Cisco Security Advisories & CVEs
193 advisories tracked · Cisco Security Advisories · direct feeds checked every minute; rate-limited backstops use a safe source cadence
Android app · Google Play
Monitor Cisco CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Check if your Cisco device is affected
Pick your device's OS (and platform, where it matters), choose the software release it runs, and we'll check it against Cisco's recent security advisories — the same data behind the Cisco Software Checker.
Official source
Cisco Security Advisories
Polled via the official Cisco PSIRT RSS feed. Advisory pages are fetched for new items to extract fixed software and workarounds.
Latest Cisco advisories
Medium [CVE-2026-20069] Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software VPN Web Services Client-Side Request Smuggling Vulnerability
A vulnerability in the VPN web services component of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct browser-based attacks against users of an affected device. This vulnerability is due to improper validation of HTTP requests. An attacker could exploit this vulnerability by persuading a user to visit a website that is designed to pass malicious HTTP requests to a device that is running Cisco Secure Firewall ASA Software or Cisco Secure FTD Software and has web … Affected products named by the advisory: Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1.2; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1.3; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.2.4; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.2.5; and 3 more.
Medium [CVE-2026-20149] Cisco Webex Services Cross-Site Scripting Vulnerability
A vulnerability in Cisco Webex could have allowed an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. Cisco has addressed this vulnerability, and no customer action is needed. This vulnerability was due to improper filtering of user-supplied input. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by persuading a user to follow a malicious link. A successful exploit could have allowed the attacker to conduct an XSS attack against the targeted user. As mentioned, Cisco has addressed this vulnerability in the Cisco… Affected product named by the advisory: Cisco Webex Meetings.
Medium [CVE-2026-20044] Cisco Secure Firewall Management Center Software Command Injection Vulnerability
A vulnerability in the lockdown mechanism of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, local attacker to perform arbitrary commands as root. This vulnerability is due to insufficient restrictions on remediation modules while in lockdown mode. An attacker could exploit this vulnerability by sending crafted input to the system CLI of the affected device. A successful exploit could allow the attacker to run arbitrary commands or code as root, even when the system is in lockdown mode. To exploit this vulnerability, the attacker must have valid administ… Affected products named by the advisory: Cisco Secure Firewall Management Center (FMC) 6.4.0.1; Cisco Secure Firewall Management Center (FMC) 6.4.0.3; Cisco Secure Firewall Management Center (FMC) 6.4.0.2; Cisco Secure Firewall Management Center (FMC) 6.4.0.4; and 5 more.
Medium [CVE-2026-20016 +3] Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Authenticated Command Injection Vulnerabilities
Multiple vulnerabilities in the CLI feature of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to cause a device to execute commands with elevated privileges or reload unexpectedly, resulting in a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is part … Affected products named by the advisory: Cisco Secure Firewall Threat Defense (FTD) Software 6.4.0.1; Cisco Secure Firewall Threat Defense (FTD) Software 6.4.0.3; Cisco Secure Firewall Threat Defense (FTD) Software 6.4.0.2; Cisco Secure Firewall Threat Defense (FTD) Software 6.4.0.4; and 4 more.
Medium [CVE-2026-20031] ClamAV Cascading Style Sheets Image Parsing Error Handling Denial of Service Vulnerability
A vulnerability in the HTML Cascading Style Sheets (CSS) module of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper error handling when splitting UTF-8 strings. An attacker could exploit this vulnerability by submitting a crafted HTML file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the scanning process. Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulne… Affected product named by the advisory: Cisco Secure Endpoint Private Cloud Console.
Medium [CVE-2026-20018] Cisco Secure Firewall Management Center and Secure Firewall Threat Defense Software Path Traversal Vulnerability
A vulnerability in the sftunnel functionality of Cisco Secure Firewall Management Center (FMC) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, remote attacker with administrative privileges to write arbitrary files as root on the underlying operating system. This vulnerability is due to insufficient validation of the directory path during file synchronization. An attacker could exploit this vulnerability by crafting a directory path outside of the expected file location. A successful exploit could allow the attacker to create or replace any fil… Affected products named by the advisory: Cisco Secure Firewall Management Center (FMC) 7.0.0.1; Cisco Secure Firewall Management Center (FMC) 7.0.1.1; Cisco Secure Firewall Management Center (FMC) 7.0.2.1; Cisco Secure Firewall Management Center (FMC) 7.0.3; and 2 more.
