Skip to content
VulniPulse

Cisco Security Advisories & CVEs

193 advisories tracked · Cisco Security Advisories · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Cisco CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your Cisco device is affected

Pick your device's OS (and platform, where it matters), choose the software release it runs, and we'll check it against Cisco's recent security advisories — the same data behind the Cisco Software Checker.

Official source

Cisco Security Advisories

Polled via the official Cisco PSIRT RSS feed. Advisory pages are fetched for new items to extract fixed software and workarounds.

Latest Cisco advisories

Critical9.8Cisco Exploited CISA KEV Updated

Critical [CVE-2026-76504] Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability

An unauthenticated remote attacker could exploit a flaw in the API session-based authentication management of Cisco Catalyst SD-WAN Manager to access an affected system with privileges of the admin user. The flaw is caused by improper handling of URI encoding in an HTTP request, which allows the request to bypass an authentication rule that is intended to restrict access to a specific API endpoint. Cisco has released a Live Protect shield for CVE-2026-76504 to provide temporary security coverage to allow time for software upgrade planning, including preserving any information that customers may require for governance or compliance purposes.

CVE-2026-76504
SD-WANCatalyst SD-WAN
Sep 30, 2026
UnratedCisco Updated

Advisory Cisco Advance Notification for Publication of October 7, 2026, Security Advisories

On October 7, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products: Application Policy Infrastructure Controller (security hardening release) Finesse License On-Prem, formerly Cisco Smart Software Manager On-Prem (security hardening release) NX-OS Software for MDS 9000, Nexus 3000, 7000, and 9000 Series Switches, Nexus 9000 in ACI mode, and UCS Fabric Interconnects (security hardening release)

Nexus 3000
Sep 30, 2026
Critical9.9Cisco

Critical [CVE-2026-20324] Cisco Secure Firewall Management Center Software sftunnel Root Arbitrary Code Execution Vulnerability

A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands as root. This vulnerability exists because a registered sftunnel peer has incorrect permissions to write an arbitrary file to any location on the device. An attacker could exploit this vulnerability by hijacking the sftunnel communication connection or being a valid registered sftunnel peer and sending an sftunnel command to write a malicious file to the disk of an affected device. A successful exploit could allow the attacker to write a file to the device that is executed with root privileges. To exploit this vulnerability, the attacker must have valid user credentials on the affected device. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. Affected product named by the advisory: Secure Firewall Management Center (FMC) Appliances.

CVE-2026-20324
FirewallASA / Firepower
Sep 16, 2026
Critical9.8Cisco

Critical [CVE-2026-20242] Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Execution Vulnerability

A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary commands as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream from a host that is configured in the external database access list. An attacker could exploit this vulnerability by sending a crafted, serialized Java byte stream to a specific TCP port of an affected device. A successful exploit could allow the attacker to execute arbitrary commands on the device and elevate privileges to root. Notes: - This vulnerability can be exploited only by an attacker who has control of a host in the external database access list. - If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. Affected product named by the advisory: Secure Firewall Management Center (FMC) Appliances.

CVE-2026-20242
FirewallASA / Firepower
Sep 16, 2026
Critical9.9Cisco

Critical [CVE-2026-20176 +2] Cisco Identity Services Engine Remote Code Execution Vulnerabilities

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit these vulnerabilities, the attacker must have valid administrative credentials. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Identity Services Engine, see Cisco Identity Services Engine Security Hardening Release: September 2026. Affected product named by the advisory: Identity Services Engine Software.

CVE-2026-20176CVE-2026-20211CVE-2026-20307
ISEIdentity Services Engine
Sep 16, 2026
Critical9.1Vendor: HighCisco

Critical [CVE-2026-20282 +2] Cisco Identity Services Engine Authenticated Remote Code Execution and API Vulnerabilities

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct SQL injections, modify data, or execute arbitrary commands on the underlying operating system on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Note: For CVE-2026-20282 and CVE-2026-20283, Cisco has assigned a Security Impact Rating (SIR) of High rather than Medium as the scores indicate. The reason is that it is easy to get to root from the achieved privilege level. Cisco has released software updates that address these vulnerabilities. There are workarounds that address one of these vulnerabilities. This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Identity Services Engine, see Cisco Identity Services Engine Security Hardening Release: September 2026. Affected product named by the advisory: Identity Services Engine Software.

