VulnSea

Cisco has 397 CVEs on record between 2017 and 2026. Disclosure cadence is accelerating: 122 in the last 90 days against 33 in the 90 before. The busiest recent month was September 2026 with 95. The median CVSS is 7.2 (high), with 50 rated critical. 4% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 189 days (13 cases). The dominant weakness classes are CWE-20 (34) and CWE-400 (30). Most affected products: secure_firewall_threat_defense (75), Cisco Identity Services Engine Software (41), enterprise_nfv_infrastructure_software (21).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
4% vs 1% corpus
Median CVSS
7.2
Publish → KEV
189 d median(13)
Last 90 days
122 prev 33

Products

  • secure_firewall_threat_defense 75
  • Cisco Identity Services Engine Software 41
  • enterprise_nfv_infrastructure_software 21
  • adaptive_security_appliance 18
  • Cisco TelePresence Endpoint Software (TC/CE) 17
  • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 16
397
Total CVEs
50
Critical
13
CISA KEV
15
Exploited

Cisco vulnerabilities

CVEs affecting Cisco, newest first. Open any entry for full detail, references, and exploit status.

397 CVEsRSS

CVE-2026-20277High· 8.2
3w ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases tha…

▾ TwilightCisco · Cisco IOS XR SoftwareEPSS 0.23%via NVD
CVE-2026-20278High· 8.8
3w ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases tha…

▾ TwilightCisco · Cisco IOS XR SoftwareEPSS 0.30%via NVD
CVE-2026-20275High· 8.8
3w ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases tha…

▾ TwilightCisco · Cisco IOS XR SoftwareEPSS 0.20%via NVD
CVE-2026-20355Medium· 5.9
3w ago

Cisco Secure Email S/MIME Ciphertext Decryption Vulnerabilty

Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. …

▾ SunlitCisco · Cisco Secure EmailEPSS 0.16%via CVEORG
CVE-2026-20354Medium· 5.9
3w ago

Cisco Secure Email S/MIME Ciphertext Decryption Vulnerabilty

Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. Th…

▾ SunlitCisco · Cisco Secure EmailEPSS 0.16%via CSAF
CVE-2026-20319High· 7.5
1mo ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that…

▾ TwilightCisco · Cisco Secure WorkloadEPSS 0.47%via NVD
CVE-2026-20318Critical· 9.6
1mo ago

Cisco Secure Workload Software Security Hardening Release August 2026 - Input Validation Vulnerabilities

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that ad…

▾ MidnightCisco · Cisco Secure WorkloadEPSS 0.44%via CSAF
CVE-2026-20317Critical· 10.0
1mo ago

Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Authentication Vulnerabilities

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that ad…

▾ MidnightCisco · Cisco Secure WorkloadEPSS 0.56%via CSAF
CVE-2026-20315Critical· 10.0
1mo ago

Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Access Control Vulnerabilities

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that ad…

▾ MidnightCisco · Cisco Secure WorkloadEPSS 0.49%via CSAF
CVE-2026-20231Critical· 9.9
1mo ago

Cisco Secure Workload Software Security Hardening Release August 2026 - Improper Neutralization of Special Elements Vulnerabilities

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that ad…

▾ MidnightCisco · Cisco Secure WorkloadEPSS 0.53%via CSAF
CVE-2026-20349High· 8.6CISA KEV0dayPoC
1mo ago

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause th…

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause th…

▾ Abyssalcisco · adaptive_security_appliance_softwareEPSS 1.0%via NVD
CVE-2026-20124High· 7.7
1mo ago

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. …

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. …

▾ Twilightcisco · ios_xeEPSS 0.50%via NVD
CVE-2026-20301High· 8.6
1mo ago

A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of se…

A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of se…

▾ Twilightcisco · iosEPSS 0.57%via NVD
CVE-2026-20200High· 8.8PoC
1mo ago

Cisco Integrated Management Controller Argument Injection and Remote Code Execution Vulnerability

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with low privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privi…

▾ MidnightCisco · Cisco Unified Computing System (Standalone)EPSS 0.73%via CVEORG
CVE-2026-20288Medium· 6.5
1mo ago

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with Admin privileges to execute arbitrary commands on the underlying operating system of an affected system and elevat…

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with Admin privileges to execute arbitrary commands on the underlying operating system of an affected system and elevat…

▾ Sunlitcisco · unified_computing_systemEPSS 0.64%via NVD
CVE-2026-20308Medium· 4.3
1mo ago

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device. This vulnerabilit…

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device. This vulnerabilit…

▾ SunlitCisco · Cisco IOS XE SoftwareEPSS 0.32%via NVD
CVE-2026-20273High· 8.6
1mo ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that…

▾ TwilightCisco · Cisco IOS XE SoftwareEPSS 0.47%via NVD
CVE-2026-20272Critical· 9.8
1mo ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that …

▾ Midnightcisco · ios_xeEPSS 0.57%via NVD
CVE-2026-20271High· 8.6
1mo ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that …

▾ Twilightcisco · ios_xeEPSS 0.47%via NVD
CVE-2026-20270High· 8.6
1mo ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that …

▾ Twilightcisco · ios_xeEPSS 0.47%via NVD
CVE-2026-20269High· 8.6
1mo ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that …

▾ Twilightcisco · ios_xeEPSS 0.47%via NVD
CVE-2026-20268High· 8.6
1mo ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that …

▾ Twilightcisco · ios_xeEPSS 0.47%via NVD
CVE-2026-20267Critical· 9.0
1mo ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that …

▾ Midnightcisco · ios_xeEPSS 0.38%via NVD
CVE-2026-20316Medium· 5.3CISA KEV0dayPoC
2mo ago

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within…

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within…

▾ Midnightcisco · secure_firewall_management_centerEPSS 35%via NVD
CVE-2026-20146Medium· 5.5
2mo ago

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read …

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read …

▾ Sunlitcisco · identity_services_engine_passive_identity_connectorEPSS 0.50%via NVD
CVE-2026-20187High· 7.5
2mo ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresse…

▾ Twilightcisco · roomosEPSS 0.47%via NVD
CVE-2026-20158High· 7.5
2mo ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresse…

▾ Twilightcisco · roomosEPSS 0.47%via NVD
CVE-2026-20157High· 7.5
2mo ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresse…

▾ Twilightcisco · roomosEPSS 0.19%via NVD
CVE-2026-20156High· 8.1
2mo ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresse…

▾ Twilightcisco · roomosEPSS 0.46%via NVD
CVE-2026-20153High· 7.5
2mo ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresse…

▾ Twilightcisco · roomosEPSS 0.47%via NVD
Cisco vulnerabilities (CVEs) — page 4 · VulnSea