VulnSea

cisco has 397 CVEs on record between 2017 and 2026. Disclosure cadence is accelerating: 122 in the last 90 days against 33 in the 90 before. The busiest recent month was September 2026 with 95. The median CVSS is 7.2 (high), with 50 rated critical. 4% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 189 days (13 cases). The dominant weakness classes are CWE-20 (34) and CWE-400 (30). Most affected products: secure_firewall_threat_defense (75), Cisco Identity Services Engine Software (41), enterprise_nfv_infrastructure_software (21).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
4% vs 1% corpus
Median CVSS
7.2
Publish → KEV
189 d median(13)
Last 90 days
122 prev 33

Products

  • secure_firewall_threat_defense 75
  • Cisco Identity Services Engine Software 41
  • enterprise_nfv_infrastructure_software 21
  • adaptive_security_appliance 18
  • Cisco TelePresence Endpoint Software (TC/CE) 17
  • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 16
397
Total CVEs
50
Critical
13
CISA KEV
15
Exploited

Cisco vulnerabilities

CVEs affecting Cisco, newest first. Open any entry for full detail, references, and exploit status.

397 CVEsRSS

CVE-2022-20783High· 7.5
4y ago

Cisco Telepresence CE and RoomOS Software Denial of Service Vulnerability

A vulnerability in the packet processing functionality of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an …

▾ TwilightCisco · Cisco TelePresence Endpoint Software (TC/CE)EPSS 1.4%via CSAF
CVE-2022-20622High· 8.6
4y ago

Cisco Aironet Access Points ICMP Denial of Service Vulnerability

A vulnerability in IP ingress packet processing of the Cisco Embedded Wireless Controller with Catalyst Access Points Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, causing a denial of …

▾ TwilightCisco · Cisco Aironet Access Point Software (IOS XE Controller)EPSS 1.4%via CSAF
CVE-2021-1529High· 7.8
4y ago

Cisco IOS XE SD-WAN Software Command Injection Vulnerability (CVE-2021-1529)

A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation by the system CLI. An …

▾ TwilightCisco · Cisco 4000 Series Integrated Services RoutersEPSS 0.31%via CSAF
CVE-2021-34758None
4y ago

Cisco TelePresence Collaboration Endpoint and RoomOS Software Denial of Service Vulnerability

It was previously published that a vulnerability in the memory management of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to corrupt a shared memory segment,…

▾ SunlitCisco · Cisco TelePresence Endpoint Software (TC/CE)EPSS 0.19%via CSAF
CVE-2021-34725Medium· 6.7
5y ago

Cisco IOS XE SD-WAN Command Injection Vulnerability

A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with root-level privileges on the underlying operating system. This vulnerability is due…

▾ SunlitCisco · Cisco 4000 Series Integrated Services RoutersEPSS 0.36%via CSAF
CVE-2021-1625Medium· 5.8
5y ago

Cisco IOS XE Software Zone Based Firewall ICMP and UDP Inspection Vulnerability

A vulnerability in the Zone-Based Policy Firewall feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to prevent the Zone-Based Policy Firewall from correctly classifying traffic. This vulnerability exists b…

▾ SunlitCisco · Cisco IOS XE SoftwareEPSS 0.91%via CSAF
CVE-2021-1619Critical· 9.8
5y ago

Cisco IOS XE Software NETCONF/RESTCONF AAA Vulnerability

A vulnerability in the authentication, authorization, and accounting (AAA) function of Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass NETCONF or RESTCONF authentication and do either of the following: In…

▾ MidnightCisco · Cisco IOS XE SoftwareEPSS 1.8%via CSAF
CVE-2021-34727Critical· 9.8
5y ago

Cisco IOS XE SD-WAN Software Buffer Overflow Vulnerability (CVE-2021-34727)

A vulnerability in the vDaemon process in Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. This vulnerability is due to insufficient bounds checking when an a…

▾ MidnightCisco · Cisco 4000 Series Integrated Services RoutersEPSS 2.6%via CSAF
CVE-2021-1612Medium· 5.5
5y ago

