco Identity Services Engine (ISE)

  • WID-SEC-2026-1928mediumCVSS 6.516. Juni 2026

    Affected products: Cisco SD-WAN

  • WID-SEC-2026-1801highCVSS 8.605. Juni 2026

    Affected products: Cisco Unified Communications Manager (CUCM)

  • WID-SEC-2026-1798mediumCVSS 6.105. Juni 2026

    Affected products: Cisco WebEx

  • WID-SEC-2026-1790mediumCVSS 6.105. Juni 2026

    Affected products: Cisco Finesse

  • WID-SEC-2026-1788highCVSS 7.805. Juni 2026

    Affected products: Cisco Catalyst SD-WAN Manager

  • WID-SEC-2026-1622mediumCVSS 6.821. Mai 2026

    Affected products: Cisco Nexus, Cisco NX-OS

  • WID-SEC-2026-1540highCVSS 8.615. Mai 2026

    Affected products: Cisco Catalyst SD-WAN Manager

  • WID-SEC-2026-1534criticalCVSS 10.015. Mai 2026

    Affected products: Cisco Catalyst

  • WID-SEC-2026-1391mediumCVSS 5.307. Mai 2026

    Affected products: Cisco Identity Services Engine (ISE)

  • WID-SEC-2026-1390mediumCVSS 7.507. Mai 2026

    Affected products: Cisco Network Services Orchestrator

  • WID-SEC-2026-1389lowCVSS 4.307. Mai 2026

    Affected products: Cisco Prime Infrastructure

  • WID-SEC-2026-1388highCVSS 8.807. Mai 2026

    Affected products: Cisco Unity Connection

  • CVE-2026-2018806. Mai 2026

    Following the initial publication of the Security Advisory about a denial of service (DoS) condition in Cisco Crosswork Network Controller and Cisco Network Services Orchestrator (NSO)…

  • WID-SEC-2025-2142criticalCVSS 9.924. Apr. 2026

    Affected products: Cisco ASA (Adaptive Security Appliance), Cisco Secure Firewall Threat Defense, Cisco IOS, Cisco IOS XE

  • WID-SEC-2026-0516criticalCVSS 10.021. Apr. 2026

    Affected products: Cisco Catalyst SD-WAN Manager

  • WID-SEC-2026-1149mediumCVSS 6.516. Apr. 2026

    Affected products: Cisco Unity Connection

  • WID-SEC-2026-1146highCVSS 9.916. Apr. 2026

    Affected products: Cisco Identity Services Engine (ISE)

  • WID-SEC-2026-1132highCVSS 9.816. Apr. 2026

    Affected products: Cisco WebEx

  • WID-SEC-2026-1131mediumCVSS 5.316. Apr. 2026

    Affected products: Cisco Secure Web Appliance, Cisco AsyncOS

  • WID-SEC-2026-0964highCVSS 9.807. Apr. 2026

    Affected products: Cisco Smart Software Manager On-Prem

  • WID-SEC-2026-0955mediumCVSS 6.502. Apr. 2026

    Affected products: Cisco Nexus Dashboard

  • WID-SEC-2026-0953highCVSS 9.802. Apr. 2026

    Affected products: Cisco Integrated Management Controller

  • WID-SEC-2026-0951highCVSS 8.002. Apr. 2026

    Affected products: Cisco Evolved Programmable Network Manager

  • CVE-2026-20096mediumCVSS 6.501. Apr. 2026

    A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an…

  • CVE-2026-20097mediumCVSS 6.501. Apr. 2026

    A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to execute arbitrary code as the root…

