LIVE · cybersecurity feed
Live wire
vendor6 exploited in the wild

Cisco

41 CVEs published in the last four months and 12 stories. Exploited flaws first.

Critical5
High33
Medium3
Exploited (KEV)6

Patch these first

CVECVSSSeverityProductSummaryPublished
CVE-2026-20182exploited10criticalcatalyst sd-wan managerMay 2026: This security advisory provides the details and fix information for a vulnerability that was discovered 114d ago
CVE-2026-20230exploited8.6highunified communications managerA vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Sess94d ago
CVE-2026-20349exploited8.6highadaptive security appliance softwareA vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) S25d ago
CVE-2026-20245exploited7.8highcatalyst sd-wan managerA vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Mana93d ago
CVE-2026-20262exploited6.5mediumcatalyst sd-wan managerA vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authentica82d ago
CVE-2026-20316exploited5.3mediumsecure firewall management centerA vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unau38d ago

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-2022310criticalsecure workloadA vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauth108d ago
CVE-2026-20182exploited10criticalcatalyst sd-wan managerMay 2026: This security advisory provides the details and fix information for a vulnerability that was discovered 114d ago
CVE-2026-202729.8criticalios xeAs part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software enginee31d ago
CVE-2026-201819.1criticalidentity services engineA vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary comman80d ago
CVE-2026-202679criticalios xeAs part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software enginee31d ago
CVE-2026-200468.8highios xrA vulnerability in task group assignment for a specific CLI command in Cisco IOS XR Software could allow an authen178d ago
CVE-2026-200408.8highios xrA vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitr178d ago
CVE-2026-201508.8highroomosAs part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team52d ago
CVE-2026-202008.8highunified computing systemA vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker w31d ago
CVE-2026-763898.8hightalos intelligence for enterprise security cloudIn Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, a user that holds a role with the 17d ago
CVE-2026-202248.6highcatalyst sd-wan managerA vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenti114d ago
CVE-2026-20230exploited8.6highunified communications managerA vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Sess94d ago
CVE-2026-202738.6highios xeAs part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software enginee31d ago
CVE-2026-202718.6highios xeAs part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software enginee31d ago
CVE-2026-202708.6highios xeAs part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software enginee31d ago
CVE-2026-202698.6highios xeAs part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software enginee31d ago
CVE-2026-202688.6highios xeAs part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software enginee31d ago
CVE-2026-20349exploited8.6highadaptive security appliance softwareA vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) S25d ago
CVE-2026-201568.1highroomosAs part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team52d ago
CVE-2026-20245exploited7.8highcatalyst sd-wan managerA vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Mana93d ago
CVE-2026-202147.5highsecure endpointA vulnerability in the FSG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a66d ago
CVE-2026-202137.5highsecure endpointA vulnerability in the PE file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a 66d ago
CVE-2026-203487.5highsecure endpointA vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a29d ago
CVE-2026-201537.5highroomosAs part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team52d ago
CVE-2026-202447.5highsecure endpointA vulnerability in the DMG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a66d ago
CVE-2026-201577.5highroomosAs part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team52d ago
CVE-2026-201587.5highroomosAs part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team52d ago
CVE-2026-201877.5highroomosAs part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team52d ago
CVE-2026-202167.5highsecure endpointA vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker 66d ago
CVE-2026-202157.5highsecure endpointA vulnerability in the 7z file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a 66d ago
CVE-2026-202437.5highsecure endpointA vulnerability in the ALZ file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a66d ago
CVE-2026-201907.5highidentity services engineA vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive informa80d ago
CVE-2026-202177.5highsecure endpointA vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to caus66d ago
CVE-2026-200747.4highios xrA vulnerability in the Intermediate System-to-Intermediate System (IS-IS) multi-instance routing feature of Cisco 178d ago
CVE-2026-246977.2highrv130 firmwareAn OS command injection vulnerability exists in the start_bonjour() function of the "rc" binary in Cisco RV130/RV159d ago
CVE-2026-246987.2highrv130 firmwareAn OS command injection vulnerability exists in the save_syslog_to_file() function of the "httpd" binary in Cisco 59d ago
CVE-2026-246997.2highrv130 firmwareAn OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco RV130/RV130W 59d ago
CVE-2026-247007.2highrv130 firmwareAn OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisco RV130/RV130W59d ago
CVE-2026-20262exploited6.5mediumcatalyst sd-wan managerA vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authentica82d ago
CVE-2026-201176.1mediumunified contact center expressA vulnerability in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could 178d ago
CVE-2026-20316exploited5.3mediumsecure firewall management centerA vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unau38d ago

