Skip to content
VulniPulse

Cisco Security Advisories & CVEs

149 advisories tracked · Cisco Security Advisories · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Cisco CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your Cisco device is affected

Pick your device's OS (and platform, where it matters), choose the software release it runs, and we'll check it against Cisco's recent security advisories — the same data behind the Cisco Software Checker.

Official source

Cisco Security Advisories

Polled via the official Cisco PSIRT RSS feed. Advisory pages are fetched for new items to extract fixed software and workarounds.

Latest Cisco advisories

High7.4Cisco

High [CVE-2026-20004] Cisco IOS XE Software TLS Memory Exhaustion Denial of Service Vulnerability

A vulnerability in the TLS library of Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to exhaust the available memory of an affected device. This vulnerability is due to improper management of memory resources during TLS connection setup. An attacker could exploit this vulnerability by repeatedly triggering the conditions that cause the memory increase. This could be done in a variety of ways, such as by repeatedly attempting Extensible Authentication Protocol (EAP) authentication when local EAP is enabled on an affected device or by using a machine-in-the-middle att… Affected products named by the advisory: Cisco IOS XE Software 16.9.2; Cisco IOS XE Software 16.9.1a; Cisco IOS XE Software 16.9.1b; Cisco IOS XE Software 16.9.1s; and 3 more.

CVE-2026-20004
IOS XE
Mar 25, 2026
High8.6Cisco

High [CVE-2026-20086] Cisco IOS XE Wireless Controller Software for the Catalyst CW9800 Family CAPWAP Denial of Service Vulnerability

A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) packets of Cisco IOS XE Wireless Controller Software for the Catalyst CW9800 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of a malformed CAPWAP packet. An attacker could exploit this vulnerability by sending a malformed CAPWAP packet to an affected device. A successful exploit could allow the attacker to cause the affected device to reload unexpectedly, resulting in a DoS … Affected products named by the advisory: Cisco IOS XE Software 17.14.1; Cisco IOS XE Software 17.15.1; Cisco IOS XE Software 17.15.3; Cisco IOS XE Software 17.15.2b; and 2 more.

CVE-2026-20086
SwitchesWirelessCatalystIOS XE
Mar 25, 2026
High8.6Cisco

High [CVE-2026-20084] Cisco IOS XE Software for Catalyst 9000 Series Switches DHCP Snooping Denial of Service Vulnerability

A vulnerability in the DHCP snooping feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause BOOTP packets to be forwarded between VLANs, resulting in a denial of service (DoS) condition. This vulnerability is due to improper handling of BOOTP packets on Cisco Catalyst 9000 Series Switches. An attacker could exploit this vulnerability by sending BOOTP request packets to an affected device. A successful exploit could allow an attacker to forward BOOTP packets from one VLAN to another, resulting in BOOTP VLAN leakage and potentially leading to high CPU utiliz… Affected products named by the advisory: Cisco IOS XE Software 16.6.1; Cisco IOS XE Software 16.6.2; Cisco IOS XE Software 16.6.3; Cisco IOS XE Software 16.6.5; and 3 more.

CVE-2026-20084
SwitchesCatalystIOS XECatalyst 9000
Mar 25, 2026
High7.7Cisco

High [CVE-2026-20125] Cisco IOS Software and IOS XE Software Release 3E HTTP Server Denial of Service Vulnerability

A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release 3E could allow an authenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending malformed HTTP requests to an affected device. A successful exploit could allow the attacker to cause a watchdog timer to expire and the device to reload, resulting in a DoS condition. Affected products named by the advisory: Cisco IOS 12.2(33)CY1; Cisco IOS 12.2(33)CY2; Cisco IOS 12.2(55)SE3; Cisco IOS 12.2(55)SE2; and 2 more.

CVE-2026-20125
IOS XE
Mar 25, 2026
High8.6Cisco

High [CVE-2026-20012] Cisco IOS, IOS XE, Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service Vulnerability

A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak, resulting in a denial of service (DoS) condition on an affected device. This vulnerability is due to improper parsing of IKEv2 packets. An attacker could exploit this vulnerability by sending crafted IKEv2 packets to an affected device. A successful exploit of Cisco IOS Software and … Affected products named by the advisory: Cisco IOS 15.2(1)S1; Cisco IOS 15.2(4)S; Cisco IOS 15.2(1)S2; Cisco IOS 15.2(2)S1; and 2 more.