  • CVE-2026-20095mediumCVSS 6.501. Apr. 2026

    A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an…

  • WID-SEC-2026-0874highCVSS 8.626. März 2026

    Affected products: Cisco IOS XE, Cisco Catalyst, Cisco IOS

  • WID-SEC-2026-0872mediumCVSS 5.426. März 2026

    Affected products: Cisco Catalyst SD-WAN Manager

  • WID-SEC-2026-0866highCVSS 8.626. März 2026

    Affected products: Cisco IOS, Cisco IOS XE, Cisco Secure Firewall Threat Defense

  • CVE-2026-20104mediumCVSS 6.125. März 2026

    A vulnerability in the bootloader of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches, Cisco Catalyst ESS9300 Embedded Series Switches, Cisco Catalyst IE9310 and IE9320 Rugged…

  • CVE-2026-20012highCVSS 8.625. März 2026

    A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, and…

  • WID-SEC-2026-0610criticalCVSS 10.019. März 2026

    Affected products: Cisco Secure Firewall Management Center, Cisco Secure Firewall Threat Defense

  • WID-SEC-2026-0706highCVSS 8.812. März 2026

    Affected products: Cisco IOS XR

  • WID-SEC-2026-0699mediumCVSS 6.112. März 2026

    Affected products: Cisco Finesse, Cisco Unified Intelligence Center, Cisco Unified Contact Center Express (UCCX)

  • CVE-2026-20118mediumCVSS 6.811. März 2026

    A vulnerability in the handling of an Egress Packet Network Interface (EPNI) Aligner interrupt in Cisco IOS XR Software for Cisco Network Convergence System (NCS) 5500 Series with NC57 line…

  • WID-SEC-2026-0608mediumCVSS 5.805. März 2026

    Affected products: Open Source Snort, Cisco ASA (Adaptive Security Appliance), Cisco IOS XE, Cisco Meraki MX

  • WID-SEC-2026-0605mediumCVSS 7.105. März 2026

    Affected products: Cisco Secure Firewall Threat Defense

  • CVE-2026-20025mediumCVSS 6.804. März 2026

    A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, adjacent attacker to cause an affected device to…

  • CVE-2026-20024mediumCVSS 6.804. März 2026

    A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, adjacent attacker to cause an affected device to…

  • CVE-2026-20023mediumCVSS 6.104. März 2026

    A vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an…

  • CVE-2026-20062highCVSS 7.204. März 2026

    A vulnerability in the CLI of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software in multiple context mode could allow an authenticated, local attacker with administrative…

  • CVE-2026-20015mediumCVSS 5.804. März 2026

    A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to cause a DoS condition on an…

  • CVE-2026-20014highCVSS 7.704. März 2026

    A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, remote attacker with valid VPN user credentials to…

  • CVE-2026-20013mediumCVSS 5.804. März 2026

    A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to cause a DoS condition on an…

  • CVE-2026-20106mediumCVSS 5.304. März 2026

    A vulnerability in the Remote Access SSL VPN, HTTP management and MUS functionality, of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense…

  • CVE-2026-20105highCVSS 7.704. März 2026

    A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow…

  • CVE-2026-20103highCVSS 8.604. März 2026

    A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow…

  • CVE-2026-20101highCVSS 8.604. März 2026

    A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Secure FTD Software could allow an unauthenticated, remote attacker to cause the…

  • CVE-2026-20100highCVSS 7.704. März 2026

    A vulnerability in the LUA interperter of the Remote Access SSL VPN feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD)…

  • CVE-2026-20003mediumCVSS 4.904. März 2026

    A vulnerability in the REST API of Cisco Secure FMC Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.

  • CVE-2026-20039highCVSS 8.604. März 2026

    A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an…

  • CVE-2026-20008mediumCVSS 6.004. März 2026

    A vulnerability in a small subset of CLI commands that are used on Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software…

  • CVE-2026-20009mediumCVSS 5.304. März 2026

    A vulnerability in the implementation of the proprietary SSH stack with SSH key-based authentication in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software could allow an…

  • CVE-2026-20001mediumCVSS 6.504. März 2026

    A vulnerability in the REST API of Cisco Secure FMC Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.

