Vendor
Cisco vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 379 vulnerabilities in Cisco: 0 in the last 7 days and 150 in the last 90 days, 171 of them critical and 124 exploited in the wild. The most recent, CVE-2026-76460, was published on 16 September 2026. It has 59 technologies with a page of its own.
- Last 7 days
- 0
- Last 90 days
- 150
- Critical, all time
- 171
- Exploited in the wild
- 124
About Cisco
Multinational technology conglomerate that designs, manufactures, and sells networking and IT infrastructure products and services.
Cisco technologies
- Cisco IOS69
- Cisco IOS XE53
- Cisco Identity Services Engine51
- Cisco Firepower Threat Defense Software32
- Cisco IOS XR30
- Cisco IOS XE Software27
- Cisco Firepower Threat Defense22
- Cisco Adaptive Security Appliance Software22
- Cisco Ios Software19
- Cisco ISE Passive Identity Connector19
- Cisco Secure Firewall Management Center16
- Cisco Catalyst SD-WAN Manager12
- Cisco Adaptive Security Appliance (ASA)10
- Cisco Identity Services Engine Passive Identity Connector10
- Cisco Firepower Threat Defense (FTD)9
- Cisco IOS XR Software9
- Cisco Nexus Dashboard9
- Cisco Secure Email Gateway9
- Cisco Secure Firewall Management Center Software9
- Cisco Snort 39
- Cisco RoomOS8
- Cisco Secure Firewall Adaptive Security Appliance (ASA) Software8
- Cisco Secure Firewall Threat Defense (FTD) Software8
- Cisco ClamAV7
- Cisco Download Manager7
- Cisco Secure Email and Web Manager7
- Cisco Secure Endpoint Connector for Linux7
- Cisco Secure Endpoint Connector for Mac7
- Cisco Secure Endpoint Connector for Windows7
- Cisco Catalyst 8000V Edge Software6
- Cisco Catalyst 8200 Series Edge Platforms6
- Cisco Crosswork Network Controller6
- Cisco Cyber Vision6
- Cisco Secure Firewall Adaptive Security Appliance Software6
- Cisco Catalyst 8300 Series Edge Platforms5
- Cisco RV1605
- Cisco RV2605
- Cisco RV3405
- Cisco RV345 Series Routers5
- Cisco Secure Firewall Management Center (FMC)5
- Cisco Secure Workload5
- Cisco Small Business Rv1605
- Cisco Catalyst 8500L Edge Platforms4
- Cisco Cloud Services Router 1000V4
- Cisco Crosswork Data Gateway4
- Cisco Crosswork Planning4
- Cisco Crosswork Workflow Manager4
- Cisco Prime Infrastructure4
- Cisco RV110W Wireless-N VPN Firewall4
- Cisco Secure Firewall Adaptive Security Appliance4
- Cisco Unified Communications Manager4
- Cisco Webex Meetings Server4
- Cisco Catalyst 8300 Series Edge uCPE3
- Cisco Evolved Programmable Network Manager3
- Cisco IoT Field Network Director3
- Cisco SD-WAN3
- Cisco Secure Firewall Adaptive Security Appliance (Asa)3
- Cisco UCS S-Series Storage Servers3
- Cisco Unity Connection3
Latest Cisco vulnerabilities
- CVE-2026-76460: A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to…criticalexploited in the wildCVSS 10EPSS 14.0%
- CVE-2026-76451: Cisco ISE SQL and HQL injection in APIsmediumCVSS 4.9EPSS 0.4%
- CVE-2026-76450: Cisco Identity Services Engine SQL and HQL injectionmediumCVSS 4.9EPSS 0.4%
- CVE-2026-76449: Cisco ISE SQL/HQL injection in APIsmediumCVSS 4.9EPSS 0.4%
- CVE-2026-76448: Cisco Identity Services Engine SQL and HQL injectionmediumCVSS 4.9EPSS 0.4%
- CVE-2026-76447: Cisco ISE OCSP responder authentication bypassmediumCVSS 5.3EPSS 0.4%
- CVE-2026-76446: Cisco ISE external entity injection in APImediumCVSS 4.9EPSS 0.3%
- CVE-2026-76444: Cisco ISE information disclosure in Policy Runtime Repository Table servicemediumCVSS 5.3EPSS 0.3%
