Skip to main content
All vendors

Cisco security briefs

25 published alerts for Cisco products and services.

Actively exploited (KEV)

CVE-2026-20349

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) vulnerability

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-20349). Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. CISA remediation due date: 2026-08-14. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-20316

Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability

Cisco Secure Firewall Management Center (FMC) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-20316). Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. CISA remediation due date: 2026-08-01. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2008-4128

Cisco IOS Cross-Site Request Forgery Vulnerability

Cisco IOS is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2008-4128). Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. CISA remediation due date: 2026-07-16. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-20230

Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability

Cisco Unified Communications Manager is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-20230). Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root. CISA remediation due date: 2026-06-28. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-20262

Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability

Cisco Catalyst SD-WAN Manager is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-20262). Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. CISA remediation due date: 2026-06-29. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-20245

Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability

Cisco Catalyst SD-WAN Manager is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-20245). Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. CISA remediation due date: 2026-06-23. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-20182

Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

Cisco Catalyst SD-WAN is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-20182). Cisco Catalyst SD-WAN Controller & Manager contain an authentication bypass vulnerability that allows an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. CISA remediation due date: 2026-05-17. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-20133

Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

Cisco Catalyst SD-WAN Manager is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-20133). Cisco Catalyst SD-WAN Manager contains an exposure of sensitive information to an unauthorized actor vulnerability that could allow remote attackers to view sensitive information on affected systems. CISA remediation due date: 2026-04-23. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-20128

Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability

Cisco Catalyst SD-WAN Manager is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-20128). Cisco Catalyst SD-WAN Manager contains a storing passwords in a recoverable format vulnerability that allows an authenticated, local attacker to gain DCA user privileges by accessing a credential file for the DCA user on the filesystem as a low-privileged user. CISA remediation due date: 2026-04-23. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-20122

Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability

Cisco Catalyst SD-WAN Manger is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-20122). Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges. CISA remediation due date: 2026-04-23. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2026-20131

Secure Firewall Management Center (FMC) vulnerability

Cisco Secure Firewall Management Center (FMC) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-20131). Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. CISA remediation due date: 2026-03-22. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-20127

Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability

Cisco Catalyst SD-WAN Controller and Manager is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-20127). Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, and Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, contain an authentication bypass vulnerability could allow an unauthenticated, remote attacker to bypass authentication and obtain administrative privileges on an affected system. This vulnerability exists because the peering authentication mechanism in an affected system is not working properly. An attacker could exploit this vulnerability by sending crafted requests to an affected system. A successful exploit could allow the attacker to log in to an affected Cisco Catalyst SD-WAN Controller as an internal, high-privileged, non-root user account. Using this account, the attacker could access NETCONF, which would then allow the attacker to manipulate network configuration for the SD-WAN fabric. CISA remediation due date: 2026-02-27. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2022-20775

Cisco SD-WAN Path Traversal Vulnerability

Cisco SD-WAN is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-20775). Cisco SD-WAN CLI contains a path traversal vulnerability that could allow an authenticated local attacker to gain elevated privileges via improper access controls on commands within the application CLI. A successful exploit could allow the attacker to execute arbitrary commands as the root user. CISA remediation due date: 2026-02-27. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-20045

Cisco Unified Communications Products Code Injection Vulnerability

Cisco Unified Communications Manager is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-20045). Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), Cisco Unity Connection, and Cisco Webex Calling Dedicated Instance contain a code injection vulnerability that could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root. CISA remediation due date: 2026-02-11. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-20393

Cisco Multiple Products Improper Input Validation Vulnerability

Cisco Multiple Products is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-20393). Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability that allows threat actors to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance. CISA remediation due date: 2025-12-24. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-20352

Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability

Cisco IOS and IOS XE is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-20352). Cisco IOS and IOS XE contains a stack-based buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) subsystem that could allow for denial of service or remote code execution. A successful exploit could allow a low-privileged attacker to cause the affected system to reload, resulting in a DoS condition, or allow a high-privileged attacker to execute arbitrary code as the root user and obtain full control of the affected system. CISA remediation due date: 2025-10-20. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-20362

Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense vulnerability

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-20362). Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a missing authorization vulnerability. This vulnerability could be chained with CVE-2025-20333. CISA remediation due date: 2025-09-26. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-20333

Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense vulnerability

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-20333). Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a buffer overflow vulnerability that allows for remote code execution. This vulnerability could be chained with CVE-2025-20362. CISA remediation due date: 2025-09-26. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-20337

Cisco Identity Services Engine Injection Vulnerability

Cisco Identity Services Engine is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-20337). Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device. CISA remediation due date: 2025-08-18. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Actively exploited (KEV)

CVE-2025-20281

Cisco Identity Services Engine Injection Vulnerability

Cisco Identity Services Engine is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-20281). Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to exploit this vulnerability by submitting a crafted API request. Successful exploitation could allow an attacker to perform remote code execution and obtaining root privileges on an affected device. CISA remediation due date: 2025-08-18. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.

Actively exploited (KEV)Ransomware

CVE-2020-3259

Cisco ASA and FTD Information Disclosure Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-3259). Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which could lead to the disclosure of confidential information due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. This vulnerability affects only specific AnyConnect and WebVPN configurations. CISA remediation due date: 2024-03-07. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2023-20269

Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability

Cisco Adaptive Security Appliance and Firepower Threat Defense is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2023-20269). Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user. CISA remediation due date: 2023-10-04. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2020-3433

Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability

Cisco AnyConnect Secure is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-3433). Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by the application at run time. An attacker with valid credentials on Windows could execute code on the affected machine with SYSTEM privileges. CISA remediation due date: 2022-11-14. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2020-3153

Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability

Cisco AnyConnect Secure is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2020-3153). Cisco AnyConnect Secure Mobility Client for Windows allows for incorrect handling of directory paths. An attacker with valid credentials on Windows would be able to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks. CISA remediation due date: 2022-11-14. If you need help checking exposure, call (864) 335-9223.