CyberMax
Home › Exploited CVEs

Cisco known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 99 Cisco CVEs as exploited in the wild. 19 were added in the last 12 months (latest 2026-09-16), and 7 are known to be used in ransomware campaigns.

Cisco CVEs added to CISA KEV per year
2021: 112021112022: 502022502023: 7202372024: 6202462025: 8202582026: 17202617

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected Cisco products

IOS and IOS XE Software (14), Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) (6), IOS XR (6), IOS software (6), Small Business RV160, RV260, RV340, and RV345 Series Routers (5), Catalyst SD-WAN Manager (4), IOS and IOS XE (4), Adaptive Security Appliance (ASA) (4), IOS Software (4), Identity Services Engine (3), IOS Software and Cisco IOS XE Software (3), Secure Firewall Management Center (FMC) (2).

All Cisco CVEs in KEV (latest 60)

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2026-76460Identity Services EngineIdentity Services Engine Incorrect Use of Privileged APIs2026-09-162026-09-1914.0%–
CVE-2026-76461Secure Email GatewaySecure Email Gateway SQL Injection2026-09-142026-09-1728.3%–
CVE-2026-20079Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementFirewall Management Center Authentication Bypass Using an Alternate Path or Channel2026-09-092026-09-1288.2%–
CVE-2026-20349Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection2026-08-112026-08-141.0%–
CVE-2026-20316Secure Firewall Management Center (FMC)Secure Firewall Management Center Use of Hard-coded Password2026-07-292026-08-0135.1%Yes
CVE-2008-4128IOSIOS Cross-Site Request Forgery2026-07-132026-07-1633.9%–
CVE-2026-20230Unified Communications ManagerUnified Communications Manager Server-Side Request Forgery (SSRF)2026-06-252026-06-2888.2%–
CVE-2026-20262Catalyst SD-WAN ManagerCatalyst SD-WAN Manager Directory or Path Traversal2026-06-152026-06-2928.2%–
CVE-2026-20245Catalyst SD-WAN ManagerCatalyst SD-WAN Manager Improper Encoding or Escaping of Output2026-06-092026-06-2325.3%–
CVE-2026-20182Catalyst SD-WANCatalyst SD-WAN Controller Authentication Bypass2026-05-142026-05-1791.5%–
CVE-2026-20133Catalyst SD-WAN ManagerCatalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor2026-04-202026-04-2331.8%–
CVE-2026-20128Catalyst SD-WAN ManagerCatalyst SD-WAN Manager Storing Passwords in a Recoverable Format2026-04-202026-04-237.1%–
CVE-2026-20122Catalyst SD-WAN MangerCatalyst SD-WAN Manager Incorrect Use of Privileged APIs2026-04-202026-04-2325.0%–
CVE-2026-20131Secure Firewall Management Center (FMC)Secure Firewall Management Center (FMC) Software and Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data2026-03-192026-03-2242.7%Yes
CVE-2026-20127Catalyst SD-WAN Controller and ManagerCatalyst SD-WAN Controller and Manager Authentication Bypass2026-02-252026-02-2788.5%–
CVE-2022-20775SD-WANSD-WAN Path Traversal2026-02-252026-02-2712.5%–
CVE-2026-20045Unified Communications ManagerUnified Communications Products Code Injection2026-01-212026-02-114.5%–
CVE-2025-20393Multiple ProductsMultiple Products Improper Input Validation2025-12-172025-12-2432.4%–
CVE-2025-20352IOS and IOS XEIOS and IOS XE Software SNMP Denial of Service and Remote Code Execution2025-09-292025-10-2039.4%–
CVE-2025-20362Secure Firewall Adaptive Security Appliance and Secure Firewall Threat DefenseSecure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization2025-09-252025-09-2687.1%–
CVE-2025-20333Secure Firewall Adaptive Security Appliance and Secure Firewall Threat DefenseSecure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow2025-09-252025-09-2670.7%–
CVE-2025-20337Identity Services EngineIdentity Services Engine Injection2025-07-282025-08-1867.8%–
CVE-2025-20281Identity Services EngineIdentity Services Engine Injection2025-07-282025-08-1897.6%–
CVE-2024-20439Smart Licensing UtilitySmart Licensing Utility Static Credential2025-03-312025-04-2197.1%–
CVE-2023-20118Small Business RV Series RoutersSmall Business RV Series Routers Command Injection2025-03-032025-03-2454.1%–
