Network security

Cisco Security advisories: every record the registers tie to its products

In one line

82 advisories are attributed to Cisco Security products in this record, covering November 2021 to July 2026, and 18 of them appear in the CISA catalogue of known exploited vulnerabilities. A further 2 register entries mention Cisco Security without naming one of its products as affected, and are excluded rather than counted. Each entry below links to the register that published it.

Attributed

82

tied to a named product

Known exploited

18

in the CISA catalogue

Rated critical

22

by the register

Last checked

Jul 17, 2026

sources re-queried

Why this list is shorter than a CVE mirror

The registers are searched by keyword, so a search for a company name returns advisories that merely mention it. A mirror publishes those. This page does not: an entry appears only when the register itself ties it to a product of Cisco Security, through a reference on the vendor's own domain, the vendor named as the assigning authority, or the affected product list naming it.

2 entries did not clear that bar and are not shown. That is the difference, and it is deliberate: a page that lists another company's vulnerability under this heading is wrong in the way that matters most.

65 of the 82 records carry a CVSS base score from the register. Where none is published, none is shown, and no score is estimated.

The full list, most recently exploited and most recent first

Records held by several registers are folded into one entry with a link to each, so the same vulnerability is not counted twice. Entries listed in the CISA catalogue of known exploited vulnerabilities are shown first, because that is the one flag on this page that changes what a reader should do next.

  • CVE-2026-20230criticalCVSS 8.6Known exploitedJun 25, 2026

    Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability

  • CVE-2026-20182criticalCVSS 10.0Known exploitedMay 14, 2026

    Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

  • CVE-2026-20045criticalKnown exploitedJan 21, 2026

    Cisco Unified Communications Products Code Injection Vulnerability

  • CVE-2025-20362criticalKnown exploitedSep 25, 2025

    Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability

  • CVE-2025-20333criticalKnown exploitedSep 25, 2025

    Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability

  • CVE-2014-2120criticalKnown exploitedNov 12, 2024

    Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability

  • CVE-2024-20481criticalKnown exploitedOct 24, 2024

    Cisco ASA and FTD Denial-of-Service Vulnerability

  • CVE-2024-20359criticalKnown exploitedApr 24, 2024

    Cisco ASA and FTD Privilege Escalation Vulnerability

  • CVE-2024-20353criticalKnown exploitedApr 24, 2024

    Cisco ASA and FTD Denial of Service Vulnerability

  • CVE-2020-3259criticalKnown exploitedFeb 15, 2024

    Cisco ASA and FTD Information Disclosure Vulnerability

  • CVE-2023-20269criticalKnown exploitedSep 13, 2023

    Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability

  • CVE-2016-6415criticalKnown exploitedMay 19, 2023

    Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability

  • CVE-2016-6367criticalKnown exploitedMay 24, 2022

    Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability

  • CVE-2016-6366criticalKnown exploitedMay 24, 2022

    Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability

  • CVE-2017-12237criticalKnown exploitedMar 03, 2022

    Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability

  • CVE-2018-0296criticalKnown exploitedNov 03, 2021

    Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability

  • CVE-2020-3580criticalKnown exploitedNov 03, 2021

    Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability

  • CVE-2020-3452criticalKnown exploitedNov 03, 2021

    Cisco ASA and FTD Read-Only Path Traversal Vulnerability

  • WID-SEC-2026-2374mediumCVSS 5.5Jul 16, 2026

    Affected products: Cisco Identity Services Engine (ISE)

  • CVE-2026-20187highCVSS 7.5Jul 15, 2026

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review.

  • CVE-2026-20158highCVSS 7.5Jul 15, 2026

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review.

  • CVE-2026-20153highCVSS 7.5Jul 15, 2026

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review.

  • CVE-2026-20157highCVSS 7.5Jul 15, 2026

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review.

  • CVE-2026-20156highCVSS 8.1Jul 15, 2026

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review.

  • CVE-2026-20150highCVSS 8.8Jul 15, 2026

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review.

  • WID-SEC-2026-2174mediumCVSS 7.5Jul 03, 2026

    Affected products: Cisco Catalyst

  • WID-SEC-2026-1988lowCVSS 4.3Jun 18, 2026

    Affected products: Cisco WebEx

  • WID-SEC-2026-1989highCVSS 9.1Jun 18, 2026

    Affected products: Cisco Identity Services Engine (ISE)

  • WID-SEC-2026-1928mediumCVSS 6.5Jun 16, 2026

    Affected products: Cisco SD-WAN

  • WID-SEC-2026-1801highCVSS 8.6Jun 05, 2026

    Affected products: Cisco Unified Communications Manager (CUCM)

