cisco has 397 CVEs on record between 2017 and 2026. Disclosure cadence is accelerating: 122 in the last 90 days against 33 in the 90 before. The busiest recent month was September 2026 with 95. The median CVSS is 7.2 (high), with 50 rated critical. 4% have been exploited in the wild, in line with the corpus average. The median gap from publication to a KEV listing is 189 days (13 cases). The dominant weakness classes are CWE-20 (34) and CWE-400 (30). Most affected products: secure_firewall_threat_defense (75), Cisco Identity Services Engine Software (41), enterprise_nfv_infrastructure_software (21).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 4% vs 1% corpus
- Median CVSS
- 7.2
- Publish → KEV
- 189 d median(13)
- Last 90 days
- 122 prev 33
Weakness classes
Products
- secure_firewall_threat_defense 75
- Cisco Identity Services Engine Software 41
- enterprise_nfv_infrastructure_software 21
- adaptive_security_appliance 18
- Cisco TelePresence Endpoint Software (TC/CE) 17
- Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 16
Worst active — by depth score
CVE-2026-20079Critical· 10.0A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access …98CVE-2020-3452High· 7.5A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks an…86CVE-2020-3259High· 7.5A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to retrieve memory contents on an affecte…86CVE-2018-0296High· 7.5A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition86CVE-2026-76461Critical· 9.8A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This …85
cisco vulnerabilities
CVEs affecting cisco, newest first. Open any entry for full detail, references, and exploit status.
397 CVEsRSS
CVE-2024-20265Medium· 5.9Cisco Access Point Software Secure Boot Bypass Vulnerability (CVE-2024-20265)
A vulnerability in the boot process of Cisco Access Point (AP) Software could allow an unauthenticated, physical attacker to bypass the Cisco Secure Boot functionality and load a software image that has been tampered with on an affected de…
CVE-2024-20267High· 8.6Cisco NX-OS Software MPLS IPv6 Denial of Serice Vulnerability
A vulnerability with the handling of MPLS traffic for Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause the netstack process to unexpectedly restart, which could cause the device to stop processing network traff…
CVE-2023-20268Medium· 4.7Cisco Access Point Software Uncontrolled Resource Consumption Vulnerability (CVE-2023-20268)
A vulnerability in the packet processing functionality of Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to exhaust resources on an affected device. This vulnerability is due to insufficient managemen…
CVE-2023-20176Medium· 5.8Cisco Aironet Access Points Denial of Service
A vulnerability in the networking component of Cisco access point (AP) software could allow an unauthenticated, remote attacker to cause a temporary disruption of service. This vulnerability is due to overuse of AP resources. An attacke…
CVE-2023-20033High· 8.6Cisco IOS XE Software for Catalyst 3650 and Catalyst 3850 Switches Denial of Service Vulnerability
A vulnerability in Cisco IOS XE Software for Cisco Catalyst 3650 and Catalyst 3850 Series Switches could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) c…
CVE-2023-20193Medium· 6.0A vulnerability in the Embedded Service Router (ESR) of Cisco ISE could allow an authenticated, local attacker to read, write, or delete arbitrary files on the underlying operating system and escalate their privileges to root
A vulnerability in the Embedded Service Router (ESR) of Cisco ISE could allow an authenticated, local attacker to read, write, or delete arbitrary files on the underlying operating system and escalate their privileges to root. To exploit…
CVE-2023-20269Medium· 5.0CISA KEVA vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an …
A vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an …
CVE-2023-20094Medium· 4.3Cisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS could allow an attacker to elevate privileges, overwrite arbitrary files, or view sensitive data on an affected device. For more information abo…
CVE-2023-20093Medium· 4.4Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Overwrite Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS could allow an attacker to elevate privileges, overwrite arbitrary files, or view sensitive data on an affected device. For more information abo…
CVE-2023-20092Medium· 4.4Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Overwrite Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS could allow an attacker to elevate privileges, overwrite arbitrary files, or view sensitive data on an affected device. For more information abo…
CVE-2023-20091Medium· 5.1Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Overwrite Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS could allow an attacker to elevate privileges, overwrite arbitrary files, or view sensitive data on an affected device. For more information abo…
