Skip to content

Data collected

CVEs Live

Cisco vulnerabilities exploited in the wild

The Cisco CVEs that CISA lists as exploited, newest first. Only confirmed exploitation appears here, each with its EPSS and the CVSS as published.

Build snapshot collected · KEV catalog 2026.10.02 · EPSS of 2 Oct 2026 · not a live feed: collected once, at build time

100
flaws with confirmed attacks
7
used by ransomware
5.8%
of the whole catalog

12 vulnerabilities · newest first.Showing the entries bundled with this page while the full catalog loads.

RSS of KEV additions
  1. CVE-2026-76504Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Cisco · Catalyst SD-WAN Manager

    Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · cisco.com

    Attack probability (EPSS)

    1.57%75th pct

    KEV dates

    added due
  2. CVE-2026-76460Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Cisco · Identity Services Engine

    Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability

    Severity

    10.0CRITICALCVSS 3.1 · cisco.com

    Attack probability (EPSS)

    14.0%96th pct

    KEV dates

    added due
  3. CVE-2026-76461Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Cisco · Secure Email Gateway

    Cisco Secure Email Gateway SQL Injection Vulnerability

    Severity

    9.8CRITICALCVSS 3.1 · cisco.com

    Attack probability (EPSS)

    28.3%98th pct

    KEV dates

    added due
  4. CVE-2026-20079Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Cisco · Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management

    Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability

    Severity

    10.0CRITICALCVSS 3.1 · cisco.com

    Attack probability (EPSS)

    88.2%99.8th pct

    KEV dates

    added due
  5. CVE-2026-20349Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Cisco · Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)

    Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability

    Severity

    8.6HIGHCVSS 3.1 · cisco.com

    Attack probability (EPSS)

    1.01%62th pct

    KEV dates

    added due
  6. CVE-2026-20316Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalogransomware use: known

    Cisco · Secure Firewall Management Center (FMC)

    Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability

    Severity

    5.3MEDIUMCVSS 3.1 · cisco.com

    Attack probability (EPSS)

    35.1%98th pct

    KEV dates

    added due
  7. CVE-2008-4128Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Cisco · IOS

    Cisco IOS Cross-Site Request Forgery Vulnerability

    Severity

    8.1HIGHCVSS 3.1 · CISA-ADP

    Attack probability (EPSS)

    33.9%98th pct

    KEV dates

    added due
  8. CVE-2026-20230Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Cisco · Unified Communications Manager

    Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability

    Severity

    8.6HIGHCVSS 3.1 · cisco.com

    Attack probability (EPSS)

    88.2%99.8th pct

    KEV dates

    added due
  9. CVE-2026-20262Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Cisco · Catalyst SD-WAN Manager

    Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability

    Severity

    6.5MEDIUMCVSS 3.1 · cisco.com

    Attack probability (EPSS)

    28.2%98th pct

    KEV dates

    added due
  10. CVE-2026-20245Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Cisco · Catalyst SD-WAN Manager

    Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability

    Severity

    7.8HIGHCVSS 3.1 · cisco.com

    Attack probability (EPSS)

    25.3%98th pct

    KEV dates

    added due
  11. CVE-2026-20182Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Cisco · Catalyst SD-WAN

    Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability

    Severity

    10.0CRITICALCVSS 3.1 · cisco.com

    Attack probability (EPSS)

    91.5%99.8th pct

    KEV dates

    added due
  12. CVE-2026-20133Exploited · KEV: listed in the CISA Known Exploited Vulnerabilities catalog

    Cisco · Catalyst SD-WAN Manager

    Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

    Severity

    7.5HIGHCVSS 3.1 · NVD

    Attack probability (EPSS)

    31.8%98th pct

    KEV dates

    added due

Cisco products in the catalog

Among the most recent entries, the products that appear most often are:

  • Catalyst SD-WAN Manager4 entries
  • Identity Services Engine1 entry
  • Secure Email Gateway1 entry
  • Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management1 entry
  • Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD)1 entry
  • Secure Firewall Management Center (FMC)1 entry
  • IOS1 entry
  • Unified Communications Manager1 entry

Product names are the ones CISA uses in the catalog. To check a specific Cisco CVE that is not on this page, use the CVE lookup: it shows the record, the affected versions and the EPSS score even when the CVE is not in KEV.

Fixed versions and workarounds are published by the vendor: Cisco Security Advisories.

Other vendors

Questions

How many Cisco vulnerabilities are known to be exploited?

The CISA KEV catalog, version 2026.10.02, lists 100 Cisco vulnerabilities as of 3 Oct 2026. CISA marks 7 of them as known to be used in ransomware campaigns.

What is the most recent Cisco entry in KEV?

CVE-2026-76504 (Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability), added on 30 Sep 2026 with a due date of 3 Oct 2026 for US federal agencies, as of the collection of 3 Oct 2026.

Does this page list every Cisco CVE?

No. It lists only the Cisco CVEs that CISA has confirmed as exploited. Cisco publishes many more CVEs that are not in KEV; look up any of them by identifier in the CVE lookup to see its record and EPSS score.

In what order should Cisco vulnerabilities be patched?

Everything on this page is already confirmed as exploited, so all of it is urgent where the product is in use. Within the list, entries marked with known ransomware use and those with the highest EPSS come first in the "Risk" order; internet-facing systems should go before internal ones.

Related sections