Skip to content
VulniPulse

Cisco Security Advisories & CVEs

84 advisories tracked · Cisco Security Advisories · direct feeds checked every minute; rate-limited backstops use a safe source cadence

Android app · Google Play

Monitor Cisco CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Check if your Cisco device is affected

Pick your device's OS (and platform, where it matters), choose the software release it runs, and we'll check it against Cisco's recent security advisories — the same data behind the Cisco Software Checker.

Official source

Cisco Security Advisories

Polled via the official Cisco PSIRT RSS feed. Advisory pages are fetched for new items to extract fixed software and workarounds.

Latest Cisco advisories

Medium4.9Cisco PoC reported

Medium [CVE-2026-20029] Cisco Identity Services Engine XML External Entity Processing Information Disclosure Vulnerability

A vulnerability in the licensing features of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker with administrative privileges to gain access to sensitive information. This vulnerability is due to improper parsing of XML that is processed by the web-based management interface of Cisco ISE and Cisco ISE-PIC. An attacker could exploit this vulnerability by uploading a malicious file to the application. A successful exploit could allow the attacker to read arbitrary files from the underlying operating system tha… Affected products named by the advisory: Cisco Identity Services Engine Software.

CVE-2026-20029
ISEIdentity Services Engine
Jan 7, 2026
Medium5.8Cisco

Medium [CVE-2026-20026 +1] Multiple Cisco Products Snort 3 Distributed Computing Environment/Remote Procedure Call Vulnerabilities

Multiple Cisco products are affected by vulnerabilities in the processing of Distributed Computing Environment Remote Procedure Call (DCE/RPC) requests that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to leak sensitive information or to restart, which would result in an interruption of packet inspection. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are workarounds that address these vulnerabilities. Affected products named by the advisory: Cisco UTD SNORT IPS Engine Software; Cisco Secure Firewall Threat Defense (FTD) Software 7.0.0.1; Cisco Secure Firewall Threat Defense (FTD) Software 7.0.1.1; Cisco Secure Firewall Threat Defense (FTD) Software 7.0.2.1; and 1 more.

CVE-2026-20026CVE-2026-20027
FirewallASA / Firepower
Jan 7, 2026
Medium5.0Cisco Exploited CISA KEV

Medium [CVE-2023-20269] vulnerability in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or an authenticated, remote attacker to establish a clientless SSL VPN session with an unauthorized user

An unauthenticated remote attacker could exploit a flaw in the remote access VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software to conduct a brute force attack in an attempt to identify valid username and password combinations or an authenticated, remote attacker to establish a clientless SSL VPN session with an unauthorized user. The flaw is caused by improper separation of authentication, authorization, and accounting (AAA) between the remote access VPN feature and the HTTPS management and site-to-site VPN features. Establish a clientless SSL VPN session (only when running Cisco ASA Software Release 9.16 or earlier). Affected products named by the advisory: Secure Firewall Adaptive Security Appliance (ASA) Software; ASA 5500-X Series Firewalls; 3000 Series Industrial Security Appliances (ISA); Firepower 9000 Series; and 4 more. Affected products named by the advisory: Firepower 4100 Series; Adaptive Security Virtual Appliance (ASAv); Firepower 2100 Series; Firepower 1000 Series.

CVE-2023-20269
FirewallASA / FirepowerASA 5500
Sep 6, 2023
Medium6.5Cisco Exploited CISA KEV

Medium [CVE-2020-3153] Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability

A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling of directory paths.

CVE-2020-3153
Unclassified
Feb 19, 2020

← All vendors