Skip to content
English

Products › Brands

Brand

Cisco: actively exploited vulnerabilities

99 vulnerabilities in Cisco products (IOS / IOS XE, ASA / Firepower (FTD), RV routers (Small Business)…) are in CISA’s catalog of exploited vulnerabilities, 6 of them added in the last 90 days. Last added: September 16, 2026.

The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).

By category

Add just one Cisco category to your radar, or open its page.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

Affected products

  • IOS / IOS XE 39 vulnerabilities · Switches and routers
  • ASA / Firepower (FTD) 14 vulnerabilities · Firewalls and VPNs
  • RV routers (Small Business) 10 vulnerabilities · Home routers and IoT
  • Catalyst SD-WAN 8 vulnerabilities · Switches and routers
  • IOS XR 6 vulnerabilities · Switches and routers
  • Identity Services Engine (ISE) 3 vulnerabilities · Identity and access
  • IOS / IOS XE / IOS XR 3 vulnerabilities · Switches and routers
  • Secure Firewall Management Center (FMC) 3 vulnerabilities · Firewalls and VPNs
  • AnyConnect Secure Mobility Client 2 vulnerabilities · Firewalls and VPNs
  • HyperFlex HX 2 vulnerabilities · Virtualization and VDI
  • Secure Email Gateway 2 vulnerabilities · Email
  • Unified Communications Manager 2 vulnerabilities · Collaboration and video
Show 5 more products
  • IP Phones 1 vulnerability · Collaboration and video
  • NX-OS 1 vulnerability · Switches and routers
  • Prime Data Center Network Manager (DCNM) 1 vulnerability · Monitoring and ITSM
  • Secure Access Control System (ACS) 1 vulnerability · Identity and access
  • Smart Licensing Utility 1 vulnerability · Monitoring and ITSM

Name used by CISA: Cisco. Product families: indicative classification by this site.

Pace of additions

Number of Cisco vulnerabilities added to CISA’s KEV catalog, per 30-day period (the last one, still in progress, ends on September 28, 2026). Source: CISA KEV catalog.
Catalog additions per 30-day period
PeriodVulnerabilities added
Sep 4, 2025 to Oct 3, 20253
Oct 4, 2025 to Nov 2, 20250
Nov 3, 2025 to Dec 2, 20250
Dec 3, 2025 to Jan 1, 20261
Jan 2, 2026 to Jan 31, 20261
Feb 1, 2026 to Mar 2, 20262
Mar 3, 2026 to Apr 1, 20261
Apr 2, 2026 to May 1, 20263
May 2, 2026 to May 31, 20261
Jun 1, 2026 to Jun 30, 20263
Jul 1, 2026 to Jul 30, 20262
Jul 31, 2026 to Aug 29, 20261
Aug 30, 2026 to Sep 28, 2026 (in progress)3

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this Cisco list.

  1. Rank 1Cisco Identity Services Engine (ISE)

    CVE-2026-76460

    Recently addedHunt for compromise (CISA)

    Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 16, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  2. Rank 2Cisco Secure Email Gateway

    CVE-2026-76461

    Recently addedHunt for compromise (CISA)

    Cisco Secure Email Gateway SQL Injection Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 14, 2026
    CISA deadline
    3 days
    CVSS severity
    9.8 (critical)
  3. Rank 3Cisco Secure Firewall Management Center (FMC)

    CVE-2026-20079

    Recently addedHunt for compromise (CISA)

    Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability

    Added to the catalog less than 30 days ago: ranked by date added.

