Cyber Resilience

← All vendors

Cisco

CPE vendor key: cisco · 737 CVEs published in the last 24 months.

CVEs (365 d)
330
▲ +56 vs prior 30d
Avg CVSS (365 d)
6.59
over 330 CVEs
Avg EPSS pct (365 d)
0.28
higher = more likely exploited
KEV hit rate (365 d)
4.8%
16 of 330 added to CISA KEV
LLM-credited CVEs
0
none detected

Monthly CVE volume — last 24 months

2024202520260103
Each point is one calendar month. Bars in the severity card to the right slice the same volume by CVSS band.

Severity mix

CritHighMedLow
Stacked by CVSS band (Critical / High / Medium / Low) using the best available metric per CVE.

Top affected products (24 mo)

secure_firewall_threat_defense
67
ios_xe
48
adaptive_security_appliance_software
48
identity_services_engine
46
secure_firewall_management_center
37
catalyst_sd-wan_manager
36
ios_xr
26
ios
16
roomos
16
unified_contact_center_express
16
Distinct CVEs that include each product in their CPE configuration.

Top CWEs (24 mo)

CWE-79
92
CWE-78
34
CWE-284
29
CWE-20
29
CWE-200
21
CWE-22
21
CWE-787
19
CWE-77
16
CWE-120
16
CWE-862
15
Distinct CVEs assigned each weakness.

Recent CISA KEV adds (last 12 months)

AddedCVEProductKEV name
2026-08-11CVE-2026-20349Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability
2026-07-29CVE-2026-20316Secure Firewall Management Center (FMC)Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
2026-07-13CVE-2008-4128IOSCisco IOS Cross-Site Request Forgery Vulnerability
2026-06-25CVE-2026-20230Unified Communications ManagerCisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability
2026-06-15CVE-2026-20262Catalyst SD-WAN ManagerCisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability
2026-06-09CVE-2026-20245Catalyst SD-WAN ManagerCisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability
2026-05-14CVE-2026-20182Catalyst SD-WANCisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
2026-04-20CVE-2026-20133Catalyst SD-WAN ManagerCisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
2026-04-20CVE-2026-20128Catalyst SD-WAN ManagerCisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability
2026-04-20CVE-2026-20122Catalyst SD-WAN MangerCisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability
2026-03-19CVE-2026-20131Secure Firewall Management Center (FMC)Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability
2026-02-25CVE-2026-20127Catalyst SD-WAN Controller and ManagerCisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability
2026-02-25CVE-2022-20775SD-WANCisco SD-WAN Path Traversal Vulnerability
2026-01-21CVE-2026-20045Unified Communications ManagerCisco Unified Communications Products Code Injection Vulnerability
2025-12-17CVE-2025-20393Multiple ProductsCisco Multiple Products Improper Input Validation Vulnerability
2025-09-29CVE-2025-20352IOS and IOS XECisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability
2025-09-25CVE-2025-20362Secure Firewall Adaptive Security Appliance and Secure Firewall Threat DefenseCisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability
2025-09-25CVE-2025-20333Secure Firewall Adaptive Security Appliance and Secure Firewall Threat DefenseCisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability
Filtered to KEV entries whose CISA vendor or product name matches this vendor exactly, to drop cross-OS noise (e.g. third-party Windows apps that CPE-map to Microsoft).

Generated 23 August 2026 00:24 UTC .