Cisco IOS XE SD-WAN Arbitrary File Overwrite Vulnerability

A vulnerability in the Cisco IOS XE SD-WAN Software CLI could allow an authenticated, local attacker to overwrite arbitrary files on the local system. This vulnerability is due to improper access controls on files within the local file …

▾ SunlitCisco · Cisco 4000 Series Integrated Services RoutersEPSS 0.25%via CSAF
CVE-2021-34740High· 7.4
5y ago

Cisco Aironet Access Points WLAN Control Protocol Packet Buffer Leak Denial of Service Vulnerability (CVE-2021-34740)

A vulnerability in the WLAN Control Protocol (WCP) implementation for Cisco Aironet Access Point (AP) software could allow an unauthenticated, adjacent attacker to cause a reload of an affected device, resulting in a denial of service (DoS…

▾ TwilightCisco · Cisco Aironet Access Point SoftwareEPSS 0.36%via CSAF
CVE-2021-1419High· 7.8
5y ago

Cisco Aironet Access Points Privilege Escalation Vulnerability

A vulnerability in the SSH management feature of multiple Cisco Access Points (APs) platforms could allow a local, authenticated user to modify files on the affected device and possibly gain escalated privileges. The vulnerability is du…

▾ TwilightCisco · Cisco 5500 Series Wireless ControllersEPSS 0.22%via CSAF
CVE-2021-1532Medium· 6.5
5y ago

Cisco Telepresence CE and RoomOS Software Arbitrary File Read Vulnerability

A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, remote attacker to read arbitrary files from the underlying operating syste…

▾ SunlitCisco · Cisco TelePresence Endpoint Software (TC/CE)EPSS 1.4%via CSAF
CVE-2021-1448High· 7.8
5y ago

A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges on the underlying operating system of an affected device that is …

A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges on the underlying operating system of an affected device that is …

▾ Twilightcisco · secure_firewall_threat_defenseEPSS 0.30%via NVD
CVE-2021-1445High· 8.6
5y ago

Multiple vulnerabilities in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device

Multiple vulnerabilities in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. …

▾ Twilightcisco · secure_firewall_threat_defenseEPSS 1.7%via NVD
CVE-2021-1402High· 8.6
5y ago

A vulnerability in the software-based SSL/TLS message handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (D…

A vulnerability in the software-based SSL/TLS message handler of Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial of service (D…

▾ Twilightcisco · secure_firewall_threat_defenseEPSS 1.4%via NVD
CVE-2021-1256Medium· 6.0
5y ago

A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite files on the file system of an affected device by using directory traversal techniques

A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to overwrite files on the file system of an affected device by using directory traversal techniques. A successful ex…

▾ Sunlitcisco · secure_firewall_threat_defenseEPSS 0.50%via NVD
CVE-2021-1371Medium· 6.6
5y ago

Cisco SD-WAN Software Improper Privilege Management Vulnerability

A vulnerability in the role-based access control of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker with read-only privileges to obtain administrative privileges by using the console port when the device is in the…

▾ SunlitCisco · Cisco IOS XE SoftwareEPSS 0.25%via CSAF
CVE-2021-1449Medium· 6.7
5y ago

Cisco Aironet Access Points Privilege Escalation Vulnerability

A vulnerability in the boot logic of Cisco Access Points Software could allow an authenticated, local attacker to execute unsigned code at boot time. The vulnerability is due to an improper check that is performed by the area of code th…

▾ SunlitCisco · Cisco Aironet Access Point SoftwareEPSS 0.27%via CSAF
CVE-2021-1437High· 7.5
5y ago

Cisco Aironet Access Points FlexConnect Upgrade Information Disclosure Vulnerability (CVE-2021-1437)

A vulnerability in the FlexConnect Upgrade feature of Cisco Aironet Series Access Points Software could allow an unauthenticated, remote attacker to obtain confidential information from an affected device. This vulnerability is due to a…