CVE-2023-20090Medium· 6.7Cisco TelePresence Collaboration Endpoint and RoomOS Software Privilege Escalation Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS could allow an attacker to elevate privileges, overwrite arbitrary files, or view sensitive data on an affected device. For more information abo…
CVE-2023-20004Medium· 4.4Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Write Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) and Cisco RoomOS could allow an attacker to elevate privileges, overwrite arbitrary files, or view sensitive data on an affected device. For more information abo…
CVE-2023-20035High· 7.8Cisco IOS XE SD-WAN Software Command Injection Vulnerability (CVE-2023-20035)
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges. This vulnerability is due to insufficient input validation by the system CLI…
CVE-2023-20056Medium· 6.5Cisco Access Point Software Denial of Service
A vulnerability in the management CLI of Cisco access point (AP) software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input v…
CVE-2023-20112High· 7.4Cisco Access Point Software Association Request Denial of Service Vulnerability (CVE-2023-20112)
A vulnerability in Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of certain pa…
CVE-2023-20097Medium· 4.6Cisco Access Points (AP) Command Injection Vulnerability
A vulnerability in Cisco access points (AP) software could allow an authenticated, local attacker to inject arbitrary commands and execute them with root privileges. This vulnerability is due to improper input validation of commands tha…
CVE-2023-20002Medium· 4.4Cisco TelePresence CE and RoomOS Software Server-Side Request Forgery Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to conduct server-side request forgery (SSRF) attacks through an affected device or …
CVE-2023-20008Medium· 4.4Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Write Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an authenticated, local attacker to conduct server-side request forgery (SSRF) attacks through an affected device or …
CVE-2022-20955Medium· 4.4Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Write Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. …
CVE-2022-20954Medium· 4.4Cisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Write Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. …
CVE-2022-20953Medium· 5.0Cisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. …
CVE-2022-20811Medium· 5.5Cisco TelePresence Collaboration Endpoint and RoomOS Software Path Traversal Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. …
CVE-2022-20776Medium· 5.1Cisco TelePresence Collaboration Endpoint and RoomOS Software Path Traversal Vulnerability
Multiple vulnerabilities in Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an attacker to conduct path traversal attacks, view sensitive data, or write arbitrary files on an affected device. …
CVE-2022-20931Medium· 6.5Cisco Touch 10 Device Downgrade Attack Vulnerability
A vulnerability in the version control of Cisco TelePresence CE Software for Cisco Touch 10 Devices could allow an unauthenticated, adjacent attacker to install an older version of the software on an affected device. This vulnerability …
CVE-2022-20793Medium· 6.8Cisco Touch 10 Device Insufficient Identity Verification Vulnerability
A vulnerability in pairing process of Cisco TelePresence CE Software and RoomOS Software for Cisco Touch 10 Devices could allow an unauthenticated, remote attacker to impersonate a legitimate device and pair with an affected device. Thi…
CVE-2022-20728Medium· 4.7Cisco Aironet Access Points VLAN bypass from Native VLAN Vulnerability
A vulnerability in the client forwarding code of multiple Cisco Access Points (APs) could allow an unauthenticated, adjacent attacker to inject packets from the native VLAN to clients within nonnative VLANs on an affected device. This v…
CVE-2022-20768Medium· 4.9Cisco TelePresence Collaboration Endpoint and RoomOS Software Information Disclosure Vulnerability (CVE-2022-20768)
A vulnerability in the logging component of Cisco TelePresence Collaboration Endpoint (CE) and RoomOS Software could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnera…
CVE-2022-20794Medium· 4.7vuln-CVE-2022-20794
Multiple vulnerabilities in the web engine of Cisco Telepresence CE Software and RoomOS Software could allow a remote attacker to cause a denial of service (DoS) condition, redirect users to an attacker controlled destination or view sensi…
CVE-2022-20764Medium· 6.5Cisco RoomsOS Denial of Service Vulnerability
Multiple vulnerabilities in the web engine of Cisco Telepresence CE Software and RoomOS Software could allow a remote attacker to cause a denial of service (DoS) condition, redirect users to an attacker controlled destination or view sensi…