Filter the full tracker by Cisco

Our coverage of Cisco

vulnerabilitycritical

Cisco searched for IOS XR bugs and found so many it rolled them into an update release

Three critical vulns demand your attention, one a make-me-root mess in Nexus 9000 Series Switches that you can mitigate, not fix

vulnerabilitycritical

Six Maximum-Severity Flaws Found in Cisco Products

Cisco patched nine critical flaws, including six rated CVSS 10.0, found during internal testing. None are known to be exploited. Cisco released another batch of security fixes for its Crosswork platforms and Secure Workload software, part of what it’s calling an ongoing internal security review, and the CVSS scores in this round are unusually severe. […]

ciscocritical

Cisco Patches Nine Flaws in Crosswork and Secure Workload Software

Cisco has released security updates addressing nine vulnerabilities affecting its Crosswork platforms and Secure Workload Software. Five of these flaws have received a critical CVSS score of 10.0. The vulnerabilities impact Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, irrespective of device configuration.

vulnerability

Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5.

Secure Workload Software has five nasty flaws and even SaaS users have updates to install

vulnerabilitycritical

Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities

The flaws could lead to remote code execution, authentication bypasses, and path traversal attacks. The post Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities appeared first on SecurityWeek.

CVE-2026-20349

U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-20349 is a vulnerability in Cisco Secure Firewall ASA and FTD software

CVE-2026-20349critical

U.S. CISA adds Metabase, Windows, and Cisco Secure Firewall flaws to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to patch them by specific deadlines. The vulnerabilities affect Cisco Secure Firewall, Microsoft Windows, and Metabase, with the Metabase flaw being a critical SQL injection that was actively exploited.

CVE-2026-20349high

Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)

A high-severity vulnerability (CVE-2026-20349) is being leveraged by attackers to temporarily interrupt the operation of Cisco firewalls, the company has confirmed. The flaw has been added to CISA’s Known Exploited Vulnerabilities catalog and needs to be remediated by US civilian federal agencies by August 14, 2026. Details about the attacks are currently under wraps. Cisco only shared that its Pr

CVE-2026-20148

Cisco Identity Services Engine Vulnerability Discloses Sensitive Information

A directory traversal vulnerability in Cisco Identity Services Engine allows authenticated remote attackers to access sensitive information. The vulnerability, assigned CVE-2026-20148, has a CVSS score of 4.9, indicating a medium severity.

CVE-2026-20190high

Cisco Identity Services Engine Leaks Information Due to Missing Authentication

A critical vulnerability has been discovered in Cisco Identity Services Engine, allowing unauthenticated remote attackers to access sensitive information. The flaw stems from a missing authentication check for a critical function within the software. This could lead to significant data exposure on affected systems.

CVE-2026-20147high

Cisco Identity Services Engine Vulnerable to Command Injection

A critical vulnerability has been discovered in Cisco Identity Services Engine that permits remote attackers to execute arbitrary code. Exploitation requires prior authentication. The vulnerability has been assigned a CVSS score of 7.2.

CVE-2026-20181high

Cisco Identity Services Engine Vulnerable to RCE via Directory Traversal

A directory traversal vulnerability in Cisco Identity Services Engine could allow authenticated remote attackers to execute arbitrary code on affected systems. The vulnerability has a CVSS score of 7.2, indicating a significant security risk.