VulnSea

Cisco has 397 CVEs on record between 2017 and 2026. Disclosure cadence is accelerating: 122 in the last 90 days against 33 in the 90 before. The busiest recent month was September 2026 with 95. The median CVSS is 7.2 (high), with 50 rated critical. 4% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 189 days (13 cases). The dominant weakness classes are CWE-20 (34) and CWE-400 (30). Most affected products: secure_firewall_threat_defense (75), Cisco Identity Services Engine Software (41), enterprise_nfv_infrastructure_software (21).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
4% vs 1% corpus
Median CVSS
7.2
Publish → KEV
189 d median(13)
Last 90 days
122 prev 33

Products

  • secure_firewall_threat_defense 75
  • Cisco Identity Services Engine Software 41
  • enterprise_nfv_infrastructure_software 21
  • adaptive_security_appliance 18
  • Cisco TelePresence Endpoint Software (TC/CE) 17
  • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 16
397
Total CVEs
50
Critical
13
CISA KEV
15
Exploited

Cisco vulnerabilities

CVEs affecting Cisco, newest first. Open any entry for full detail, references, and exploit status.

397 CVEsRSS

CVE-2026-20151High· 7.3
5mo ago

A vulnerability in the web interface of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges on an affected system. This vulnerability is due to the improper transmissi…

A vulnerability in the web interface of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to elevate privileges on an affected system. This vulnerability is due to the improper transmissi…

▾ Twilightcisco · smart_software_manager_on-premEPSS 0.27%via NVD
CVE-2026-20042Medium· 6.5
5mo ago

A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encryption password and access to Full or Config-only backup files to access sensitive information. This vulnerability ex…

A vulnerability in the configuration backup feature of Cisco Nexus Dashboard could allow an attacker who has the encryption password and access to Full or Config-only backup files to access sensitive information. This vulnerability ex…

▾ Sunlitcisco · nexus_dashboardEPSS 0.29%via NVD
CVE-2026-20155High· 8.0
5mo ago

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker with low privileges to access sensitive information that they are not authorized to …

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker with low privileges to access sensitive information that they are not authorized to …

▾ Twilightcisco · evolved_programmable_network_managerEPSS 0.27%via NVD
CVE-2026-20174Medium· 4.9
5mo ago

A vulnerability in the Metadata update feature of Cisco Nexus Dashboard Insights could allow an authenticated, remote attacker to write arbitrary files to an affected system. This vulnerability is due to insufficient validation of the…

A vulnerability in the Metadata update feature of Cisco Nexus Dashboard Insights could allow an authenticated, remote attacker to write arbitrary files to an affected system. This vulnerability is due to insufficient validation of the…

▾ Sunlitcisco · nexus_dashboard_insightsEPSS 0.49%via NVD
CVE-2026-20160Critical· 9.8
5mo ago

A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host. This vulnerability…

A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected SSM On-Prem host. This vulnerability…

▾ Midnightcisco · smart_software_manager_on-premEPSS 0.91%via NVD
CVE-2026-20012High· 8.6
6mo ago

A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, and Cisco Secure Firewall Threat Defense (FTD) Softwar…

A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, and Cisco Secure Firewall Threat Defense (FTD) Softwar…

▾ Twilightcisco · secure_firewall_threat_defenseEPSS 0.35%via NVD
CVE-2026-20112Medium· 4.8
6mo ago

A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user o…

A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user o…

▾ SunlitCisco · Cisco IOS XE SoftwareEPSS 0.19%via NVD
CVE-2026-20108Medium· 5.4
6mo ago

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. …

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. …

▾ Sunlitcisco · catalyst_sd-wan_managerEPSS 0.16%via NVD
CVE-2026-20117Medium· 6.1
6mo ago

A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. …

A vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. …

▾ Sunlitcisco · unified_contact_center_expressEPSS 0.21%via NVD
CVE-2026-20074High· 7.4
6mo ago

A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) multi-instance routing feature of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the IS-IS process to restart unexpectedly. Th…

A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) multi-instance routing feature of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the IS-IS process to restart unexpectedly. Th…

▾ Twilightcisco · ios_xrEPSS 0.16%via NVD
CVE-2026-20046High· 8.8
6mo ago

A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges and gain full administrative control of an affected device. This vulnerabi…

A vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authenticated, local attacker to elevate privileges and gain full administrative control of an affected device. This vulnerabi…

▾ Twilightcisco · ios_xrEPSS 0.14%via NVD
CVE-2026-20040High· 8.8
6mo ago

A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient…

A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnerability is due to insufficient…

▾ Twilightcisco · ios_xrEPSS 0.17%via NVD
CVE-2026-20044Medium· 6.0
6mo ago

A vulnerability in the lockdown mechanism of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, local attacker to perform arbitrary commands as root. This vulnerability is due to insufficient restrict…