- CVE-2026-76439: Cisco ISE authentication bypass in guest portal endpoint posturemediumCVSS 5.3EPSS 0.3%
- CVE-2026-76438: Cisco BroadWorks CommPilot authorization bypass in web management interfacemediumCVSS 6.5EPSS 0.6%
- CVE-2026-76434: Cisco ISE path traversal in certificate importmediumCVSS 4.9EPSS 0.4%
- CVE-2026-76433: Cisco ISE path traversal in client provisioningmediumCVSS 5.3EPSS 1.3%
- CVE-2026-76432: Cisco ISE path traversal in file uploadmediumCVSS 4.9EPSS 1.2%
- CVE-2026-76431: Cisco ISE arbitrary file deletion in web management interfacemediumCVSS 4.9EPSS 1.2%
- CVE-2026-76428: Cisco ISE REST API SQL injection in session databasemediumCVSS 4.9EPSS 0.5%
- CVE-2026-76427: Cisco ISE XML external entity injection in offline profiler feed servicemediumCVSS 4.9EPSS 0.5%
- CVE-2026-76425: Cisco Identity Services Engine SQL injection in APIshighCVSS 7.6EPSS 0.4%
- CVE-2026-76424: Cisco ISE arbitrary file upload and executionhighCVSS 7.2EPSS 0.9%
- CVE-2026-76413: Cisco Secure FMC SSO token forgery in ASDM handlerhighCVSS 8.2EPSS 0.5%
- CVE-2026-76412: Cisco Secure FMC privilege escalation in remote diagnostics debuggerhighCVSS 8.5EPSS 0.4%
- CVE-2026-76409: Cisco Nexus Dashboard path traversal and weak access controlshighCVSS 8.8EPSS 0.5%
- CVE-2026-20360: Cisco Nexus Dashboard information exposure and insecure handlinghighCVSS 8.8EPSS 0.3%
- CVE-2026-20352: Cisco Identity Services Engine RADIUS denial of servicehighCVSS 8.6EPSS 0.4%
- CVE-2026-20350: Cisco ThousandEyes Virtual Appliance command injection in web interfacemediumCVSS 4.7EPSS 0.4%
- CVE-2026-20344: Cisco Secure FMC SQL injection in web management interfacehighCVSS 8.8EPSS 0.4%
Most severe Cisco vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-20079: Cisco Secure Firewall Management Center auth bypass in web interfacecriticalexploited in the wildCVSS 10EPSS 88.2%
- CVE-2026-20182: Cisco Catalyst SD-WAN authentication bypass in peering mechanismcriticalexploited in the wildCVSS 10EPSS 77.9%
- CVE-2026-20127: Cisco Catalyst SD-WAN auth bypass in peering authenticationcriticalexploited in the wildCVSS 10EPSS 48.2%
- CVE-2025-32433: Erlang Erlang/OTP authentication bypass in SSH Servercriticalexploited in the wildCVSS 10EPSS 47.1%
- CVE-2025-20281: Cisco Identity Services Engine unauthenticated RCE in APIcriticalexploited in the wildCVSS 10EPSS 36.0%
- CVE-2026-76460: A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to…criticalexploited in the wildCVSS 10EPSS 14.0%
- CVE-2025-20393: Cisco Secure Email Gateway command injection in Spam Quarantinecriticalexploited in the wildCVSS 10EPSS 5.0%
- CVE-2025-43300: Apple iOS, iPadOS, and macOS out-of-bounds write in Image I/Ocriticalexploited in the wildCVSS 10EPSS 4.5%
- CVE-2026-20131: Cisco Secure Firewall Management Center deserialization RCEcriticalexploited in the wildCVSS 10EPSS 1.7%
- CVE-2025-20337: Cisco Identity Services Engine injection vulnerability in APIcriticalexploited in the wildCVSS 10EPSS 1.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 7 | 0 | |
| 6 Jul 2026 | 4 | 0 | |
| 13 Jul 2026 | 8 | 1 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 1 | 1 | |
| 3 Aug 2026 | 15 | 2 | |
| 10 Aug 2026 | 1 | 1 | |
| 17 Aug 2026 | 19 | 8 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 11 | 3 | |
| 7 Sep 2026 | 1 | 0 | |
| 14 Sep 2026 | 83 | 29 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/cisco.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Cisco vulnerabilities", https://junglewise.ai/threats/vendors/cisco, 26 September 2026.