Medium [CVE-2026-20053 +3] Multiple Cisco Products Snort 3 Visual Basic for Applications Denial of Service Vulnerabilities
Multiple Cisco products are affected by vulnerabilities in the Snort 3 Visual Basic for Applications (VBA) Decompression Engine that could allow an unauthenticated, remote attacker to cause the Snort 3 Detection Engine to unexpectedly restart, resulting in a denial of service (DoS) condition. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are workarounds that address these vulnerabilities. This advisory is part of the March 2026 release of the Cisco Secure Firewall ASA,… Affected products named by the advisory: Cisco Cyber Vision; Cisco UTD SNORT IPS Engine Software; Cisco Secure Firewall Threat Defense (FTD) Software 7.2.0.1; Cisco Secure Firewall Threat Defense (FTD) Software 7.2.1; and 4 more.
High [CVE-2026-20033] Cisco Nexus 9000 Series Fabric Switches in ACI Mode Denial of Service Vulnerability
A vulnerability in Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation when processing specific Ethernet frames. An attacker could exploit this vulnerability by sending a crafted Ethernet frame to the management interface of an affected device. A successful exploit could allow the attacker to cause the device to reload unexpectedly, resulting in a DoS condition. Note: Only the out-of-band (OOB) management interface is affe… Affected products named by the advisory: Cisco NX-OS System Software in ACI Mode 15.2(1g); Cisco NX-OS System Software in ACI Mode 15.2(2e); Cisco NX-OS System Software in ACI Mode 15.2(2f); Cisco NX-OS System Software in ACI Mode 15.2(2g); and 4 more.
High [CVE-2026-20048] Cisco Nexus 9000 Series Fabric Switches in ACI Mode SNMP Denial of Service Vulnerability
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco Nexus 9000 Series Fabric Switches in ACI mode could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper processing when parsing SNMP requests. An attacker could exploit this vulnerability by continuously sending SNMP queries to a specific MIB of an affected device. A successful exploit could allow the attacker to cause a kernel panic on the device, resulting in a reload and a DoS condition. Note: This vulnerability … Affected products named by the advisory: Cisco NX-OS System Software in ACI Mode 15.2(1g); Cisco NX-OS System Software in ACI Mode 15.2(2e); Cisco NX-OS System Software in ACI Mode 15.2(2f); Cisco NX-OS System Software in ACI Mode 15.2(2g); and 4 more.
High [CVE-2026-20051] Cisco Nexus 3600 and 9500-R Series Switching Platforms Layer 2 Loop Denial of Service Vulnerability
A vulnerability with the Ethernet VPN (EVPN) Layer 2 ingress packet processing of Cisco Nexus 3600 Platform Switches and Cisco Nexus 9500-R Series Switching Platforms could allow an unauthenticated, adjacent attacker to trigger a Layer 2 traffic loop. This vulnerability is due to a logic error when processing a crafted Layer 2 ingress frame. An attacker could exploit this vulnerability by sending a stream of crafted Ethernet frames through the targeted device. A successful exploit could allow the attacker to cause a Layer 2 Virtual eXtensible LAN (VxLAN) traffic loop, which, in turn, could … Affected products named by the advisory: Cisco NX-OS Software 9.2(1); Cisco NX-OS Software 9.2(2); Cisco NX-OS Software 9.2(2t); Cisco NX-OS Software 9.2(3); and 4 more.
High [CVE-2026-20010] Cisco NX-OS Software Link Layer Discovery Protocol Denial of Service Vulnerability
A vulnerability in the Link Layer Discovery Protocol (LLDP) feature of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause the LLDP process to restart, which could cause an affected device to reload unexpectedly. This vulnerability is due to improper handling of specific fields in an LLDP frame. An attacker could exploit this vulnerability by sending a crafted LLDP packet to an interface of an affected device. A successful exploit could allow the attacker to cause the device to reload, resulting in a denial of service (DoS) condition. Affected products named by the advisory: Cisco Unified Computing System (Managed); Cisco NX-OS Software 10.3(1); Cisco NX-OS Software 10.3(2); Cisco NX-OS Software 10.3(3); and 5 more.