  • WID-SEC-2026-1798mediumCVSS 6.1Jun 05, 2026

    Affected products: Cisco WebEx

  • WID-SEC-2026-1790mediumCVSS 6.1Jun 05, 2026

    Affected products: Cisco Finesse

  • WID-SEC-2026-1788highCVSS 7.8Jun 05, 2026

    Affected products: Cisco Catalyst SD-WAN Manager

  • WID-SEC-2026-1622mediumCVSS 6.8May 21, 2026

    Affected products: Cisco Nexus, Cisco NX-OS

  • WID-SEC-2026-1540highCVSS 8.6May 15, 2026

    Affected products: Cisco Catalyst SD-WAN Manager

  • WID-SEC-2026-1534criticalCVSS 10.0May 15, 2026

    Affected products: Cisco Catalyst

  • WID-SEC-2026-1391mediumCVSS 5.3May 07, 2026

    Affected products: Cisco Identity Services Engine (ISE)

  • WID-SEC-2026-1390mediumCVSS 7.5May 07, 2026

    Affected products: Cisco Network Services Orchestrator

  • WID-SEC-2026-1389lowCVSS 4.3May 07, 2026

    Affected products: Cisco Prime Infrastructure

  • WID-SEC-2026-1388highCVSS 8.8May 07, 2026

    Affected products: Cisco Unity Connection

  • CVE-2026-20188May 06, 2026

    Following the initial publication of the Security Advisory about a denial of service (DoS) condition in Cisco Crosswork Network Controller and Cisco Network Services Orchestrator (NSO)…

  • WID-SEC-2025-2142criticalCVSS 9.9Apr 24, 2026

    Affected products: Cisco ASA (Adaptive Security Appliance), Cisco Secure Firewall Threat Defense, Cisco IOS, Cisco IOS XE

  • WID-SEC-2026-0516criticalCVSS 10.0Apr 21, 2026

    Affected products: Cisco Catalyst SD-WAN Manager

  • WID-SEC-2026-1149mediumCVSS 6.5Apr 16, 2026

    Affected products: Cisco Unity Connection

  • WID-SEC-2026-1146highCVSS 9.9Apr 16, 2026

    Affected products: Cisco Identity Services Engine (ISE)

  • WID-SEC-2026-1132highCVSS 9.8Apr 16, 2026

    Affected products: Cisco WebEx

  • WID-SEC-2026-1131mediumCVSS 5.3Apr 16, 2026

    Affected products: Cisco Secure Web Appliance, Cisco AsyncOS

  • WID-SEC-2026-0964highCVSS 9.8Apr 07, 2026

    Affected products: Cisco Smart Software Manager On-Prem

  • WID-SEC-2026-0955mediumCVSS 6.5Apr 02, 2026

    Affected products: Cisco Nexus Dashboard

  • WID-SEC-2026-0953highCVSS 9.8Apr 02, 2026

    Affected products: Cisco Integrated Management Controller

  • WID-SEC-2026-0951highCVSS 8.0Apr 02, 2026

    Affected products: Cisco Evolved Programmable Network Manager

  • CVE-2026-20096mediumCVSS 6.5Apr 01, 2026

    A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an…

  • CVE-2026-20097mediumCVSS 6.5Apr 01, 2026

    A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to execute arbitrary code as the root…

  • CVE-2026-20095mediumCVSS 6.5Apr 01, 2026

    A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an…

  • WID-SEC-2026-0874highCVSS 8.6Mar 26, 2026

    Affected products: Cisco IOS XE, Cisco Catalyst, Cisco IOS

  • WID-SEC-2026-0872mediumCVSS 5.4Mar 26, 2026

    Affected products: Cisco Catalyst SD-WAN Manager

  • WID-SEC-2026-0866highCVSS 8.6Mar 26, 2026

    Affected products: Cisco IOS, Cisco IOS XE, Cisco Secure Firewall Threat Defense

  • CVE-2026-20104mediumCVSS 6.1Mar 25, 2026

    A vulnerability in the bootloader of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches, Cisco Catalyst ESS9300 Embedded Series Switches, Cisco Catalyst IE9310 and IE9320 Rugged…

  • CVE-2026-20012highCVSS 8.6Mar 25, 2026

    A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, and…

  • WID-SEC-2026-0610criticalCVSS 10.0Mar 19, 2026

    Affected products: Cisco Secure Firewall Management Center, Cisco Secure Firewall Threat Defense

  • WID-SEC-2026-0706highCVSS 8.8Mar 12, 2026

    Affected products: Cisco IOS XR

  • WID-SEC-2026-0699mediumCVSS 6.1Mar 12, 2026

    Affected products: Cisco Finesse, Cisco Unified Intelligence Center, Cisco Unified Contact Center Express (UCCX)

  • CVE-2026-20118mediumCVSS 6.8Mar 11, 2026

    A vulnerability in the handling of an Egress Packet Network Interface (EPNI) Aligner interrupt in Cisco IOS XR Software for Cisco Network Convergence System (NCS) 5500 Series with NC57 line…

  • WID-SEC-2026-0608mediumCVSS 5.8Mar 05, 2026

    Affected products: Open Source Snort, Cisco ASA (Adaptive Security Appliance), Cisco IOS XE, Cisco Meraki MX

  • WID-SEC-2026-0605mediumCVSS 7.1Mar 05, 2026

    Affected products: Cisco Secure Firewall Threat Defense

  • CVE-2026-20025mediumCVSS 6.8Mar 04, 2026

    A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, adjacent attacker to cause an affected device to…