    Added
    Sep 9, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  4. Rank 4Cisco Catalyst SD-WAN

    CVE-2026-20182

    Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    May 14, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  5. Rank 5Cisco Secure Firewall Management Center (FMC)

    CVE-2026-20131

    Ransomware

    Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Mar 19, 2026
    CISA deadline
    3 days
    CVSS severity
    10.0 (critical)
  6. Rank 6Cisco Catalyst SD-WAN

    CVE-2026-20127

    Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 25, 2026
    CISA deadline
    2 days
    CVSS severity
    10.0 (critical)
  7. Rank 7Cisco Secure Email Gateway

    CVE-2025-20393

    Cisco Multiple Products Improper Input Validation Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Dec 17, 2025
    CISA deadline
    7 days
    CVSS severity
    10.0 (critical)
  8. Rank 8Cisco Unified Communications Manager

    CVE-2026-20045

    Cisco Unified Communications Products Code Injection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jan 21, 2026
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  9. Rank 9Cisco ASA / Firepower (FTD)

    CVE-2026-20349

    Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Aug 11, 2026
    CISA deadline
    3 days
    CVSS severity
    8.6 (high)
  10. Rank 10Cisco Unified Communications Manager

    CVE-2026-20230

    Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 25, 2026
    CISA deadline
    3 days
    CVSS severity
    8.6 (high)
Show 89 more vulnerabilities
  1. Rank 11Cisco IOS / IOS XE

    CVE-2008-4128

    Hunt for compromise (CISA)CVE from 2008, added in 2026

    Cisco IOS Cross-Site Request Forgery Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 13, 2026
    CISA deadline
    3 days
    CVSS severity
    8.1 (high)
  2. Rank 12Cisco Catalyst SD-WAN

    CVE-2026-20245

    Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 9, 2026
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  3. Rank 13Cisco Catalyst SD-WAN

    CVE-2022-20775

    CVE from 2022, added in 2026

    Cisco SD-WAN Path Traversal Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Feb 25, 2026
    CISA deadline
    2 days
    CVSS severity
    7.8 (high)
  4. Rank 14Cisco IOS / IOS XE

    CVE-2025-20352

    Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Sep 29, 2025
    CISA deadline
    21 days
    CVSS severity
    7.7 (high)
  5. Rank 15Cisco Catalyst SD-WAN

    CVE-2026-20128

    Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 20, 2026
    CISA deadline
    3 days
    CVSS severity
    7.5 (high)
  6. Rank 16Cisco Catalyst SD-WAN

    CVE-2026-20133

    Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 20, 2026
    CISA deadline
    3 days
    CVSS severity
    7.5 (high)
  7. Rank 17Cisco Catalyst SD-WAN

    CVE-2026-20262

    Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jun 15, 2026
    CISA deadline
    14 days
    CVSS severity
    6.5 (medium)
  8. Rank 18Cisco Catalyst SD-WAN

    CVE-2026-20122

    Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Apr 20, 2026
    CISA deadline
    3 days
    CVSS severity
    5.4 (medium)
  9. Rank 19Cisco Secure Firewall Management Center (FMC)

    CVE-2026-20316

    Ransomware

    Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability

    Added in the last 12 months: ranked by severity.

    Added
    Jul 29, 2026
    CISA deadline
    3 days
    CVSS severity
    5.3 (medium)
  10. Rank 20Cisco Identity Services Engine (ISE)

    CVE-2025-20281

    Cisco Identity Services Engine Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 28, 2025
    CISA deadline
    21 days
    CVSS severity
    10.0 (critical)
  11. Rank 21Cisco Identity Services Engine (ISE)

    CVE-2025-20337

    Cisco Identity Services Engine Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 28, 2025
    CISA deadline
    21 days
    CVSS severity
    10.0 (critical)
  12. Rank 22Cisco IOS / IOS XE

    CVE-2023-20198

    Cisco IOS XE Web UI Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 16, 2023
    CISA deadline
    4 days
    CVSS severity
    10.0 (critical)
  13. Rank 23Cisco ASA / Firepower (FTD)

    CVE-2025-20333

    Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 25, 2025
    CISA deadline
    1 day
    CVSS severity
    9.9 (critical)
  14. Rank 24Cisco Smart Licensing Utility

    CVE-2024-20439

    Cisco Smart Licensing Utility Static Credential Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 31, 2025
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  15. Rank 25Cisco IOS / IOS XE

    CVE-2017-3881

    CVE from 2017, added in 2022

    Cisco IOS and IOS XE Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  16. Rank 26Cisco RV routers (Small Business)