Medium [CVE-2026-20107] Cisco Application Policy Infrastructure Controller Denial of Service Vulnerability
A vulnerability in the Object Model CLI component of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, local attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. To exploit this vulnerability, the attacker must have valid user credentials and any role that includes CLI access. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by issuing crafted commands at the CLI prompt. A successful exploit could allow the attacker to cause the device to re…
Medium [CVE-2026-20037] Cisco UCS Manager Software Privilege Escalation Vulnerability
A vulnerability in the NX-OS CLI privilege levels of Cisco UCS Manager Software could allow an authenticated, local attacker with read-only privileges to modify files and perform unauthorized actions on an affected system. This vulnerability exists because unnecessary privileges are given to the user. An attacker could exploit this vulnerability by authenticating to a device as a read-only user and connecting to the NX-OS CLI. A successful exploit could allow the attacker to create or overwrite files in the file system or perform limited privileged actions on an affected device. Cisco has r… Affected products named by the advisory: Cisco Unified Computing System (Managed).
Medium [CVE-2026-20036] Cisco UCS Manager Software Command Injection Vulnerability
A vulnerability in the CLI and web-based management interface of Cisco UCS Manager Software could allow an authenticated, remote attacker with valid administrative privileges to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to insufficient input validation of command arguments that are supplied by the user. An attacker could exploit this vulnerability by authenticating to a device and submitting crafted input to the affected command. Affected products named by the advisory: Cisco Unified Computing System (Managed); NX-OS.
Medium [CVE-2026-20091] Cisco FXOS and UCS Manager Software Stored Cross-Site Scripting Vulnerability
A vulnerability in the web-based management interface of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected system. An attacker could exploit this vulnerability by injecting malicious data into specific pages of the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affecte… Affected products named by the advisory: Cisco Unified Computing System (Managed); Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1.2; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1.3; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.2.5; and 4 more.
Medium [CVE-2026-20099] Cisco FXOS and UCS Manager Software Command Injection Vulnerability
A vulnerability in the web-based management interface of Cisco FXOS Software and Cisco UCS Manager Software could allow an authenticated, local attacker with administrative privileges to perform command injection attacks on an affected system and elevate privileges to root. This vulnerability is due to insufficient input validation of command arguments supplied by the user. An attacker could exploit this vulnerability by authenticating to a device and submitting crafted input to the affected command. A successful exploit could allow the attacker to execute arbitrary commands on the underlyi… Affected products named by the advisory: Cisco Unified Computing System (Managed); Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1.2; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.1.3; Cisco Secure Firewall Adaptive Security Appliance (ASA) Software 9.12.2.5; and 4 more.
High [CVE-2026-20098] Cisco Meeting Management Arbitrary File Upload Vulnerability
A vulnerability in the Certificate Management feature of Cisco Meeting Management could allow an authenticated, remote attacker to upload arbitrary files, execute arbitrary commands, and elevate privileges to root on an affected system. This vulnerability is due to improper input validation in certain sections of the web-based management interface. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. The malicious files could overwrite system files…
High [CVE-2026-20119] Cisco TelePresence Collaboration Endpoint Software and RoomOS Software Denial of Service Vulnerability
A vulnerability in the text rendering subsystem of Cisco TelePresence Collaboration Endpoint (CE) Software and Cisco RoomOS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient validation of input received by an affected device. An attacker could exploit this vulnerability by getting the affected device to render crafted text, for example, a crafted meeting invitation. As indicated in the CVSS score, no user interaction is required, such as accepting the meeting invitation. A su… Affected products named by the advisory: Cisco TelePresence Endpoint Software (TC/CE).
Medium [CVE-2026-20056] Cisco Secure Web Appliance Real-Time Scanning Archive File Bypass Vulnerability
A vulnerability in the Dynamic Vectoring and Streaming (DVS) Engine implementation of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass the anti-malware scanner, allowing malicious archive files to be downloaded. This vulnerability is due to improper handling of certain archive files. An attacker could exploit this vulnerability by sending a crafted archive file, which should be blocked, through an affected device. A successful exploit could allow the attacker to bypass the anti-malware scanner and download malware onto an end us…
Medium [CVE-2026-20123] Cisco Evolved Programmable Network Manager and Cisco Prime Infrastructure Open Redirect Vulnerability
A vulnerability in the web-based management interface of Cisco Evolved Programmable Network Manager (EPNM) and Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the parameters in the HTTP request. An attacker could exploit this vulnerability by intercepting and modifying an HTTP request from a user. Cisco has released software updates that address this vulnerability. There ar…