CVE-2026-20012
FirewallASA / FirepowerIOS XE
Mar 25, 2026
Medium6.5Cisco

Medium [CVE-2026-20083] Cisco IOS XE Software Secure Copy Protocol Server Denial of Service Vulnerability

A vulnerability in the Secure Copy Protocol (SCP) server feature of Cisco IOS XE Software could allow an authenticated, local attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of a malformed SCP request. An attacker could exploit this vulnerability by issuing a crafted command through SSH. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition. Cisco has released software updates that address this vulnerability. There are no workaround… Affected products named by the advisory: Cisco IOS XE Software 3.5.0E; Cisco IOS XE Software 3.5.1E; Cisco IOS XE Software 3.5.2E; Cisco IOS XE Software 3.5.3E; and 4 more.

CVE-2026-20083
IOS XE
Mar 25, 2026
Medium6.1Vendor: HighCisco

Medium [CVE-2026-20104] Cisco IOS XE Software for Cisco Catalyst and Rugged Series Switches Secure Boot Bypass Vulnerability

A vulnerability in the bootloader of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches, Cisco Catalyst ESS9300 Embedded Series Switches, Cisco Catalyst IE9310 and IE9320 Rugged Series Switches, and Cisco IE3500 and IE3505 Rugged Series Switches could allow an authenticated, local attacker with level-15 privileges or an unauthenticated attacker with physical access to an affected device to execute arbitrary code at boot time and break the chain of trust. This vulnerability is due to insufficient validation of software at boot time. An attacker could exploit this vulnerability by … Affected products named by the advisory: Cisco IOS XE Software 16.12.8; Cisco IOS XE Software 16.12.6a; Cisco IOS XE Software 16.12.7; Cisco IOS XE Software 17.3.3; and 3 more.

CVE-2026-20104
SwitchesCatalystIOS XECatalyst 9200
Mar 25, 2026
Medium6.1Cisco

Medium [CVE-2026-20115] Cisco IOS XE Software Secure Channel for Meraki Information Disclosure Vulnerability

A vulnerability in Cisco IOS XE Software for Cisco Meraki could allow a remote, unauthenticated attacker to view confidential device information. This vulnerability is due to a device configuration upload being performed over an insecure tunnel. An attacker could exploit this vulnerability by conducting an on-path attack between the affected device and the Cisco Meraki Dashboard. A successful exploit could allow the attacker to view sensitive device configuration information. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vuln… Affected products named by the advisory: Cisco IOS XE Software 17.14.1a; Cisco IOS XE Software 17.15.1w; Cisco IOS XE Software 17.15.1a; Cisco IOS XE Software 17.15.2; and 2 more.

CVE-2026-20115
IOS XEMeraki
Mar 25, 2026
Medium5.3Cisco

Medium [CVE-2026-20113] Cisco IOx Application Hosting Environment Carriage Return Line Feed Injection Vulnerability

A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a carriage return line feed (CRLF) injection attack against a user. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by sending crafted packets to an affected device. A successful exploit could allow the attacker to arbitrarily inject log entries, manipulate the structure of log files, or obscure legitimate log events. Cisco has released software upda… Affected products named by the advisory: Cisco IOS XE Software 16.6.1; Cisco IOS XE Software 16.6.2; Cisco IOS XE Software 16.6.3; Cisco IOS XE Software 16.6.4s; and 2 more.

CVE-2026-20113
IOS XE
Mar 25, 2026
Medium4.8Cisco

Medium [CVE-2026-20112] Cisco IOx Application Hosting Environment Stored Cross-Site Scripting Vulnerability

A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by injecting malicious code into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected in… Affected products named by the advisory: Cisco IOS XE Software 16.6.1; Cisco IOS XE Software 16.6.2; Cisco IOS XE Software 16.6.3; Cisco IOS XE Software 16.6.4s; and 2 more.

CVE-2026-20112
IOS XE
Mar 25, 2026
Medium5.4Cisco

Medium [CVE-2026-20108] Cisco Catalyst SD-WAN Manager Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user input. An attacker could exploit this vulnerability by persuading a user of the web-based management interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based informatio…

CVE-2026-20108
SD-WANCatalyst SD-WAN
Mar 25, 2026
Medium5.4Cisco

Medium [CVE-2026-20114] Cisco IOS XE Software Lobby Ambassador Privilege Escalation Vulnerability

A vulnerability in the Lobby Ambassador web-based management API of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate their privileges and access management APIs that would not normally be available for Lobby Ambassador users. This vulnerability exists because parameters that are received by an API endpoint are not sufficiently validated. An attacker could exploit this vulnerability by authenticating as a Lobby Ambassador user and sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to create a new user with privile… Affected products named by the advisory: Cisco IOS XE Software 16.11.1a; Cisco IOS XE Software 16.11.1b; Cisco IOS XE Software 16.11.2; Cisco IOS XE Software 16.11.1s; and 2 more.