    CVE-2018-0125

    CVE from 2018, added in 2022

    Cisco VPN Routers Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  17. Rank 27Cisco Secure Access Control System (ACS)

    CVE-2018-0147

    CVE from 2018, added in 2022

    Cisco Secure Access Control System Java Deserialization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  18. Rank 28Cisco IOS / IOS XE

    CVE-2017-12240

    CVE from 2017, added in 2022

    Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    9.8 (critical)
  19. Rank 29Cisco IOS / IOS XE

    CVE-2018-0151

    CVE from 2018, added in 2022

    Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  20. Rank 30Cisco RV routers (Small Business)

    CVE-2022-20699

    Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  21. Rank 31Cisco RV routers (Small Business)

    CVE-2022-20700

    Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  22. Rank 32Cisco IOS / IOS XE

    CVE-2018-0171

    CVE from 2018, added in 2021

    Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  23. Rank 33Cisco IP Phones

    CVE-2020-3161

    Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    9.8 (critical)
  24. Rank 34Cisco HyperFlex HX

    CVE-2021-1497

    Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  25. Rank 35Cisco HyperFlex HX

    CVE-2021-1498

    Cisco HyperFlex HX Data Platform Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    14 days
    CVSS severity
    9.8 (critical)
  26. Rank 36Cisco ASA / Firepower (FTD)

    CVE-2023-20269

    Ransomware

    Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 13, 2023
    CISA deadline
    21 days
    CVSS severity
    9.1 (critical)
  27. Rank 37Cisco IOS / IOS XE

    CVE-2017-6742

    CVE from 2017, added in 2023

    Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 19, 2023
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  28. Rank 38Cisco RV routers (Small Business)

    CVE-2019-15271

    CVE from 2019, added in 2022

    Cisco RV Series Routers Deserialization of Untrusted Data Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jun 8, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  29. Rank 39Cisco ASA / Firepower (FTD)

    CVE-2016-6366

    CVE from 2016, added in 2022

    Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  30. Rank 40Cisco IOS / IOS XE

    CVE-2017-6736

    CVE from 2017, added in 2022

    Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  31. Rank 41Cisco IOS / IOS XE

    CVE-2017-6737

    CVE from 2017, added in 2022

    Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  32. Rank 42Cisco IOS / IOS XE

    CVE-2017-6738

    CVE from 2017, added in 2022

    Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  33. Rank 43Cisco IOS / IOS XE

    CVE-2017-6739

    CVE from 2017, added in 2022

    Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  34. Rank 44Cisco IOS / IOS XE

    CVE-2017-6740

    CVE from 2017, added in 2022

    Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  35. Rank 45Cisco IOS / IOS XE

    CVE-2017-6743

    CVE from 2017, added in 2022

    Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  36. Rank 46Cisco IOS / IOS XE

    CVE-2017-6744

    CVE from 2017, added in 2022

    Cisco IOS Software SNMP Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    8.8 (high)
  37. Rank 47Cisco IOS / IOS XE / IOS XR

    CVE-2018-0167

    CVE from 2018, added in 2022

    Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    8.8 (high)
  38. Rank 48Cisco IOS XR

    CVE-2020-3118

    Cisco IOS XR Software Discovery Protocol Format String Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.8 (high)
  39. Rank 49Cisco ASA / Firepower (FTD)

    CVE-2025-20362

    Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Sep 25, 2025
    CISA deadline
    1 day
    CVSS severity
    8.6 (high)
  40. Rank 50Cisco ASA / Firepower (FTD)

    CVE-2024-20353

    Cisco ASA and FTD Denial of Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 24, 2024
    CISA deadline
    7 days
    CVSS severity
    8.6 (high)
  41. Rank 51Cisco IOS / IOS XE

    CVE-2018-0155

    CVE from 2018, added in 2022

    Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    8.6 (high)
  42. Rank 52Cisco IOS / IOS XE

    CVE-2018-0158

    CVE from 2018, added in 2022

    Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    8.6 (high)
  43. Rank 53Cisco IOS / IOS XE

    CVE-2018-0172

    CVE from 2018, added in 2022

    Cisco IOS and IOS XE Software Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    8.6 (high)
  44. Rank 54Cisco IOS / IOS XE

