Skip to content
VulniPulse

Cisco Security Advisories & CVEs

47 advisories tracked · Cisco Security Advisories · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Cisco CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your Cisco device is affected

Pick your device's OS (and platform, where it matters), choose the software release it runs, and we'll check it against Cisco's recent security advisories — the same data behind the Cisco Software Checker.

Official source

Cisco Security Advisories

Polled via the official Cisco PSIRT RSS feed. Advisory pages are fetched for new items to extract fixed software and workarounds.

Latest Cisco advisories

High7.4Cisco Exploited

High [CVE-2026-20051] Cisco Nexus 3600 and 9500-R Series Switching Platforms Layer 2 Loop Denial of Service Vulnerability

A vulnerability with the Ethernet VPN (EVPN) Layer 2 ingress packet processing of Cisco Nexus 3600 Platform Switches and Cisco Nexus 9500-R Series Switching Platforms could allow an unauthenticated, adjacent attacker to trigger a Layer 2 traffic loop. This vulnerability is due to a logic error when processing a crafted Layer 2 ingress frame. An attacker could exploit this vulnerability by sending a stream of crafted Ethernet frames through the targeted device. A successful exploit could allow the attacker to cause a Layer 2 Virtual eXtensible LAN (VxLAN) traffic loop, which, in turn, could … Affected products named by the advisory: Cisco NX-OS Software 9.2(1); Cisco NX-OS Software 9.2(2); Cisco NX-OS Software 9.2(2t); Cisco NX-OS Software 9.2(3); and 4 more.

CVE-2026-20051
SwitchesNexusNX-OSNexus 3600
Feb 25, 2026
High7.4Cisco

High [CVE-2026-20010] Cisco NX-OS Software Link Layer Discovery Protocol Denial of Service Vulnerability

A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause the LLDP process to restart, which could cause an affected device to reload unexpectedly. This vulnerability is due to improper handling of specific fields in an LLDP frame. An attacker could exploit this vulnerability by sending a crafted LLDP packet to an interface of an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a denial of service (DoS) condition. Affected products named by the advisory: Cisco Unified Computing System (Managed); Cisco NX-OS Software 10.3(1); Cisco NX-OS Software 10.3(2); Cisco NX-OS Software 10.3(3); and 5 more.

CVE-2026-20010
SwitchesNexusNX-OS
Feb 25, 2026
High8.8Cisco

High [CVE-2026-20098] Cisco Meeting Management Arbitrary File Upload Vulnerability

A vulnerability in the Certificate Management feature of Cisco Meeting Management could allow an authenticated, remote attacker to upload arbitrary files, execute arbitrary commands, and elevate privileges to root on an affected system. This vulnerability is due to improper input validation in certain sections of the web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. The malicious files could overwrite system files…

CVE-2026-20098
Unclassified
Feb 4, 2026
High7.5Cisco

High [CVE-2026-20119] Cisco TelePresence Collaboration Endpoint Software and RoomOS Software Denial of Service Vulnerability

A vulnerability in the text rendering subsystem of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of input received by an affected device. An attacker could exploit this vulnerability by getting the affected device to render crafted text, for example, a crafted meeting invitation. As indicated in the CVSS score, no user interaction is required, such as accepting the meeting invitation. A su… Affected products named by the advisory: Cisco TelePresence Endpoint Software (TC/CE).

CVE-2026-20119
Unclassified
Feb 4, 2026
High8.2Vendor: CriticalCisco Exploited CISA KEV

High [CVE-2026-20045] Cisco Unified Communications Products Remote Code Execution Vulnerability

A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to improper validation of user-supplied input in HTTP requests. An attacker could exploit this vulnerability by sending a sequence of craf… Affected products named by the advisory: Cisco Unified Communications Manager IM and Presence Service.

CVE-2026-20045
Unified CommunicationsWebex
Jan 21, 2026
High7.8Cisco Exploited CISA KEV

High [CVE-2020-3433] Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability

A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. The vulnerability is due to insufficient validation of resources that are loaded by the application at run time.

CVE-2020-3433
Unclassified
Aug 17, 2020
High7.5Cisco Exploited CISA KEV

High [CVE-2020-3259] Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Information Disclosure Vulnerability

An unauthenticated remote attacker could exploit a flaw in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software to retrieve memory contents on an affected device, which could lead to the disclosure of confidential information. The vulnerability is due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. Affected products named by the advisory: Secure Firewall Adaptive Security Appliance (ASA) Software; Secure Firewall Threat Defense (FTD) Software.

CVE-2020-3259
FirewallASA / Firepower
May 6, 2020

← All vendors