CVE-2014-2120Adaptive Security Appliance (ASA)Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS)2024-11-122024-12-0318.8%–
CVE-2024-20481Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)ASA and FTD Denial-of-Service2024-10-242024-11-1415.8%–
CVE-2024-20399NX-OSNX-OS Command Injection2024-07-022024-07-234.3%–
CVE-2024-20359Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)ASA and FTD Privilege Escalation2024-04-242024-05-0119.4%–
CVE-2024-20353Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)ASA and FTD Denial of Service2024-04-242024-05-0170.7%–
CVE-2020-3259Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)ASA and FTD Information Disclosure2024-02-152024-03-0771.8%Yes
CVE-2023-20273Cisco IOS XE Web UIIOS XE Web UI Command Injection2023-10-232023-10-2789.6%–
CVE-2023-20198IOS XE Web UIIOS XE Web UI Privilege Escalation2023-10-162023-10-2099.6%–
CVE-2023-20109IOS and IOS XEIOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write2023-10-102023-10-312.3%–
CVE-2023-20269Adaptive Security Appliance and Firepower Threat DefenseAdaptive Security Appliance and Firepower Threat Defense Unauthorized Access2023-09-132023-10-0425.5%Yes
CVE-2016-6415IOS, IOS XR, and IOS XEIOS, IOS XR, and IOS XE IKEv1 Information Disclosure2023-05-192023-06-0987.7%–
CVE-2004-1464IOSIOS Denial-of-Service2023-05-192023-06-094.8%–
CVE-2017-6742IOS and IOS XE SoftwareIOS and IOS XE Software SNMP Remote Code Execution2023-04-192023-05-1021.4%–
CVE-2020-3433AnyConnect SecureAnyConnect Secure Mobility Client for Windows DLL Hijacking2022-10-242022-11-1410.0%Yes
CVE-2020-3153AnyConnect SecureAnyConnect Secure Mobility Client for Windows Uncontrolled Search Path2022-10-242022-11-1428.3%Yes
CVE-2019-15271RV Series RoutersRV Series Routers Deserialization of Untrusted Data2022-06-082022-06-225.5%–
CVE-2016-6367Adaptive Security Appliance (ASA)Adaptive Security Appliance (ASA) CLI Remote Code Execution2022-05-242022-06-1422.6%–
CVE-2016-6366Adaptive Security Appliance (ASA)Adaptive Security Appliance (ASA) SNMP Buffer Overflow2022-05-242022-06-1487.6%–
CVE-2022-20821IOS XRIOS XR Open Port2022-05-232022-06-1311.5%–
CVE-2018-0147Secure Access Control System (ACS)Secure Access Control System Java Deserialization2022-03-252022-04-1518.2%–
CVE-2018-0125VPN RoutersVPN Routers Remote Code Execution2022-03-252022-04-1555.2%–
CVE-2017-3881IOS and IOS XEIOS and IOS XE Remote Code Execution2022-03-252022-04-1599.0%–
CVE-2015-0666Prime Data Center Network Manager (DCNM)Prime Data Center Network Manager (DCNM) Directory Traversal2022-03-252022-04-1540.4%–
CVE-2010-3035IOS XRIOS XR Border Gateway Protocol (BGP) Denial-of-Service2022-03-252022-04-155.7%–
CVE-2009-2055IOS XRIOS XR Border Gateway Protocol (BGP) Denial-of-Service2022-03-252022-04-153.3%–
CVE-2022-20708Small Business RV160, RV260, RV340, and RV345 Series RoutersSmall Business RV Series Routers Stack-based Buffer Overflow2022-03-032022-03-1714.9%–
CVE-2022-20703Small Business RV160, RV260, RV340, and RV345 Series RoutersSmall Business RV Series Routers Stack-based Buffer Overflow2022-03-032022-03-179.2%–
CVE-2022-20701Small Business RV160, RV260, RV340, and RV345 Series RoutersSmall Business RV Series Routers Stack-based Buffer Overflow2022-03-032022-03-179.7%–
CVE-2022-20700Small Business RV160, RV260, RV340, and RV345 Series RoutersSmall Business RV Series Routers Stack-based Buffer Overflow2022-03-032022-03-175.7%–
CVE-2022-20699Small Business RV160, RV260, RV340, and RV345 Series RoutersSmall Business RV Series Routers Stack-based Buffer Overflow2022-03-032022-03-1772.5%–
CVE-2019-1652Small Business RV320 and RV325 Dual Gigabit WAN VPN RoutersSmall Business Routers Improper Input Validation2022-03-032022-03-1795.9%–
CVE-2018-0180IOS SoftwareIOS Software Denial-of-Service2022-03-032022-03-174.9%–
CVE-2018-0179IOS SoftwareIOS Software Denial-of-Service2022-03-032022-03-174.9%–
CVE-2018-0175IOS, XR, and XE SoftwareIOS, XR, and XE Software Buffer Overflow2022-03-032022-03-173.5%–
CVE-2018-0174IOS XE SoftwareIOS Software and IOS XE Software Improper Input Validation2022-03-032022-03-177.6%–
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors