VulnSea

Cisco has 395 CVEs on record between 2017 and 2026. Disclosure cadence is accelerating: 122 in the last 90 days against 33 in the 90 before. The busiest recent month was September 2026 with 95. The median CVSS is 7.2 (high), with 50 rated critical. 4% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 189 days (13 cases). The dominant weakness classes are CWE-20 (34) and CWE-400 (30). Most affected products: secure_firewall_threat_defense (75), Cisco Identity Services Engine Software (41), enterprise_nfv_infrastructure_software (21).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
4% vs 1% corpus
Median CVSS
7.2
Publish → KEV
189 d median(13)
Last 90 days
122 prev 33

Products

  • secure_firewall_threat_defense 75
  • Cisco Identity Services Engine Software 41
  • enterprise_nfv_infrastructure_software 21
  • adaptive_security_appliance 18
  • Cisco TelePresence Endpoint Software (TC/CE) 17
  • Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 16
395
Total CVEs
50
Critical
13
CISA KEV
15
Exploited

cisco vulnerabilities

CVEs affecting cisco, newest first. Open any entry for full detail, references, and exploit status.

395 CVEsRSS

CVE-2026-20150High· 8.8
2mo ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresse…

▾ Twilightcisco · roomosEPSS 0.42%via NVD
CVE-2026-20191High· 7.5
2mo ago

A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container.  This vulnerability is due to insufficient validation of user-supplied input

A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container.  This vulnerability is due to insufficient validation of user-supplied input. An attack…

▾ Twilightcisco · catalyst_centerEPSS 0.65%via NVD
CVE-2026-20190High· 7.5
3mo ago

A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This vulnerability is due to improper authorization checks when a resource is accessed

A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This vulnerability is due to improper authorization checks when a resource is accessed. An a…

▾ Twilightcisco · identity_services_engineEPSS 0.50%via NVD
CVE-2026-20181Critical· 9.1
3mo ago

A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device

A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid ad…

▾ Midnightcisco · identity_services_engineEPSS 8.9%via NVD
CVE-2026-20223Critical· 10.0PoC
4mo ago

A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role. This vulnerability …

A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role. This vulnerability …

▾ Abyssalcisco · secure_workloadEPSS 0.83%via NVD
CVE-2026-20199Medium· 4.7
4mo ago

A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to execute commands on the underlying operating system as the root user. This vulnerability is due t…

A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to execute commands on the underlying operating system as the root user. This vulnerability is due t…

▾ Sunlitcisco · thousandeyes_virtual_applianceEPSS 0.44%via NVD
CVE-2026-20035High· 7.2
4mo ago

A vulnerability in the web UI of Cisco Unity Connection Web Inbox could allow an unauthenticated, remote attacker to conduct SSRF attacks through an affected device. This vulnerability is due to improper input validation for specific …

A vulnerability in the web UI of Cisco Unity Connection Web Inbox could allow an unauthenticated, remote attacker to conduct SSRF attacks through an affected device. This vulnerability is due to improper input validation for specific …

▾ Twilightcisco · unity_connectionEPSS 0.30%via NVD
CVE-2026-20034High· 8.8
4mo ago

A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to insufficient validation of use…

A vulnerability in the web-based management interface of Cisco Unity Connection could allow an authenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to insufficient validation of use…

▾ Twilightcisco · unity_connectionEPSS 0.71%via NVD
CVE-2026-20193Medium· 4.3
4mo ago

A vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an authenticated, remote attacker with read-only Administrator privileges to gain unauthorized access to sensitive information on an affected device. Thi…

A vulnerability in the RADIUS Policy API endpoints of Cisco ISE could allow an authenticated, remote attacker with read-only Administrator privileges to gain unauthorized access to sensitive information on an affected device. Thi…

▾ Sunlitcisco · identity_services_engineEPSS 0.22%via NVD
CVE-2026-20168Medium· 6.5
4mo ago

A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to retrieve files that they do not have permission to access. This vulnerabili…

A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to retrieve files that they do not have permission to access. This vulnerabili…

▾ Sunlitcisco · iot_field_network_directorEPSS 0.27%via NVD
CVE-2026-20167High· 7.7
4mo ago

A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to cause a DoS condition on a remotely managed router. This vulnerability is d…

A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to cause a DoS condition on a remotely managed router. This vulnerability is d…

▾ Twilightcisco · iot_field_network_directorEPSS 0.27%via NVD
CVE-2026-20189Medium· 4.3
4mo ago

A vulnerability in the log file download functionality of Cisco Prime Infrastructure could allow an authenticated, remote attacker to download arbitrary log files from the server. This vulnerability is due to insufficient authori…

A vulnerability in the log file download functionality of Cisco Prime Infrastructure could allow an authenticated, remote attacker to download arbitrary log files from the server. This vulnerability is due to insufficient authori…

▾ Sunlitcisco · prime_infrastructureEPSS 0.21%via NVD
CVE-2026-20169Medium· 6.4PoC
4mo ago

A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to access files and execute commands on a remote router. This vulnerability is…

