Vendor scorecard
Cisco
Routing, switching, security and collaboration platforms — the broadest CVE surface in enterprise networking.
CPE: cisco
Product families
10
Open in latest
2,285
Inferred — see methodology
Last disclosure
Aug 11, 2026
01
Product categories
10 trackedCVE volume, severity mix and the inferred latest shipping version per category.
| Category | CVEs | Volume | Severity mix | Open | Inferred latest |
|---|---|---|---|---|---|
| RoutingRouting & Switchingios_xe, ios_xr, ios | 1,357 | 1,015 | 16.12.3HIGH | ||
| Collaborationunified_communications_manager, webex_meetings, webex_meetings_server… | 500 | 378 | 14.3.1HIGH | ||
| ASA / FTD (Firewall)NGFW / Network Security · Secure Remote Access / VPN · Network Detection / IDS-IPSadaptive_security_appliance_software, firepower_threat_defense, asa | 369 | 230 | 6.6.1MED | ||
| SwitchingRouting & Switchingnx-os, nxos | 275 | 273 | 14.2\(1j\)HIGH | ||
| Firepower Management CenterNetwork Management & Monitoringfirepower_management_center, secure_firewall_management_center | 194 | 141 | 10.0.1HIGH | ||
| Identity Services EngineIdentity & Access Managementidentity_services_engine | 176 | 170 | 3.3.0HIGH | ||
| WirelessWireless LANmeraki_mx_firmware, meraki_mr_firmware, wireless_lan_controller… | 150 | 112 | 17.9.0.135MED | ||
| DNA / Catalyst Center + vManageNetwork Management & Monitoringcatalyst_center, catalyst_sd-wan_manager | 116 | 74 | 26.1.1.2HIGH | ||
| SD-WANSD-WAN & SASEios_xe_sd-wan | 26 | 23 | 17.3.1aMED | ||
| Umbrellaumbrella | 10 | 0 | unknown |
02
Recent CVEs
12 shownMost recently published, newest first. Each ID links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2026-20349(opens NVD record) | High | 8.6 | A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. | Aug 11, 2026 |
| CVE-2026-20273(opens NVD record) | High | 8.6 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20273 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-20. | Aug 5, 2026 |
| CVE-2026-20272(opens NVD record) | Critical | 9.8 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20272 are related to issues with improper neutralization of special elements that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-74. | Aug 5, 2026 |
| CVE-2026-20271(opens NVD record) | High | 8.6 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20271 are related to insufficient control flow management issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-691. | Aug 5, 2026 |
| CVE-2026-20270(opens NVD record) | High | 8.6 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20270 are related to incorrect calculation issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-682. | Aug 5, 2026 |
| CVE-2026-20269(opens NVD record) | High | 8.6 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20269 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664. | Aug 5, 2026 |
| CVE-2026-20268(opens NVD record) | High | 8.6 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20268 are related to issues with improper restriction of operations within the bounds of a memory buffer that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-119. | Aug 5, 2026 |
| CVE-2026-20267(opens NVD record) | Critical | 9.0 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20267 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284. | Aug 5, 2026 |
| CVE-2026-20316(opens NVD record) | Medium | 5.3 | A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the attacker to log in to the affected system and access sensitive data as the low-privileged user. Note: If the FMC management interface does not have public internet access, the attack surface that is associated with this vulnerability is reduced. Cisco has assigned this security advisory a Security Impact Rating (SIR) of High rather than Medium as the score indicates. The reason is that this vulnerability can be used with other Cisco Secure FMC Software vulnerabilities to elevate privileges. | Jul 29, 2026 |
| CVE-2026-20146(opens NVD record) | Medium | 5.5 | A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or delete arbitrary files. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to access sensitive files or delete arbitrary files on the affected system. | Jul 15, 2026 |
| CVE-2026-20190(opens NVD record) | High | 7.5 | A vulnerability in Cisco ISE and ISE-PIC could allow an unauthenticated, remote attacker to view sensitive information on an affected device. This vulnerability is due to improper authorization checks when a resource is accessed. An attacker could exploit this vulnerability by sending crafted traffic to an affected device. A successful exploit could allow the attacker to gain access to sensitive information, including hashed credentials that could be used in future attacks. | Jun 17, 2026 |
| CVE-2026-20181(opens NVD record) | Critical | 9.1 | A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to obtain user-level access to the underlying operating system and then elevate privileges to root. In single-node deployments, successful exploitation of this vulnerability could cause the affected ISE node to become unavailable, resulting in a denial of service (DoS) condition. In that condition, endpoints that have not already authenticated would be unable to access the network until the node is restored. | Jun 17, 2026 |
2,850 CVEs · 10 product families