Product of Cisco

IOS and IOS XE

As of , 4 Cisco IOS and IOS XE vulnerabilities are on CISA's list of exploited vulnerabilities; 0 were added in 2026. Patch first: CVE-2017-3881.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2017-3881Remote Code ExecutionCisco IOS and IOS XEPatch this weekMetasploit module; EPSS 0.990.99
2CVE-2018-0171Software Smart Install Remote Code ExecutionCisco IOS and IOS XEPatch this weekEPSS 0.990.99
3CVE-2025-20352Software SNMP Denial of Service and Remote Code ExecutionCisco IOS and IOS XEPatch soon0.39
4CVE-2023-20109Group Encrypted Transport VPN Out-of-Bounds WriteCisco IOS and IOS XEPatch soon0.02

Added each year

0.512021: 1120212022: 1120222023: 1120232024: nonenone20242025: 1120252026: nonenone2026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20211
20221
20231
2024none
20251
2026none

Used in ransomware

Changes CISA made to these entries

  1. CVE-2025-20352 Cisco IOS and IOS XEEdited: name.

Every change we recorded