CVE-2026-20114
IOS XE
Mar 25, 2026
High8.8Cisco

High [CVE-2026-20040 +1] Cisco IOS XR Software CLI Privilege Escalation Vulnerabilities

Multiple vulnerabilities in Cisco IOS XR Software could allow an authenticated, local attacker to execute commands as root on an underlying operating system or gain full administrative control of an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. A workaround is available for one of the vulnerabilities. This advisory is part of the March 2026 release of the Cisco IOS XR Software Security Advisory Bundled Publication. For a complete list of the advisories and l…

CVE-2026-20040CVE-2026-20046
Routers
Mar 11, 2026
High7.4Cisco

High [CVE-2026-20074] Cisco IOS XR Software Multi-Instance Intermediate System-to-Intermediate System Denial of Service Vulnerability

A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) multi-instance routing feature of Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause the IS-IS process to restart unexpectedly. This vulnerability is due to insufficient input validation of ingress IS-IS packets. An attacker could exploit this vulnerability by sending crafted IS-IS packets to an affected device after forming an adjacency. A successful exploit could allow the attacker to cause the IS-IS process to restart unexpectedly, resulting in a temporary loss of connectivity to adver…

CVE-2026-20074
Routers
Mar 11, 2026
Medium6.1Cisco

Medium [CVE-2026-20116 +1] Multiple Cisco Contact Center Products Cross-Site Scripting Vulnerabilities

Multiple vulnerabilities in the web-based management interface of Cisco Finesse, Cisco Packaged Contact Center Enterprise (Packaged CCE), Cisco Unified Contact Center Enterprise (Unified CCE), Cisco Unified Contact Center Express (Unified CCX), and Cisco Unified Intelligence Center could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulnerabilities exist because the web-based management interface of an affected system does not sufficiently validate user-supplied input. An attacker could exploit these vulnerabil…

CVE-2026-20116CVE-2026-20117
Unified Communications
Mar 11, 2026
Medium6.8Vendor: HighCisco Exploited

Medium [CVE-2026-20118] Cisco IOS XR Egress Packet Network Interface Aligner Interrupt Denial of Service Vulnerability

A vulnerability in the handling of an Egress Packet Network Interface (EPNI) Aligner interrupt in Cisco IOS XR Software for Cisco Network Convergence System (NCS) 5500 Series with NC57 line cards and Cisco NCS 5700 Routers and Cisco IOS XR Software for Third Party Software could allow an unauthenticated, remote attacker to cause the network processing unit (NPU) and ASIC to stop processing, preventing traffic from traversing the interface. This vulnerability is due to the corruption of packets in specific cases when an EPNI Aligner interrupt is triggered while an affected device is experien…

CVE-2026-20118
Routers
Mar 11, 2026
Critical10.0Cisco Exploited CISA KEV

Critical [CVE-2026-20131] Cisco Secure Firewall Management Center Software Remote Code Execution Vulnerability

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. This vulnerability is due to insecure deserialization of a user-supplied Java byte stream. An attacker could exploit this vulnerability by sending a crafted serialized Java object to the web-based management interface of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the device and elevate privileges to root. Note: If the FMC…

CVE-2026-20131
FirewallASA / Firepower
Mar 4, 2026
Critical10.0Cisco

Critical [CVE-2026-20079] Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute a variety of scripts and commands that allow root access to the device. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability. This advisory is part of the March 2026 release of the Cisco Secure Firewall ASA, Secure FMC, and Secure FTD Software Security Advisory Bundled Publication.

CVE-2026-20079
FirewallASA / Firepower
Mar 4, 2026
High7.7Cisco

High [CVE-2026-20049] Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IPsec Denial of Service Vulnerability

A vulnerability in the processing of Galois/Counter Mode (GCM)-encrypted Internet Key Exchange version 2 (IKEv2) IPsec traffic of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to the allocation of an insufficiently sized block of memory. A successful exploit could al… Affected products named by the advisory: Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.7; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.10; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.13; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.4.8; and 5 more.

CVE-2026-20049
FirewallASA / Firepower
Mar 4, 2026
High8.6Cisco

High [CVE-2026-20039] Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software VPN Web Server Denial of Service Vulnerability

A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to ineffective memory management of the VPN web server. An attacker could exploit this vulnerability by sending a large number of crafted HTTP requests to an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a DoS condition. Cisco has r… Affected products named by the advisory: Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1.2; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1.3; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.2.4; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.2.5; and 3 more.

CVE-2026-20039
FirewallASA / Firepower
Mar 4, 2026

← All vendors