A vulnerability in the web-based management interface of Cisco IoT Field Network Director could allow an authenticated, remote attacker with low privileges to access files and execute commands on a remote router. This vulnerability is…

▾ Twilightcisco · iot_field_network_directorEPSS 0.21%via NVD
CVE-2026-20195Medium· 5.3
4mo ago

A vulnerability in an identity management API endpoint of Cisco ISE could allow an unauthenticated, remote attacker to enumerate valid user accounts on an affected device. This vulnerability exists because error messages are observed …

A vulnerability in an identity management API endpoint of Cisco ISE could allow an unauthenticated, remote attacker to enumerate valid user accounts on an affected device. This vulnerability exists because error messages are observed …

▾ Sunlitcisco · identity_services_engineEPSS 0.27%via NVD
CVE-2026-20180Critical· 9.9PoC
5mo ago

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker mus…

▾ Abyssalcisco · identity_services_engineEPSS 6.0%via NVD
CVE-2026-20148Medium· 4.9
5mo ago

A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system and read arbitrary files

A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system and read arbitrary files. To exploit this vulnerability, the attacker must …

▾ Sunlitcisco · identity_services_engineEPSS 6.5%via NVD
CVE-2026-20147Critical· 9.9
5mo ago

A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device

A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have va…

▾ Midnightcisco · identity_services_engine_passive_identity_connectorEPSS 10%via NVD
CVE-2026-20136Medium· 6.0
5mo ago

A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, local attacker with administrative privileges to perform a command injection attack …

A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, local attacker with administrative privileges to perform a command injection attack …

▾ Sunlitcisco · identity_services_engineEPSS 0.50%via NVD
CVE-2026-20132Medium· 4.8
5mo ago

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative write privileges to conduct a stored cross-site scripting (XSS)…

Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative write privileges to conduct a stored cross-site scripting (XSS)…

▾ Sunlitcisco · identity_services_engineEPSS 0.17%via NVD
CVE-2026-20170Medium· 6.1
5mo ago

A vulnerability in the Desktop Agent functionality of Cisco Webex Contact Center could have allowed an unauthenticated, remote attacker to conduct cross-site scripting attacks

A vulnerability in the Desktop Agent functionality of Cisco Webex Contact Center could have allowed an unauthenticated, remote attacker to conduct cross-site scripting attacks. Cisco has addressed this vulnerability in the Cisco Webex Co…

▾ Sunlitcisco · webex_contact_centerEPSS 0.22%via NVD
CVE-2026-20186Critical· 9.9
5mo ago

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device

A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker mus…

▾ Midnightcisco · identity_services_engineEPSS 5.6%via NVD
CVE-2026-20097Medium· 6.5
5mo ago

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to execute arbitrary code as the root user. This vulnerability is due to improper validatio…

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to execute arbitrary code as the root user. This vulnerability is due to improper validatio…

▾ Sunlitcisco · unified_computing_systemEPSS 0.39%via NVD
CVE-2026-20096Medium· 6.5
5mo ago

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands a…

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands a…

▾ Sunlitcisco · enterprise_nfv_infrastructure_softwareEPSS 0.72%via NVD
CVE-2026-20095Medium· 6.5
5mo ago

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands a…

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with admin-level privileges to perform command injection attacks on an affected system and execute arbitrary commands a…

▾ Sunlitcisco · enterprise_nfv_infrastructure_softwareEPSS 0.93%via NVD
CVE-2026-20094High· 8.8
5mo ago

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command injection attacks on an affected system and execute arbitrary commands as the r…

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with read-only privileges to perform command injection attacks on an affected system and execute arbitrary commands as the r…

▾ Twilightcisco · unified_computing_systemEPSS 1.1%via NVD
CVE-2026-20090Medium· 4.8
5mo ago

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due …

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due …

▾ Sunlitcisco · enterprise_nfv_infrastructure_softwareEPSS 0.24%via NVD
CVE-2026-20089Medium· 4.8
5mo ago

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due …

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due …

▾ Sunlitcisco · enterprise_nfv_infrastructure_softwareEPSS 0.24%via NVD
CVE-2026-20088Medium· 4.8
5mo ago

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due …

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due …

▾ Sunlitcisco · enterprise_nfv_infrastructure_softwareEPSS 0.22%via NVD
CVE-2026-20087Medium· 4.8
5mo ago

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due …

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with administrative privileges to conduct a stored XSS attack against a user of the interface. This vulnerability is due …

▾ Sunlitcisco · enterprise_nfv_infrastructure_softwareEPSS 0.17%via NVD
CVE-2026-20085Medium· 6.1
5mo ago

A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. This vulnerability is due to insufficient validation…

A vulnerability in the web-based management interface of Cisco IMC could allow an unauthenticated, remote attacker to conduct a reflected XSS attack against a user of the interface. This vulnerability is due to insufficient validation…

▾ Sunlitcisco · enterprise_nfv_infrastructure_softwareEPSS 0.18%via NVD
cisco vulnerabilities (CVEs) — page 5 · VulnSea