Cisco known exploited vulnerabilities
CISA lists 99 Cisco CVEs as exploited in the wild. 19 were added in the last 12 months (latest 2026-09-16), and 7 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2021-1498 (HyperFlex HX): EPSS 100.0%, added 2021-11-03
- CVE-2020-3452 (Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)): EPSS 100.0%, added 2021-11-03
- CVE-2021-1497 (HyperFlex HX): EPSS 99.9%, added 2021-11-03
- CVE-2018-0296 (Adaptive Security Appliance (ASA)): EPSS 99.9%, added 2021-11-03
- CVE-2019-1653 (Small Business RV320 and RV325 Routers): EPSS 99.9%, added 2021-11-03
Most affected Cisco products
IOS and IOS XE Software (14), Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) (6), IOS XR (6), IOS software (6), Small Business RV160, RV260, RV340, and RV345 Series Routers (5), Catalyst SD-WAN Manager (4), IOS and IOS XE (4), Adaptive Security Appliance (ASA) (4), IOS Software (4), Identity Services Engine (3), IOS Software and Cisco IOS XE Software (3), Secure Firewall Management Center (FMC) (2).
All Cisco CVEs in KEV (latest 60)
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2026-76460 | Identity Services Engine | Identity Services Engine Incorrect Use of Privileged APIs | 2026-09-16 | 2026-09-19 | 14.0% | – |
| CVE-2026-76461 | Secure Email Gateway | Secure Email Gateway SQL Injection | 2026-09-14 | 2026-09-17 | 28.3% | – |
| CVE-2026-20079 | Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management | Firewall Management Center Authentication Bypass Using an Alternate Path or Channel | 2026-09-09 | 2026-09-12 | 88.2% | – |
| CVE-2026-20349 | Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) | Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection | 2026-08-11 | 2026-08-14 | 1.0% | – |
| CVE-2026-20316 | Secure Firewall Management Center (FMC) | Secure Firewall Management Center Use of Hard-coded Password | 2026-07-29 | 2026-08-01 | 35.1% | Yes |
| CVE-2008-4128 | IOS | IOS Cross-Site Request Forgery | 2026-07-13 | 2026-07-16 | 33.9% | – |
| CVE-2026-20230 | Unified Communications Manager | Unified Communications Manager Server-Side Request Forgery (SSRF) | 2026-06-25 | 2026-06-28 | 88.2% | – |
| CVE-2026-20262 | Catalyst SD-WAN Manager | Catalyst SD-WAN Manager Directory or Path Traversal | 2026-06-15 | 2026-06-29 | 28.2% | – |
| CVE-2026-20245 | Catalyst SD-WAN Manager | Catalyst SD-WAN Manager Improper Encoding or Escaping of Output | 2026-06-09 | 2026-06-23 | 25.3% | – |
| CVE-2026-20182 | Catalyst SD-WAN | Catalyst SD-WAN Controller Authentication Bypass | 2026-05-14 | 2026-05-17 | 91.5% | – |
| CVE-2026-20133 | Catalyst SD-WAN Manager | Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor | 2026-04-20 | 2026-04-23 | 31.8% | – |
| CVE-2026-20128 | Catalyst SD-WAN Manager | Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format | 2026-04-20 | 2026-04-23 | 7.1% | – |
| CVE-2026-20122 | Catalyst SD-WAN Manger | Catalyst SD-WAN Manager Incorrect Use of Privileged APIs | 2026-04-20 | 2026-04-23 | 25.0% | – |
| CVE-2026-20131 | Secure Firewall Management Center (FMC) | Secure Firewall Management Center (FMC) Software and Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data | 2026-03-19 | 2026-03-22 | 42.7% | Yes |
| CVE-2026-20127 | Catalyst SD-WAN Controller and Manager | Catalyst SD-WAN Controller and Manager Authentication Bypass | 2026-02-25 | 2026-02-27 | 88.5% | – |
| CVE-2022-20775 | SD-WAN | SD-WAN Path Traversal | 2026-02-25 | 2026-02-27 | 12.5% | – |
| CVE-2026-20045 | Unified Communications Manager | Unified Communications Products Code Injection | 2026-01-21 | 2026-02-11 | 4.5% | – |
| CVE-2025-20393 | Multiple Products | Multiple Products Improper Input Validation | 2025-12-17 | 2025-12-24 | 32.4% | – |
| CVE-2025-20352 | IOS and IOS XE | IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution | 2025-09-29 | 2025-10-20 | 39.4% | – |
| CVE-2025-20362 | Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense | Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization | 2025-09-25 | 2025-09-26 | 87.1% | – |
| CVE-2025-20333 | Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense | Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow | 2025-09-25 | 2025-09-26 | 70.7% | – |
| CVE-2025-20337 | Identity Services Engine | Identity Services Engine Injection | 2025-07-28 | 2025-08-18 | 67.8% | – |
| CVE-2025-20281 | Identity Services Engine | Identity Services Engine Injection | 2025-07-28 | 2025-08-18 | 97.6% | – |
| CVE-2024-20439 | Smart Licensing Utility | Smart Licensing Utility Static Credential | 2025-03-31 | 2025-04-21 | 97.1% | – |
| CVE-2023-20118 | Small Business RV Series Routers | Small Business RV Series Routers Command Injection | 2025-03-03 | 2025-03-24 | 54.1% | – |