    CVE-2018-0173

    CVE from 2018, added in 2022

    Cisco IOS and IOS XE Software Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    8.6 (high)
  45. Rank 55Cisco IOS / IOS XE

    CVE-2018-0174

    CVE from 2018, added in 2022

    Cisco IOS Software and Cisco IOS XE Software Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    8.6 (high)
  46. Rank 56Cisco IOS XR

    CVE-2020-3566

    Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.6 (high)
  47. Rank 57Cisco IOS XR

    CVE-2020-3569

    Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    8.6 (high)
  48. Rank 58Cisco IOS / IOS XE / IOS XR

    CVE-2018-0175

    CVE from 2018, added in 2022

    Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    8.0 (high)
  49. Rank 59Cisco RV routers (Small Business)

    CVE-2022-20703

    Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    8.0 (high)
  50. Rank 60Cisco RV routers (Small Business)

    CVE-2022-20708

    Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    8.0 (high)
  51. Rank 61Cisco AnyConnect Secure Mobility Client

    CVE-2020-3433

    RansomwareCVE from 2020, added in 2022

    Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 24, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  52. Rank 62Cisco ASA / Firepower (FTD)

    CVE-2016-6367

    CVE from 2016, added in 2022

    Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 24, 2022
    CISA deadline
    21 days
    CVSS severity
    7.8 (high)
  53. Rank 63Cisco RV routers (Small Business)

    CVE-2022-20701

    Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    7.8 (high)
  54. Rank 64Cisco ASA / Firepower (FTD)

    CVE-2020-3259

    RansomwareCVE from 2020, added in 2024

    Cisco ASA and FTD Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Feb 15, 2024
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  55. Rank 65Cisco IOS / IOS XE / IOS XR

    CVE-2016-6415

    CVE from 2016, added in 2023

    Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 19, 2023
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  56. Rank 66Cisco IOS XR

    CVE-2010-3035

    CVE from 2010, added in 2022

    Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  57. Rank 67Cisco Prime Data Center Network Manager (DCNM)

    CVE-2015-0666

    CVE from 2015, added in 2022

    Cisco Prime Data Center Network Manager (DCNM) Directory Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  58. Rank 68Cisco IOS / IOS XE

    CVE-2017-12231

    CVE from 2017, added in 2022

    Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  59. Rank 69Cisco IOS / IOS XE

    CVE-2017-12233

    CVE from 2017, added in 2022

    Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  60. Rank 70Cisco IOS / IOS XE

    CVE-2017-12234

    CVE from 2017, added in 2022

    Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  61. Rank 71Cisco IOS / IOS XE

    CVE-2017-12235

    CVE from 2017, added in 2022

    Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  62. Rank 72Cisco IOS / IOS XE

    CVE-2017-12237

    CVE from 2017, added in 2022

    Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  63. Rank 73Cisco IOS / IOS XE

    CVE-2017-6627

    CVE from 2017, added in 2022

    Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    7.5 (high)
  64. Rank 74Cisco IOS / IOS XE

    CVE-2018-0154

    CVE from 2018, added in 2022

    Cisco IOS Software Integrated Services Module for VPN Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  65. Rank 75Cisco IOS / IOS XE

    CVE-2018-0156

    CVE from 2018, added in 2022

    Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  66. Rank 76Cisco IOS / IOS XE

    CVE-2018-0159

    CVE from 2018, added in 2022

    Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    7.5 (high)
  67. Rank 77Cisco ASA / Firepower (FTD)

    CVE-2018-0296

    CVE from 2018, added in 2021

    Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  68. Rank 78Cisco RV routers (Small Business)

    CVE-2019-1653

    CVE from 2019, added in 2021

    Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  69. Rank 79Cisco ASA / Firepower (FTD)

    CVE-2020-3452

    Cisco ASA and FTD Read-Only Path Traversal Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    7.5 (high)
  70. Rank 80Cisco RV routers (Small Business)

    CVE-2023-20118

    CVE from 2023, added in 2025

    Cisco Small Business RV Series Routers Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2025
    CISA deadline
    21 days
    CVSS severity
    7.2 (high)
  71. Rank 81Cisco IOS / IOS XE