CVE-2026-20282CVE-2026-20283CVE-2026-20284
ISEIdentity Services Engine
Sep 16, 2026
Critical10.0Cisco

Critical [CVE-2026-76423 +5] Cisco Identity Services Engine Vulnerabilities

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to bypass authentication to the REST API, achieve remote code execution, perform SQL injection, and conduct XML External Entity injection attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Identity Services Engine, see Cisco Identity Services Engine Security Hardening Release: September 2026. Affected products named by the advisory: Identity Services Engine Software.

CVE-2026-76423CVE-2026-76424CVE-2026-76425+3
ISEIdentity Services Engine
Sep 16, 2026
Critical9.1Cisco

Critical [CVE-2026-20340 +4] Cisco Secure Firewall Management Center Software Vulnerabilities

Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software could allow a remote attacker to gain root access, download sensitive files, perform a SQL injection attack, or cause a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026. Affected product named by the advisory: Secure Firewall Management Center (FMC) Appliances.

CVE-2026-20340CVE-2026-20341CVE-2026-20342+2
FirewallASA / Firepower
Sep 16, 2026
Critical9.9Cisco Exploited

Critical [CVE-2026-20329 +7] Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software and Cisco Secure Firewall Management Center (FMC) Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing. Two of them are known to be actively exploited. For more information, see the following advisories: Cisco Secure Firewall Management Center Software Static Credential Vulnerability and Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability. To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures Identifier (CVE ID) to each CWE grouping. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories.

CVE-2026-20329CVE-2026-20330CVE-2026-20331+5
FirewallASA / Firepower
Sep 16, 2026
Critical10.0Cisco Exploited

Critical [CVE-2026-20130 +5] Cisco Identity Services Engine Hardening Release: September 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing. One of them is known to be actively exploited. For more information, see Cisco Identity Services Engine Authentication Bypass Vulnerability. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures identifier (CVE ID) to each CWE grouping. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. Affected products named by the advisory: Identity Services Engine Software.

CVE-2026-20130CVE-2026-20192CVE-2026-20194+3
ISEIdentity Services Engine
Sep 16, 2026
Critical9.1Cisco

Critical [CVE-2026-20305 +1] Cisco Identity Services Engine Command Injection Vulnerabilities

Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform command injection attacks on an affected device and execute arbitrary commands as the root user. To exploit these vulnerabilities, the attacker must have valid administrative credentials. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Identity Services Engine, see Cisco Identity Services Engine Security Hardening Release: September 2026. Affected products named by the advisory: Identity Services Engine Software.

CVE-2026-20305CVE-2026-20306
ISEIdentity Services Engine
Sep 16, 2026
Critical10.0Cisco Exploited CISA KEV

Critical [CVE-2026-76460] Cisco Identity Services Engine Authentication Bypass Vulnerability

A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted request to an affected API endpoint. A successful exploit could allow the attacker to gain unauthorized access to the affected device by bypassing the web-based management interface. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Identity Services Engine, see Cisco Identity Services Engine Security Hardening Release: September 2026. Affected products named by the advisory: ISE Passive Identity Connector; Identity Services Engine Software.

CVE-2026-76460
ISEIdentity Services Engine
Sep 16, 2026
Critical9.0Cisco

Critical [CVE-2026-76412 +2] Cisco Secure Firewall Management Center Software Vulnerabilities

Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software could allow a remote attacker to gain root access and perform session forgery or session impersonation. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026. Affected product named by the advisory: Secure Firewall Management Center (FMC) Appliances.

