Skip to content
VulniPulse

Cisco Routers Vulnerabilities & Security Advisories

6 advisories tracked · Cisco Security Advisories · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Cisco advisory that VulniPulse classified as Routers, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 1 critical, 3 high, 2 medium.

Android app · Google Play

Monitor Cisco CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Cisco Security Advisories

Polled via the official Cisco PSIRT RSS feed. Advisory pages are fetched for new items to extract fixed software and workarounds.

Latest Cisco Routers advisories

Critical9.8Cisco Exploited

Critical [CVE-2026-20274 +6] Cisco IOS XR Software Security Hardening Release: September 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures identifier (CVE ID) to each CWE grouping. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.

CVE-2026-20274CVE-2026-20275CVE-2026-20276+4
Routers
Sep 2, 2026
Medium4.3Cisco

Medium [CVE-2026-20308] Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerability

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the web-based management interface to become unresponsive. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. Affected products named by the advisory: Aironet Access Point Software (IOS XE Controller); IOS XE Catalyst SD-WAN; IOS XE Software Bootloader (ROMMON); IOS XG Software; and 1 more.

CVE-2026-20308
SD-WANRoutersWirelessIOS XE
Aug 5, 2026
High7.7Cisco

High [CVE-2026-20167 +2] Cisco IoT Field Network Director Vulnerabilities

Multiple vulnerabilities in the web-based management interface of Cisco IoT Field Network Director Software could allow an authenticated, remote attacker to access files, execute commands, and cause denial of service (DoS) conditions on managed routers. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. Affected product named by the advisory: IoT Field Network Director (IoT-FND).

CVE-2026-20167CVE-2026-20168CVE-2026-20169
Routers
May 6, 2026
High8.8Cisco

High [CVE-2026-20040 +1] Cisco IOS XR Software CLI Privilege Escalation Vulnerabilities

Multiple vulnerabilities in Cisco IOS XR Software could allow an authenticated, local attacker to execute commands as root on an underlying operating system or gain full administrative control of an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. A workaround is available for one of the vulnerabilities. This advisory is part of the March 2026 release of the Cisco IOS XR Software Security Advisory Bundled Publication. For a complete list of the advisories and l…

CVE-2026-20040CVE-2026-20046
Routers
Mar 11, 2026
High7.4Cisco

High [CVE-2026-20074] Cisco IOS XR Software Multi-Instance Intermediate System-to-Intermediate System Denial of Service Vulnerability

A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) multi-instance routing feature of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the IS-IS process to restart unexpectedly. This vulnerability is due to insufficient input validation of ingress IS-IS packets. An attacker could exploit this vulnerability by sending crafted IS-IS packets to an affected device after forming an adjacency. A successful exploit could allow the attacker to cause the IS-IS process to restart unexpectedly, resulting in a temporary loss of connectivity to adver…

CVE-2026-20074
Routers
Mar 11, 2026
Medium6.8Vendor: HighCisco Exploited

Medium [CVE-2026-20118] Cisco IOS XR Egress Packet Network Interface Aligner Interrupt Denial of Service Vulnerability

A vulnerability in the handling of an Egress Packet Network Interface (EPNI) Aligner interrupt in Cisco IOS XR Software for Cisco Network Convergence System (NCS) 5500 Series with NC57 line cards and Cisco NCS 5700 Routers and Cisco IOS XR Software for Third Party Software could allow an unauthenticated, remote attacker to cause the network processing unit (NPU) and ASIC to stop processing, preventing traffic from traversing the interface. This vulnerability is due to the corruption of packets in specific cases when an EPNI Aligner interrupt is triggered while an affected device is experien…

CVE-2026-20118
Routers
Mar 11, 2026

← All Cisco advisories