| Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability CVE-2026-76504 | Severity critical Exploited yes |
| Cisco Secure Email Gateway SQL Injection Vulnerability CVE-2026-76461 | Severity critical Exploited yes |
| Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability CVE-2026-76460 | Severity critical Exploited yes |
| A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated… CVE-2026-76451 | Severity medium |
| A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated… CVE-2026-76450 | Severity medium |
| A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated… CVE-2026-76449 | Severity medium |
| A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated… CVE-2026-76448 | Severity medium |
| A vulnerability in the Online Certificate Status Protocol (OCSP) responder of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated… CVE-2026-76447 | Severity medium |
| A vulnerability in an API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to read specific files on the… CVE-2026-76446 | Severity medium |
| A vulnerability in an internal service of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to retrieve sensitive… CVE-2026-76444 | Severity medium |
| A vulnerability in the endpoint posture status reporting functionality of the guest portal web application of Cisco ISE could allow an… CVE-2026-76439 | Severity medium |
| A vulnerability in the certificate import functionality of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an… CVE-2026-76434 | Severity medium |
| A vulnerability in the client provisioning download feature of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker… CVE-2026-76433 | Severity medium |
| A vulnerability in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker with… CVE-2026-76432 | Severity medium |
| A vulnerability in the file management function of the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an… CVE-2026-76431 | Severity medium |
| A vulnerability in the REST APIs of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection… CVE-2026-76428 | Severity medium |
| A vulnerability in the offline profiler feed service of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files… CVE-2026-76427 | Severity medium |
| A vulnerability in the REST API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to conduct SQL injection… CVE-2026-76426 | Severity medium |
| A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks against the backend… CVE-2026-76425 | Severity high |
| A vulnerability in the REST API of Cisco ISE could allow an authenticated, remote attacker to upload or copy arbitrary files on an affected… CVE-2026-76424 | Severity high |
| Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability CVE-2026-20349 | Severity high Exploited yes |
| Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability CVE-2026-20316 | Severity medium Exploited yes |
| A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software… CVE-2026-20301 | Severity high |
| A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with Admin privileges… CVE-2026-20288 | Severity medium |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has… CVE-2026-20280 | Severity high |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a… CVE-2026-20276 | Severity high |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a… CVE-2026-20274 | Severity critical |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a… CVE-2026-20273 | Severity high |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a… CVE-2026-20272 | Severity critical |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a… CVE-2026-20271 | Severity high |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a… CVE-2026-20270 | Severity high |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a… CVE-2026-20269 | Severity high |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a… CVE-2026-20268 | Severity high |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a… CVE-2026-20267 | Severity critical |
| A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauthenticated, remote… CVE-2026-20263 | Severity high |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE… CVE-2026-20234 | Severity critical |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE… CVE-2026-20192 | Severity critical |
| A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted… CVE-2026-20191 | Severity high |
| A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected… CVE-2026-20190 | Severity high |
| A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying… CVE-2026-20181 | Severity critical |
| A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to perform path traversal attacks on the… CVE-2026-20148 | Severity medium |
| A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the… CVE-2026-20147 | Severity critical |
| A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated… CVE-2026-20146 | Severity medium |
| A vulnerability in the CLI of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an… CVE-2026-20136 | Severity medium |
| As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE… CVE-2026-20130 | Severity critical |
| A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote… CVE-2026-20124 | Severity high |
| A vulnerability in the bootloader of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches, Cisco Catalyst ESS9300 Embedded Series… CVE-2026-20104 | Severity medium |
| A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause BOOTP… CVE-2026-20084 | Severity high |
| Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability CVE-2026-20079 | Severity critical Exploited yes |
| A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cisco Secure Firewall… CVE-2026-20012 | Severity high |
| A vulnerability in the TLS library of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to exhaust the available… CVE-2026-20004 | Severity high |
| Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated, remote attacker to… CVE-2025-20359 | Severity critical |
| Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability CVE-2025-20352 | Severity high Exploited yes |
| A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker with administrative privileges to execute… CVE-2025-20338 | Severity medium |
| A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (Unified CM… CVE-2025-20330 | Severity medium |
| A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to cause a denial of… CVE-2025-20327 | Severity high |
| A vulnerability in the Network-Based Application Recognition (NBAR) feature of Cisco IOS XE Software could allow an unauthenticated, remote… CVE-2025-20315 | Severity high |
| Multiple vulnerabilities in Cisco IOS XE Software of could allow an authenticated, local attacker with level-15 privileges or an… CVE-2025-20313 | Severity medium |
| A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote… CVE-2025-20312 | Severity high |
| A vulnerability in the handling of certain Ethernet frames in Cisco IOS XE Software for Catalyst 9000 Series Switches could allow an… CVE-2025-20311 | Severity high |
| A vulnerability in the web-based management interface of Cisco UCS Manager Software could allow an authenticated, remote attacker to… CVE-2025-20296 | |
| A vulnerability in the installation process of Cisco IOS XR Software could allow an authenticated, local attacker to bypass Cisco IOS XR… CVE-2025-20248 | Severity medium |
| A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software… CVE-2025-20224 | Severity medium |
| A vulnerability in the Internet Key Exchange version 1 (IKEv1) implementation of Cisco IOS XE Software could allow an authenticated, remote… CVE-2025-20192 | Severity high |
| A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allow an… CVE-2025-20160 | Severity high |
| A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to cause an… CVE-2025-20149 | Severity medium |
| A vulnerability in the GUI of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker with administrative… CVE-2025-20131 | Severity medium |
| A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to conduct an XSS attack… CVE-2024-20479 | Severity medium |
| A vulnerability in the Embedded Service Router (ESR) of Cisco ISE could allow an authenticated, local attacker to read, write, or delete… CVE-2023-20193 | Severity medium |
| Cisco IOS Cross-Site Request Forgery Vulnerability CVE-2008-4128 | Severity high Exploited yes |
| CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to bypass LDAP authentication on the server if the LDAP server allows… CVE-2000-1056 | |
| Cisco Secure PIX Firewall 5.2(2) allows remote attackers to determine the real IP address of a target FTP server by flooding the server… CVE-2000-1027 | |
| The HTTP server in Cisco IOS 12.0 through 12.1 allows local users to cause a denial of service (crash and reload) via a URL containing a… CVE-2000-0984 | |
| Cisco Virtual Central Office 4000 (VCO/4K) uses weak encryption to store usernames and passwords in the SNMP MIB, which allows an attacker… CVE-2000-0955 | |
| The web configuration interface for Catalyst 3500 XL switches allows remote attackers to execute arbitrary commands without authentication… CVE-2000-0945 | |