Vendor
Cisco, page 2
As of , 100 Cisco vulnerabilities are on CISA's list of exploited vulnerabilities, 7 of them used in ransomware campaigns; 18 were added in 2026. Patch first: CVE-2026-20079.
| # | Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|---|
| 26 | CVE-2025-20281Injection | Cisco Identity Services Engine | Patch this weekEPSS 0.98 | 0.98 | ||
| 27 | CVE-2025-20337Injection | Cisco Identity Services Engine | Patch this weekEPSS 0.68 | 0.68 | ||
| 28 | CVE-2024-20439Static Credential | Cisco Smart Licensing Utility | Patch this weekEPSS 0.97 | 0.97 | ||
| 29 | CVE-2024-20353ASA and FTD Denial of Service | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Patch this weekEPSS 0.71 | 0.71 | ||
| 30 | CVE-2020-3259ASA and FTD Information Disclosure | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Patch this weekRansomware use; EPSS 0.72 | 0.72 | ||
| 31 | CVE-2018-0125Remote Code Execution | Cisco VPN Routers | Patch this weekEPSS 0.55 | 0.55 | ||
| 32 | CVE-2017-6736SNMP Remote Code Execution | Cisco IOS and IOS XE Software | Patch this weekEPSS 0.70 | 0.70 | ||
| 33 | CVE-2018-0171Software Smart Install Remote Code Execution | Cisco IOS and IOS XE | Patch this weekEPSS 0.99 | 0.99 | ||
| 34 | CVE-2020-3161Web Server Remote Code Execution and Denial-of-Service | Cisco Cisco IP Phones | Patch this weekEPSS 0.84 | 0.84 | ||
| 35 | CVE-2020-3452ASA and FTD Read-Only Path Traversal | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Patch this weekEPSS 0.99 | 0.99 | ||
| 36 | CVE-2020-3580ASA and FTD Cross-Site Scripting (XSS) | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Patch this weekRansomware use; EPSS 0.86 | 0.86 | ||
| 37 | CVE-2023-20118Command Injection | Cisco Small Business RV Series Routers | Patch this weekEPSS 0.54 | 0.54 | ||
| 38 | CVE-2023-20269Unauthorized Access | Cisco Adaptive Security Appliance and Firepower Threat Defense | Patch this weekRansomware use | 0.25 | ||
| 39 | CVE-2026-20262Directory or Path Traversal | Cisco Catalyst SD-WAN Manager | Patch soon | 0.28 | ||
| 40 | CVE-2026-20133Exposure of Sensitive Information to an Unauthorized Actor | Cisco Catalyst SD-WAN Manager | Patch soon | 0.32 | ||
| 41 | CVE-2025-20393Improper Input Validation | Cisco Multiple Products | Patch soon | 0.32 | ||
| 42 | CVE-2025-20352Software SNMP Denial of Service and Remote Code Execution | Cisco IOS and IOS XE | Patch soon | 0.39 | ||
| 43 | CVE-2015-0666Directory Traversal | Cisco Prime Data Center Network Manager (DCNM) | Patch soon | 0.40 | ||
| 44 | CVE-2017-6737SNMP Remote Code Execution | Cisco IOS and IOS XE Software | Patch soon | 0.45 | ||
| 45 | CVE-2026-20245Improper Encoding or Escaping of Output | Cisco Catalyst SD-WAN Manager | Patch soon | 0.25 | ||
| 46 | CVE-2026-20122Catalyst SD-WAN Manager Incorrect Use of Privileged APIs | Cisco Catalyst SD-WAN Manger | Patch soon | 0.25 | ||
| 47 | CVE-2014-2120Cross-Site Scripting (XSS) | Cisco Adaptive Security Appliance (ASA) | Patch soon | 0.23 | ||
| 48 | CVE-2024-20359ASA and FTD Privilege Escalation | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Patch soon | 0.19 | ||
| 49 | CVE-2017-6742SNMP Remote Code Execution | Cisco IOS and IOS XE Software | Patch soon | 0.21 | ||
| 50 | CVE-2016-6367CLI Remote Code Execution | Cisco Adaptive Security Appliance (ASA) | Patch soon | 0.23 | ||
| 51 | CVE-2018-0147Secure Access Control System Java Deserialization | Cisco Secure Access Control System (ACS) | Patch soon | 0.18 | ||
| 52 | CVE-2022-20775Path Traversal | Cisco SD-WAN | Patch soon | 0.12 | ||
| 53 | CVE-2024-20481ASA and FTD Denial-of-Service | Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | Patch soon | 0.16 | ||
| 54 | CVE-2017-12240DHCP Remote Code Execution | Cisco IOS and IOS XE Software | Patch soon | 0.14 | ||
| 55 | CVE-2018-0151IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution | Cisco IOS and IOS XE Software | Patch soon | 0.14 | ||
| 56 | CVE-2022-20708Small Business RV Series Routers Stack-based Buffer Overflow | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | Patch soon | 0.15 | ||
| 57 | CVE-2022-20821Open Port | Cisco IOS XR | Patch soon | 0.11 | ||
| 58 | CVE-2017-6738SNMP Remote Code Execution | Cisco IOS and IOS XE Software | Patch soon | 0.11 | ||
| 59 | CVE-2017-6739SNMP Remote Code Execution | Cisco IOS and IOS XE Software | Patch soon | 0.11 | ||
| 60 | CVE-2017-6740SNMP Remote Code Execution | Cisco IOS and IOS XE Software | Patch soon | 0.11 | ||
| 61 | CVE-2017-6743SNMP Remote Code Execution | Cisco IOS and IOS XE Software | Patch soon | 0.11 | ||