  • CVE-2026-20024mediumCVSS 6.8Mar 04, 2026

    A vulnerability in the OSPF protocol of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, adjacent attacker to cause an affected device to…

  • CVE-2026-20023mediumCVSS 6.1Mar 04, 2026

    A vulnerability in the OSPF protocol of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an…

  • CVE-2026-20062highCVSS 7.2Mar 04, 2026

    A vulnerability in the CLI of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software in multiple context mode could allow an authenticated, local attacker with administrative…

  • CVE-2026-20015mediumCVSS 5.8Mar 04, 2026

    A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to cause a DoS condition on an…

  • CVE-2026-20014highCVSS 7.7Mar 04, 2026

    A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an authenticated, remote attacker with valid VPN user credentials to…

  • CVE-2026-20013mediumCVSS 5.8Mar 04, 2026

    A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to cause a DoS condition on an…

  • CVE-2026-20106mediumCVSS 5.3Mar 04, 2026

    A vulnerability in the Remote Access SSL VPN, HTTP management and MUS functionality, of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense…

  • CVE-2026-20105highCVSS 7.7Mar 04, 2026

    A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow…

  • CVE-2026-20103highCVSS 8.6Mar 04, 2026

    A vulnerability in the Remote Access SSL VPN functionality of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow…

  • CVE-2026-20101highCVSS 8.6Mar 04, 2026

    A vulnerability in the SAML 2.0 single sign-on (SSO) feature of Cisco Secure Firewall ASA Software and Secure FTD Software could allow an unauthenticated, remote attacker to cause the…

  • CVE-2026-20100highCVSS 7.7Mar 04, 2026

    A vulnerability in the LUA interperter of the Remote Access SSL VPN feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD)…

  • CVE-2026-20003mediumCVSS 4.9Mar 04, 2026

    A vulnerability in the REST API of Cisco Secure FMC Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.

  • CVE-2026-20039highCVSS 8.6Mar 04, 2026

    A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an…

  • CVE-2026-20008mediumCVSS 6.0Mar 04, 2026

    A vulnerability in a small subset of CLI commands that are used on Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software…

  • CVE-2026-20009mediumCVSS 5.3Mar 04, 2026

    A vulnerability in the implementation of the proprietary SSH stack with SSH key-based authentication in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software could allow an…

  • CVE-2026-20001mediumCVSS 6.5Mar 04, 2026

    A vulnerability in the REST API of Cisco Secure FMC Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system.

Which registers contributed

RegisterOperated byEntriesLatest
CERT-Bund security advisoriesBSI, Federal Republic of Germany35Jul 16, 2026
European Vulnerability DatabaseENISA, European Union33Jul 15, 2026
Known Exploited Vulnerabilities catalogueCISA, United States18Jun 25, 2026

The entry counts here are the raw register totals for Cisco Security, before attribution. They are larger than the list above for exactly that reason.

Questions this page answers

How many vulnerabilities does Cisco Security have?

82 advisories in this record are tied by a register to a product of Cisco Security. That is not the same as the number of vulnerabilities the products contain, and no public source knows that number. It is the count of what has been found, disclosed and published, which depends on how much the products are examined and how openly the vendor discloses.

Are any Cisco Security vulnerabilities being actively exploited?

18 of the 82 records here appear in the CISA catalogue of known exploited vulnerabilities, which lists flaws with confirmed exploitation in the wild. They are shown first in the list above. Whether any of them affects your deployment depends on the versions and components you run.

Why does this page show fewer CVEs for Cisco Security than other sites?

Because a keyword search for a company name returns advisories about other companies' products that mention it in passing, and this page excludes those. 2 register entries name Cisco Security without naming one of its products as affected. A mirror that lists them produces a longer page and a wrong number.

Where do the Cisco Security advisories on this page come from?

From CERT-Bund security advisories (BSI, Federal Republic of Germany); European Vulnerability Database (ENISA, European Union); Known Exploited Vulnerabilities catalogue (CISA, United States). Every entry links back to the register that published it, and carries the date that register states. Where the same vulnerability is held by several registers it is shown once with a link to each, rather than counted twice.

Does a long advisory list mean Cisco Security is insecure?

No. A register records what researchers found and what the vendor disclosed, so a widely deployed product with a working disclosure process accumulates more entries than one nobody examines. A short list can equally mean a small install base or a vendor that publishes little. This page reports the record and does not rate the vendor, because whether this is acceptable depends on your risk appetite, your compliance scope and the alternatives you are weighing.

A list of advisories is not a risk assessment

What matters is which of these touch the components you actually run, in the configuration you actually run them in, and whether that is acceptable next to the alternatives on your shortlist. DecisionOS reads the same pool against the criteria of a real decision and produces a memo that holds up in front of a board and an auditor.

The full Cisco Security record, including sources and open questions

Cisco Security vulnerabilities: all 82 advisories on record, with sources | DecisionOS by nexalign