A vulnerability in the lockdown mechanism of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, local attacker to perform arbitrary commands as root. This vulnerability is due to insufficient restrict…

▾ Sunlitcisco · secure_firewall_management_centerEPSS 0.14%via NVD
CVE-2026-20005Medium· 5.8
6mo ago

Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspect…

Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspect…

▾ Sunlitcisco · cyber_visionEPSS 0.49%via NVD
CVE-2026-20067Medium· 5.8
6mo ago

Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspect…

Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspect…

▾ Sunlitcisco · snortEPSS 0.45%via NVD
CVE-2026-20066Medium· 5.8
6mo ago

Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspect…

Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspect…

▾ Sunlitcisco · snortEPSS 0.45%via NVD
CVE-2026-20065Medium· 5.8
6mo ago

Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspect…

Multiple Cisco products are affected by a vulnerability in the Snort 3 Detection Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspect…

▾ Sunlitcisco · snortEPSS 0.37%via NVD
CVE-2026-20058Medium· 5.8
6mo ago

Multiple Cisco products are affected by vulnerabilities in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. These vulnerabilities are due to improper error ch…

Multiple Cisco products are affected by vulnerabilities in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. These vulnerabilities are due to improper error ch…

▾ Sunlitcisco · snortEPSS 0.39%via NVD
CVE-2026-20057Medium· 5.8
6mo ago

Multiple Cisco products are affected by a vulnerability in the Snort 3 Visual Basic for Applications (VBA) feature which could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash.    This …

Multiple Cisco products are affected by a vulnerability in the Snort 3 Visual Basic for Applications (VBA) feature which could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash.    This …

▾ Sunlitcisco · snortEPSS 0.43%via NVD
CVE-2026-20054Medium· 5.8
6mo ago

Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash.  This vulnerability is due to improper error …

Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash.  This vulnerability is due to improper error …

▾ Sunlitcisco · snortEPSS 0.43%via NVD
CVE-2026-20053Medium· 5.8
6mo ago

Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. This vulnerability is due to improper range checki…

Multiple Cisco products are affected by a vulnerability in the Snort 3 VBA feature that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to crash. This vulnerability is due to improper range checki…

▾ Sunlitcisco · snortEPSS 0.41%via NVD
CVE-2026-20052Medium· 5.8
6mo ago

A vulnerability in the memory management handling for the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart. …

A vulnerability in the memory management handling for the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart. …

▾ Sunlitcisco · secure_firewall_threat_defenseEPSS 0.41%via NVD
CVE-2026-20007Medium· 5.8
6mo ago

A vulnerability in the Snort 2 and Snort 3 deep packet inspection of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured Snort rules and allow traffic onto the network …

A vulnerability in the Snort 2 and Snort 3 deep packet inspection of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured Snort rules and allow traffic onto the network …

▾ Sunlitcisco · secure_firewall_threat_defenseEPSS 0.23%via NVD
CVE-2026-20006Medium· 5.8
6mo ago

A vulnerability in the TLS cryptography functionality of the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to unexpec…

A vulnerability in the TLS cryptography functionality of the Snort 3 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to unexpec…

▾ Sunlitcisco · secure_firewall_threat_defenseEPSS 0.37%via NVD
CVE-2026-20068Medium· 5.8
6mo ago

Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspect…

Multiple Cisco products are affected by a vulnerability in the Snort 3 detection engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to restart, resulting in an interruption of packet inspect…

▾ Sunlitcisco · snortEPSS 0.41%via NVD
CVE-2026-20003Medium· 4.9
6mo ago

A vulnerability in the REST API of Cisco Secure FMC Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to inadequate validation of user-supplied inp…

A vulnerability in the REST API of Cisco Secure FMC Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to inadequate validation of user-supplied inp…

▾ Sunlitcisco · secure_firewall_management_centerEPSS 0.28%via NVD
CVE-2026-20002High· 8.1
6mo ago

A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to inadequate validatio…

A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. This vulnerability is due to inadequate validatio…

▾ Twilightcisco · secure_firewall_management_centerEPSS 0.35%via NVD
CVE-2026-20079Critical· 10.0CISA KEVPoC
6mo ago

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access …

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access …

▾ Hadalcisco · secure_firewall_management_centerEPSS 88%via NVD
CVE-2026-20119High· 7.5
7mo ago

Cisco TelePresence Collaboration Endpoint Software and RoomOS Software Denial of Service Vulnerability (CVE-2026-20119)

A vulnerability in the text rendering subsystem of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affecte…

▾ TwilightCisco · Cisco RoomOS SoftwareEPSS 0.38%via CSAF
CVE-2026-20123Medium· 4.3
7mo ago

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This…

A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This…

▾ Sunlitcisco · evolved_programmable_network_managerEPSS 0.19%via NVD
Cisco vulnerabilities (CVEs) — page 6 · VulnSea