Welche Register beigetragen haben

RegisterBetreiberEinträgeNeuester Eintrag
CERT-Bund SicherheitshinweiseBSI, Bundesrepublik Deutschland3516. Juli 2026
European Vulnerability DatabaseENISA, Europäische Union3315. Juli 2026
Katalog bekannt ausgenutzter SchwachstellenCISA, Vereinigte Staaten1825. Juni 2026

Die Zahlen hier sind die rohen Registertreffer zu Cisco Security, vor der Zuordnung. Genau deshalb sind sie größer als die Liste darüber.

Fragen, die diese Seite beantwortet

Wie viele Schwachstellen hat Cisco Security?

82 Meldungen in diesem Bestand sind von einem Register einem Produkt von Cisco Security zugeordnet. Das ist nicht dasselbe wie die Zahl der Schwachstellen in den Produkten, und die kennt keine öffentliche Quelle. Es ist die Zahl dessen, was gefunden, offengelegt und veröffentlicht wurde, und die hängt daran, wie intensiv die Produkte geprüft werden und wie offen der Anbieter damit umgeht.

Werden Schwachstellen in Produkten von Cisco Security aktiv ausgenutzt?

18 der 82 Einträge stehen im CISA-Katalog bekannt ausgenutzter Schwachstellen, der Lücken mit bestätigter Ausnutzung in freier Wildbahn führt. Sie stehen in der Liste oben. Ob einer davon Ihre Installation betrifft, hängt an den Versionen und Komponenten, die Sie betreiben.

Warum zeigt diese Seite weniger CVEs zu Cisco Security als andere Seiten?

Weil eine Stichwortsuche nach einem Firmennamen auch Meldungen über Produkte anderer Unternehmen zurückgibt, die den Namen nur nebenbei erwähnen. Diese Seite lässt sie weg. 2 Registereinträge nennen Cisco Security, ohne eines seiner Produkte als betroffen zu benennen. Ein Spiegel, der sie mitführt, erzeugt eine längere Seite und eine falsche Zahl.

Woher stammen die Meldungen zu Cisco Security auf dieser Seite?

Aus diesen Registern: CERT-Bund Sicherheitshinweise, betrieben von BSI, Bundesrepublik Deutschland; European Vulnerability Database, betrieben von ENISA, Europäische Union; Katalog bekannt ausgenutzter Schwachstellen, betrieben von CISA, Vereinigte Staaten. Jeder Eintrag verlinkt zurück auf das Register, das ihn veröffentlicht hat, und trägt das Datum, das dieses Register nennt. Führen mehrere Register dieselbe Schwachstelle, steht sie einmal da, mit einem Link auf jedes, statt doppelt gezählt zu werden.

Heißt eine lange Liste, dass Cisco Security unsicher ist?

Nein. Ein Register hält fest, was Forschende gefunden und was der Anbieter offengelegt hat. Ein weit verbreitetes Produkt mit einem funktionierenden Offenlegungsprozess sammelt deshalb mehr Einträge als eines, das niemand prüft. Eine kurze Liste kann genauso gut für eine kleine Installationsbasis stehen oder für einen Anbieter, der wenig veröffentlicht. Diese Seite gibt den Bestand wieder und bewertet den Anbieter nicht, denn ob das für Sie tragbar ist, hängt an Ihrer Risikobereitschaft, Ihrem Compliance-Umfang und den Alternativen, die Sie abwägen.

Eine Liste von Meldungen ist noch keine Risikobewertung

Es zählt, welche davon die Komponenten betreffen, die Sie tatsächlich betreiben, in der Konfiguration, in der Sie sie betreiben, und ob das neben den Alternativen Ihrer engeren Auswahl tragbar ist. DecisionOS liest denselben Bestand an den Kriterien einer konkreten Entscheidung und liefert ein Memo, das vor Geschäftsführung und Revision standhält.

Der vollständige Bestand zu Cisco Security, samt Quellen und offenen Fragen

Cisco Security Schwachstellen: alle 82 Meldungen im Bestand, mit Quelle | DecisionOS by nexalign