| 62 | CVE-2018-0156Smart Install Denial-of-Service | Cisco IOS Software and Cisco IOS XE Software | Patch soon | 0.09 | ||
| 63 | CVE-2022-20701Small Business RV Series Routers Stack-based Buffer Overflow | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | Patch soon | 0.10 | ||
| 64 | CVE-2022-20703Small Business RV Series Routers Stack-based Buffer Overflow | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | Patch soon | 0.09 | ||
| 65 | CVE-2020-3118Software Discovery Protocol Format String | Cisco IOS XR | Patch soon | 0.12 | ||
| 66 | CVE-2026-20128Storing Passwords in a Recoverable Format | Cisco Catalyst SD-WAN Manager | Patch soon | 0.07 | ||
| 67 | CVE-2017-6744SNMP Remote Code Execution | Cisco IOS software | Patch soon | 0.07 | ||
| 68 | CVE-2017-12231Network Address Translation Denial-of-Service | Cisco IOS software | Patch soon | 0.07 | ||
| 69 | CVE-2017-12233Common Industrial Protocol Request Denial-of-Service | Cisco IOS software | Patch soon | 0.07 | ||
| 70 | CVE-2017-12234Common Industrial Protocol Request Denial-of-Service | Cisco IOS software | Patch soon | 0.07 | ||
| 71 | CVE-2017-12235for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service | Cisco IOS software | Patch soon | 0.07 | ||
| 72 | CVE-2017-12237Internet Key Exchange Denial-of-Service | Cisco IOS and IOS XE Software | Patch soon | 0.07 | ||
| 73 | CVE-2018-0154Integrated Services Module for VPN Denial-of-Service | Cisco IOS Software | Patch soon | 0.07 | ||
| 74 | CVE-2018-0155Catalyst Bidirectional Forwarding Detection Denial-of-Service | Cisco Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches | Patch soon | 0.08 | ||
| 75 | CVE-2018-0158IOS and XE Software Internet Key Exchange Memory Leak | Cisco IOS Software and Cisco IOS XE Software | Patch soon | 0.07 | ||
| 76 | CVE-2018-0172Improper Input Validation | Cisco IOS and IOS XE Software | Patch soon | 0.08 | ||
| 77 | CVE-2018-0173Improper Input Validation | Cisco IOS and IOS XE Software | Patch soon | 0.08 | ||
| 78 | CVE-2018-0174IOS Software and Cisco IOS XE Software Improper Input Validation | Cisco IOS XE Software | Patch soon | 0.08 | ||
| 79 | CVE-2017-6627IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service | Cisco IOS and IOS XE Software | Patch soon | 0.06 | ||
| 80 | CVE-2018-0159IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service | Cisco IOS Software and Cisco IOS XE Software | Patch soon | 0.07 | ||
| 81 | CVE-2019-15271Deserialization of Untrusted Data | Cisco RV Series Routers | Patch soon | 0.05 | ||
| 82 | CVE-2010-3035Border Gateway Protocol (BGP) Denial-of-Service | Cisco IOS XR | Patch soon | 0.06 | ||
| 83 | CVE-2017-12319Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service | Cisco IOS XE Software | Patch soon | 0.05 | ||
| 84 | CVE-2022-20700Small Business RV Series Routers Stack-based Buffer Overflow | Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers | Patch soon | 0.06 | ||
| 85 | CVE-2026-20045Unified Communications Products Code Injection | Cisco Unified Communications Manager | Patch soon | 0.05 | ||
| 86 | CVE-2004-1464Denial-of-Service | Cisco IOS | Patch soon | 0.05 | ||
| 87 | CVE-2018-0179Denial-of-Service | Cisco IOS Software | Patch soon | 0.05 | ||
| 88 | CVE-2018-0180Denial-of-Service | Cisco IOS Software | Patch soon | 0.05 | ||
| 89 | CVE-2024-20399Command Injection | Cisco NX-OS | Patch soon | 0.04 | ||
| 90 | CVE-2018-0161Resource Management Errors | Cisco IOS Software | Patch soon | 0.04 | ||
| 91 | CVE-2020-3566Software DVMRP Memory Exhaustion | Cisco IOS XR | Patch soon | 0.04 | ||
| 92 | CVE-2009-2055Border Gateway Protocol (BGP) Denial-of-Service | Cisco IOS XR | Patch soon | 0.03 | ||
| 93 | CVE-2018-0167Buffer Overflow | Cisco IOS, XR, and XE Software | Patch soon | 0.03 | ||
| 94 | CVE-2018-0175Buffer Overflow | Cisco IOS, XR, and XE Software | Patch soon | 0.03 | ||
| 95 | CVE-2020-3569Software DVMRP Memory Exhaustion | Cisco IOS XR | Patch soon | 0.03 | ||
| 96 | CVE-2023-20109Group Encrypted Transport VPN Out-of-Bounds Write | Cisco IOS and IOS XE | Patch soon | 0.02 | ||
| 97 | CVE-2017-6663IOS Software and Cisco IOS XE Software Denial-of-Service | Cisco IOS and IOS XE Software | Patch soon | 0.02 | ||
| 98 | CVE-2017-12232for Cisco Integrated Services Routers Denial-of-Service | Cisco IOS software | Patch soon | 0.02 | ||
| 99 | CVE-2017-12238VPLS Denial-of-Service | Cisco Catalyst 6800 Series Switches | Patch soon | 0.02 | ||
| 100 | CVE-2026-20349Heap Inspection | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) | Patch soon | 0.01 |