Secure Remote Access / VPN · head-to-head
Cisco vs Palo Alto Networks
SSL/IPsec VPN gateways and ZTNA appliances. Counts are scoped to this segment and the selected published-date window. Cisco carries 7.0× the disclosed CVE volume of Palo Alto Networks. Volume reflects disclosure practice and install base as much as code quality — read it with the severity mix. Sourced from the NIST NVD; lower counts indicate a smaller disclosed vulnerability surface — not necessarily lower risk.
Disclosure record
Bars are normalized per row to the larger value; the leading count is emphasized.
| Cisco | Metric | Palo Alto Networks | ||
|---|---|---|---|---|
| 28 | Total CVEs | 4 | ||
| 2 | Critical | 0 | ||
| 9 | High | 2 | ||
| 17 | Medium | 2 | ||
| 0 | Low | 0 | ||
| 230 | Open in latest | 13 |
Risk profile
Each severity band as a share of the vendor's own total — strips out raw volume so the profiles compare directly.
Cisco
7.1% critical- Critical
- 27.1%
- High
- 932.1%
- Medium
- 1760.7%
- Low
- 00.0%
Palo Alto Networks
0.0% critical- Critical
- 00.0%
- High
- 250.0%
- Medium
- 250.0%
- Low
- 00.0%
Recent activity
Latest in-window disclosures per vendor, newest first. Each ID links to its NVD record.
Cisco
| CVE | Severity | CVSS | Published |
|---|---|---|---|
| CVE-2026-20349(opens NVD record) | High | 8.6 | Aug 11, 2026 |
| CVE-2026-20025(opens NVD record) | Medium | 6.8 | Mar 4, 2026 |
| CVE-2026-20024(opens NVD record) | Medium | 6.8 | Mar 4, 2026 |
| CVE-2026-20023(opens NVD record) | Medium | 6.1 | Mar 4, 2026 |
| CVE-2026-20022(opens NVD record) | Medium | 6.1 | Mar 4, 2026 |
| CVE-2026-20021(opens NVD record) | Medium | 4.3 | Mar 4, 2026 |
Palo Alto Networks
| CVE | Severity | CVSS | Published |
|---|---|---|---|
| CVE-2026-0267(opens NVD record) | Medium | 5.5 | Jun 10, 2026 |
| CVE-2026-0251(opens NVD record) | High | 7.8 | May 13, 2026 |
| CVE-2026-0250(opens NVD record) | High | 8.1 | May 13, 2026 |
| CVE-2026-0249(opens NVD record) | Medium | 6.5 | May 13, 2026 |
Track new CVEs for these vendors
Get an email the moment a new vulnerability is disclosed for the products you rely on.