▾ TwilightCisco · Cisco Aironet Access Point Software (IOS XE Controller)EPSS 1.5%via CSAF
CVE-2021-1273High· 7.5
5y ago

Cisco SD-WAN Denial of Service Vulnerabilties

Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details […

▾ TwilightCisco · Cisco SD-WAN vContainerEPSS 1.4%via CSAF
CVE-2021-1279Medium· 5.3
5y ago

Cisco SD-WAN Denial of Service Vulnerabilties

Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details […

▾ SunlitCisco · Cisco Catalyst SD-WAN ManagerEPSS 1.4%via CSAF
CVE-2021-1278Medium· 5.5
5y ago

Cisco SD-WAN Denial of Service Vulnerabilties

Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details […

▾ SunlitCisco · Cisco 4000 Series Integrated Services RoutersEPSS 1.7%via CSAF
CVE-2021-1274High· 7.5
5y ago

Cisco SD-WAN Denial of Service Vulnerabilties

Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details […

▾ TwilightCisco · Cisco 4000 Series Integrated Services RoutersEPSS 1.9%via CSAF
CVE-2021-1241High· 8.6
5y ago

Cisco SD-WAN vEdge Routers Denial of Service Vulnerability

Multiple vulnerabilities in Cisco SD-WAN products could allow an unauthenticated, remote attacker to execute denial of service (DoS) attacks against an affected device. For more information about these vulnerabilities, see the Details […

▾ TwilightCisco · Cisco SD-WAN vEdge CloudEPSS 1.4%via CSAF
CVE-2021-1236Medium· 5.3
5y ago

Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system

Multiple Cisco products are affected by a vulnerability in the Snort application detection engine that could allow an unauthenticated, remote attacker to bypass the configured policies on an affected system. The vulnerability is due to a…

▾ Sunlitcisco · secure_firewall_management_centerEPSS 2.1%via NVD
CVE-2021-1224Medium· 5.8
5y ago

Multiple Cisco products are affected by a vulnerability with TCP Fast Open (TFO) when used in conjunction with the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP

Multiple Cisco products are affected by a vulnerability with TCP Fast Open (TFO) when used in conjunction with the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. T…

▾ Sunlitcisco · secure_firewall_management_centerEPSS 2.0%via NVD
CVE-2021-1223High· 7.5
5y ago

Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP

Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticated, remote attacker to bypass a configured file policy for HTTP. The vulnerability is due to incorrect handling of an …

▾ Twilightcisco · secure_firewall_management_centerEPSS 2.0%via NVD
CVE-2020-26068Medium· 5.5
5y ago

Cisco Telepresence CE Software and RoomOS Software Unauthorized Configuration Change Vulnerability

A vulnerability in the xAPI service of Cisco Telepresence CE Software and Cisco RoomOS Software could allow an authenticated, remote attacker to generate an access token for an affected device. The vulnerability is due to insufficient a…

▾ SunlitCisco · Cisco TelePresence Endpoint Software (TC/CE)EPSS 0.73%via CSAF
CVE-2020-26086Medium· 4.3
5y ago

Cisco TelePresence Collaboration Endpoint Software Information Disclosure Vulnerability (CVE-2020-26086)

A vulnerability in the video endpoint API (xAPI) of Cisco TelePresence Collaboration Endpoint (CE) Software could allow an authenticated, remote attacker to gain access to sensitive information on an affected device. The vulnerability i…

▾ SunlitCisco · Cisco TelePresence Endpoint Software (TC/CE)EPSS 0.85%via CSAF
CVE-2020-3585Medium· 5.3
5y ago

A vulnerability in the TLS handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000 Series firewalls could allow an unauthenticated, remote attacker to gain ac…

A vulnerability in the TLS handler of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000 Series firewalls could allow an unauthenticated, remote attacker to gain ac…

▾ Sunlitcisco · secure_firewall_threat_defenseEPSS 1.3%via NVD
Cisco vulnerabilities (CVEs) — page 9 · VulnSea