CVE-2026-76412CVE-2026-76413CVE-2026-76420
FirewallASA / Firepower
Sep 16, 2026
Critical9.9Cisco Exploited

Critical [CVE-2026-20322 +5] Cisco Nexus Dashboard Software Security Hardening Release: September 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures identifier (CVE ID). Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

CVE-2026-20322CVE-2026-20325CVE-2026-20326+3
SwitchesNexus
Sep 16, 2026
High8.6Cisco

High [CVE-2024-20260] Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL VPN Denial of Service Vulnerability

Update for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv) models. However, it was later found that this vulnerability affects all Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software platforms. A vulnerability in the VPN and management web servers of the Cisco Secure Firewall ASA Software and Cisco Secure FTD Software platforms could allow an unauthenticated, remote attacker to cause an affected device to run out of system memory or buffer blocks, which in turn could cause SSL VPN connection processing to slow down and eventually cease altogether. This vulnerability is due to a lack of proper memory management for new incoming SSL/TLS connections. An attacker could exploit this vulnerability by sending a large number of new incoming SSL/TLS connections to the targeted device. A successful exploit could allow the attacker to deplete system memory or buffers, resulting in a denial of service (DoS) condition. The memory or buffers could be reclaimed slowly if the attack traffic is stopped, but a manual reload may be required to restore operations quickly. Cisco has released software updates that address this vulnerability.

CVE-2024-20260
FirewallASA / FirepowerASA 5500
Sep 16, 2026
High8.6Cisco

High [CVE-2026-20250] Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Secure Firewall 3100 and 4200 Series DTLS Denial of Service Vulnerability

A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Secure Firewall 3100 Series and 4200 Series devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper resource management when processing certain DTLS messages. An attacker could exploit this vulnerability by sending a crafted stream of DTLS traffic to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition. Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability. This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026. Affected products named by the advisory: Secure Firewall 4200 Series.

CVE-2026-20250
FirewallASA / Firepower
Sep 16, 2026
High8.6Cisco

High [CVE-2026-20352] Cisco Identity Services Engine RADIUS Denial of Service Vulnerability

A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain RADIUS requests. An attacker could exploit this vulnerability by sending a crafted RADIUS request directly to an affected device. A successful exploit could allow the attacker to cause the ISE node to become unavailable. For single node deployments in that condition, endpoints that have not already authenticated would be unable to access the network until the node comes back up on its own. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Identity Services Engine, see Cisco Identity Services Engine Security Hardening Release: September 2026. Affected product named by the advisory: Identity Services Engine Software.

CVE-2026-20352
ISEIdentity Services Engine
Sep 16, 2026
High8.6Cisco

High [CVE-2026-20295 +1] Cisco Secure Firewall Management Center and Secure Firewall Threat Defense Software sftunnel Vulnerabilities

Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated attacker to perform an sftunnel authentication bypass or sftunnel denial of service (DoS) attack. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026. Affected products named by the advisory: Firepower 2100 Series; Firepower 1000 Series; ASA 5500-X Series Firewalls; 3000 Series Industrial Security Appliances (ISA); and 3 more.

CVE-2026-20295CVE-2026-20323
FirewallASA / FirepowerASA 5500
Sep 16, 2026
HighCisco

High [CVE-2026-20135] Cisco Secure Firewall Threat Defense Software TLS 1.3 Denial of Service Vulnerability

A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper buffer management during the TLS 1.3 connection. An attacker could exploit this vulnerability by sending a crafted TLS 1.3 packet to an affected system through a TLS 1.3-enabled listening socket. A successful exploit could allow the attacker to cause the LINA process to crash, which would cause the device to reload. The reload can happen before or after authentication of the connection. Note: TLS 1.3 connections include both data traffic and user-management traffic. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026.

CVE-2026-20135
FirewallASA / Firepower
Sep 16, 2026
High7.4Cisco

High [CVE-2026-20222] Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software EIGRP Denial of Service Vulnerability

A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper resource management when handling EIGRP update messages. An attacker could exploit this vulnerability by sending crafted EIGRP updates at a high rate to an affected device. A successful exploit could allow the attacker to trigger a memory leak that will eventually cause the affected device to reload unexpectedly. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is part of a group of advisories. For a complete list of the advisories and links to them, see Cisco Advance Notification for Publication of September 16, 2026, Security Advisories. In addition, for further documentation of improvements and fixes in Cisco Secure Firewall products, see Cisco Secure Firewall Adaptive Security Appliance Software, Secure Firewall Threat Defense Software, and Secure Firewall Management Center Software Hardening Release: September 2026.

CVE-2026-20222
FirewallASA / Firepower
Sep 16, 2026

← All vendors