| CVE-2014-2120 | Adaptive Security Appliance (ASA) | Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) | 2024-11-12 | 2024-12-03 | 18.8% | – |
| CVE-2024-20481 | Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | ASA and FTD Denial-of-Service | 2024-10-24 | 2024-11-14 | 15.8% | – |
| CVE-2024-20399 | NX-OS | NX-OS Command Injection | 2024-07-02 | 2024-07-23 | 4.3% | – |
| CVE-2024-20359 | Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | ASA and FTD Privilege Escalation | 2024-04-24 | 2024-05-01 | 19.4% | – |
| CVE-2024-20353 | Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | ASA and FTD Denial of Service | 2024-04-24 | 2024-05-01 | 70.7% | – |
| CVE-2020-3259 | Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | ASA and FTD Information Disclosure | 2024-02-15 | 2024-03-07 | 71.8% | Yes |
| CVE-2023-20273 | Cisco IOS XE Web UI | IOS XE Web UI Command Injection | 2023-10-23 | 2023-10-27 | 89.6% | – |
| CVE-2023-20198 | IOS XE Web UI | IOS XE Web UI Privilege Escalation | 2023-10-16 | 2023-10-20 | 99.6% | – |
| CVE-2023-20109 | IOS and IOS XE | IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write | 2023-10-10 | 2023-10-31 | 2.3% | – |
| CVE-2023-20269 | Adaptive Security Appliance and Firepower Threat Defense | Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access | 2023-09-13 | 2023-10-04 | 25.5% | Yes |
| CVE-2016-6415 | IOS, IOS XR, and IOS XE | IOS, IOS XR, and IOS XE IKEv1 Information Disclosure | 2023-05-19 | 2023-06-09 | 87.7% | – |
| CVE-2004-1464 | IOS | IOS Denial-of-Service | 2023-05-19 | 2023-06-09 | 4.8% | – |
| CVE-2017-6742 | IOS and IOS XE Software | IOS and IOS XE Software SNMP Remote Code Execution | 2023-04-19 | 2023-05-10 | 21.4% | – |
| CVE-2020-3433 | AnyConnect Secure | AnyConnect Secure Mobility Client for Windows DLL Hijacking | 2022-10-24 | 2022-11-14 | 10.0% | Yes |
| CVE-2020-3153 | AnyConnect Secure | AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path | 2022-10-24 | 2022-11-14 | 28.3% | Yes |
| CVE-2019-15271 | RV Series Routers | RV Series Routers Deserialization of Untrusted Data | 2022-06-08 | 2022-06-22 | 5.5% | – |
| CVE-2016-6367 | Adaptive Security Appliance (ASA) | Adaptive Security Appliance (ASA) CLI Remote Code Execution | 2022-05-24 | 2022-06-14 | 22.6% | – |
| CVE-2016-6366 | Adaptive Security Appliance (ASA) | Adaptive Security Appliance (ASA) SNMP Buffer Overflow | 2022-05-24 | 2022-06-14 | 87.6% | – |
| CVE-2022-20821 | IOS XR | IOS XR Open Port | 2022-05-23 | 2022-06-13 | 11.5% | – |
| CVE-2018-0147 | Secure Access Control System (ACS) | Secure Access Control System Java Deserialization | 2022-03-25 | 2022-04-15 | 18.2% | – |
| CVE-2018-0125 | VPN Routers | VPN Routers Remote Code Execution | 2022-03-25 | 2022-04-15 | 55.2% | – |
| CVE-2017-3881 | IOS and IOS XE | IOS and IOS XE Remote Code Execution | 2022-03-25 | 2022-04-15 | 99.0% | – |
| CVE-2015-0666 | Prime Data Center Network Manager (DCNM) | Prime Data Center Network Manager (DCNM) Directory Traversal | 2022-03-25 | 2022-04-15 | 40.4% | – |
| CVE-2010-3035 | IOS XR | IOS XR Border Gateway Protocol (BGP) Denial-of-Service | 2022-03-25 | 2022-04-15 | 5.7% | – |
| CVE-2009-2055 | IOS XR | IOS XR Border Gateway Protocol (BGP) Denial-of-Service | 2022-03-25 | 2022-04-15 | 3.3% | – |
| CVE-2022-20708 | Small Business RV160, RV260, RV340, and RV345 Series Routers | Small Business RV Series Routers Stack-based Buffer Overflow | 2022-03-03 | 2022-03-17 | 14.9% | – |
| CVE-2022-20703 | Small Business RV160, RV260, RV340, and RV345 Series Routers | Small Business RV Series Routers Stack-based Buffer Overflow | 2022-03-03 | 2022-03-17 | 9.2% | – |
| CVE-2022-20701 | Small Business RV160, RV260, RV340, and RV345 Series Routers | Small Business RV Series Routers Stack-based Buffer Overflow | 2022-03-03 | 2022-03-17 | 9.7% | – |
| CVE-2022-20700 | Small Business RV160, RV260, RV340, and RV345 Series Routers | Small Business RV Series Routers Stack-based Buffer Overflow | 2022-03-03 | 2022-03-17 | 5.7% | – |
| CVE-2022-20699 | Small Business RV160, RV260, RV340, and RV345 Series Routers | Small Business RV Series Routers Stack-based Buffer Overflow | 2022-03-03 | 2022-03-17 | 72.5% | – |
| CVE-2019-1652 | Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers | Small Business Routers Improper Input Validation | 2022-03-03 | 2022-03-17 | 95.9% | – |
| CVE-2018-0180 | IOS Software | IOS Software Denial-of-Service | 2022-03-03 | 2022-03-17 | 4.9% | – |
| CVE-2018-0179 | IOS Software | IOS Software Denial-of-Service | 2022-03-03 | 2022-03-17 | 4.9% | – |
| CVE-2018-0175 | IOS, XR, and XE Software | IOS, XR, and XE Software Buffer Overflow | 2022-03-03 | 2022-03-17 | 3.5% | – |
| CVE-2018-0174 | IOS XE Software | IOS Software and IOS XE Software Improper Input Validation | 2022-03-03 | 2022-03-17 | 7.6% | – |
Read next: Which CVEs to patch first this week · All vendors