    CVE-2023-20273

    Cisco IOS XE Web UI Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 23, 2023
    CISA deadline
    4 days
    CVSS severity
    7.2 (high)
  72. Rank 82Cisco RV routers (Small Business)

    CVE-2019-1652

    CVE from 2019, added in 2022

    Cisco Small Business Routers Improper Input Validation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    7.2 (high)
  73. Rank 83Cisco NX-OS

    CVE-2024-20399

    Cisco NX-OS Command Injection Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Jul 2, 2024
    CISA deadline
    21 days
    CVSS severity
    6.7 (medium)
  74. Rank 84Cisco IOS / IOS XE

    CVE-2023-20109

    Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 10, 2023
    CISA deadline
    21 days
    CVSS severity
    6.6 (medium)
  75. Rank 85Cisco AnyConnect Secure Mobility Client

    CVE-2020-3153

    RansomwareCVE from 2020, added in 2022

    Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 24, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  76. Rank 86Cisco IOS XR

    CVE-2022-20821

    Cisco IOS XR Open Port Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 23, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  77. Rank 87Cisco IOS / IOS XE

    CVE-2017-12232

    CVE from 2017, added in 2022

    Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  78. Rank 88Cisco IOS / IOS XE

    CVE-2017-12238

    CVE from 2017, added in 2022

    Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  79. Rank 89Cisco IOS / IOS XE

    CVE-2017-6663

    CVE from 2017, added in 2022

    Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    6.5 (medium)
  80. Rank 90Cisco IOS / IOS XE

    CVE-2018-0161

    CVE from 2018, added in 2022

    Cisco IOS Software Resource Management Errors Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    6.3 (medium)
  81. Rank 91Cisco ASA / Firepower (FTD)

    CVE-2014-2120

    CVE from 2014, added in 2024

    Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 12, 2024
    CISA deadline
    21 days
    CVSS severity
    6.1 (medium)
  82. Rank 92Cisco ASA / Firepower (FTD)

    CVE-2020-3580

    Ransomware

    Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Nov 3, 2021
    CISA deadline
    181 days
    CVSS severity
    6.1 (medium)
  83. Rank 93Cisco ASA / Firepower (FTD)

    CVE-2024-20359

    Cisco ASA and FTD Privilege Escalation Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Apr 24, 2024
    CISA deadline
    7 days
    CVSS severity
    6.0 (medium)
  84. Rank 94Cisco IOS / IOS XE

    CVE-2004-1464

    CVE from 2004, added in 2023

    Cisco IOS Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    May 19, 2023
    CISA deadline
    21 days
    CVSS severity
    5.9 (medium)
  85. Rank 95Cisco IOS XR

    CVE-2009-2055

    CVE from 2009, added in 2022

    Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 25, 2022
    CISA deadline
    21 days
    CVSS severity
    5.9 (medium)
  86. Rank 96Cisco IOS / IOS XE

    CVE-2017-12319

    CVE from 2017, added in 2022

    Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    21 days
    CVSS severity
    5.9 (medium)
  87. Rank 97Cisco IOS / IOS XE

    CVE-2018-0179

    CVE from 2018, added in 2022

    Cisco IOS Software Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    5.9 (medium)
  88. Rank 98Cisco IOS / IOS XE

    CVE-2018-0180

    CVE from 2018, added in 2022

    Cisco IOS Software Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Mar 3, 2022
    CISA deadline
    14 days
    CVSS severity
    5.9 (medium)
  89. Rank 99Cisco ASA / Firepower (FTD)

    CVE-2024-20481

    Cisco ASA and FTD Denial-of-Service Vulnerability

    Added more than a year ago: ranked by severity.

    Added
    Oct 24, 2024
    CISA deadline
    21 days
    CVSS severity
    5.8 (medium)

Follow and verify

Get new Cisco vulnerabilities: RSS feed (add it to Outlook, Teams, Slack or your feed reader).

Indicative classification, based on the vendor and product names given by CISA. How products are classified.