FAIL › dossier
Cisco Systems Inc.
COMPANY FEDRAMP MARKETFedRAMP provider · · dossier confidence 80%
Cisco Systems Inc. is a major public technology vendor with a significant security track record in 2026 characterized by multiple critical zero-day vulnerabilities, particularly in SD-WAN Manager and Unified CM products, with some vulnerabilities remaining unpatched for extended periods.
PROFILE
CategoryTechnology VendorWhat they doCisco Systems Inc. is a global technology company that designs, manufactures, and sells networking hardware, software, and telecommunications equipment.Founded1984HQSan Jose, California, USAOwnershipPublic
Websitehttps://www.cisco.com ↗
SECURITY POSTURE
Cisco has demonstrated a pattern of releasing multiple critical and high-severity zero-day vulnerabilities in 2026, particularly within the SD-WAN Manager product line, with some vulnerabilities remaining unpatched for extended periods.
Notable failures
- CVE-2026-20230: Cisco Unified CM SSRF vulnerability allowing unauthenticated root escalation
- CVE-2026-20182: Cisco Catalyst SD-WAN Controller bypass authentication for admin privileges
- CVE-2026-20131: Cisco FMC and SCC critical RCE via Java deserialization
- CVE-2026-20245: Cisco SD-WAN Manager zero-day command injection with no patch available
- CVE-2026-20133: Cisco FMC and SCC critical RCE via untrusted data deserialization
- CVE-2026-20128: Cisco Catalyst SD-WAN Manager storing passwords in recoverable format
Patterns: Repeated unpatched zero-day vulnerabilities in SD-WAN Manager; High-severity RCE vulnerabilities in Cisco Unified CM and FMC; Authentication bypass vulnerabilities in SD-WAN Controller
FAILURE HISTORY · 60
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-02-25 | CVE-2022-20775 | high | Cisco SD-WAN CLI exposed to path traversal, allowing local attackers to escalate privileges and execute commands as root. |
| 2026-01-21 | CVE-2026-20045 | high | Cisco UC products allow remote code execution. |
| 2025-07-28 | CVE-2025-20337 | high | Cisco ISE API RCE |
| 2026-07-29 | CVE-2026-20316 | high | Cisco FMC shipped with a hardcoded password allowing unauthenticated remote login to sensitive data. |
| 2026-06-25 | CVE-2026-20230 | high | Cisco Unified CM SSRF vulnerability allows unauthenticated remote attackers to write files to the OS and escalate to root. |
| 2026-05-14 | CVE-2026-20182 | high | Cisco Catalyst SD-WAN Controller allows unauthenticated remote attackers to bypass authentication and gain administrative privileges. |
| 2026-03-19 | CVE-2026-20131 | critical | Cisco FMC and SCC allow unauthenticated remote attackers to execute arbitrary Java code as root via deserialization of untrusted data. |
| 2023-09-13 | CVE-2023-20269 | critical | Cisco ASA and Firepower Threat Defense suffered an unpatched unauthorized access vulnerability allowing remote brute-force attacks and clientless SSL VPN sessions. |
| 2022-10-24 | CVE-2020-3433 | critical | Cisco AnyConnect's IPC channel allowed attackers with valid Windows credentials to execute SYSTEM-level code via DLL hijacking. |
| 2022-10-24 | CVE-2020-3153 | critical | Cisco AnyConnect for Windows mishandles directory paths, allowing attackers with valid credentials to copy malicious files to arbitrary locations with system-level privileges. |
| 2024-02-15 | CVE-2020-3259 | critical | Cisco ASA/FTD memory disclosure flaw leaked secrets via invalid URL parsing in specific AnyConnect/WebVPN setups. |
| 2022-05-24 | CVE-2016-6366 | high | Cisco ASA's SNMP code had a buffer overflow allowing remote code execution or system reloads. |
| 2022-05-23 | CVE-2022-20821 | high | Cisco IOS XR software health check opens TCP port 6379 by default, allowing attackers to access the Redis instance running within the NOSi container. |
| 2026-02-25 | CVE-2026-20127 | high | Cisco's SD-WAN devices had an unpatched authentication bypass flaw allowing remote attackers to gain admin access. |
| 2025-12-17 | CVE-2025-20393 | high | Cisco gear with AsyncOS, Web Manager, and Secure Email suffered remote code execution due to improper input validation, allowing root access on affected systems. |
| 2025-09-29 | CVE-2025-20352 | high | Cisco IOS and IOS XE SNMP RCE DoS |
| 2025-09-25 | CVE-2025-20362 | high | Cisco firewalls with missing auth vuln exploited in wild |
| 2025-09-25 | CVE-2025-20333 | high | Cisco ASA and FTD suffered remote code execution due to a buffer overflow, actively exploited in the wild. |
| 2025-07-28 | CVE-2025-20281 | high | Cisco ISE API flaw allows RCE and root privileges |
| 2023-10-23 | CVE-2023-20273 | high | Cisco IOS XE Web UI Command Injection Vulnerability |
| 2023-10-16 | CVE-2023-20198 | high | Cisco IOS XE Web UI privilege escalation vulnerability allows remote, unauthenticated attackers to gain control of devices. |
| 2023-10-10 | CVE-2023-20109 | high | Cisco IOS and IOS XE Group Encrypted Transport VPN out-of-bounds write vulnerability allows remote code execution. |
| 2023-05-19 | CVE-2016-6415 | high | Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability |
| 2023-05-19 | CVE-2004-1464 | high | Cisco IOS Denial-of-Service Vulnerability |
| 2023-04-19 | CVE-2017-6742 | high | Cisco IOS and IOS XE SNMP RCE vulnerability exploited in the wild |
| 2021-11-03 | CVE-2020-3580 | critical | Cisco ASA/FTD devices were vulnerable to XSS, actively exploited and linked to ransomware attacks. |
| 2026-07-13 | CVE-2008-4128 | high | Cisco IOS 12.4 devices are actively exploited in the wild via a cross-site request forgery vulnerability enabling remote command execution. |
| 2026-04-20 | CVE-2026-20128 | high | Cisco Catalyst SD-WAN Manager stores passwords in a recoverable format, allowing local attackers to escalate privileges by reading credential files. |
| 2025-03-03 | CVE-2023-20118 | high | Cisco Small Business routers have a command injection vulnerability actively exploited by attackers to gain root access remotely. |
| 2022-06-08 | CVE-2019-15271 | high | Cisco RV Series routers had a remotely exploitable deserialization vulnerability allowing code execution with root privileges, actively exploited in the wild. |
| 2022-05-24 | CVE-2016-6367 | high | Cisco ASA CLI parser flaw allowed authenticated local attackers to cause DoS or execute code. |
| 2022-03-25 | CVE-2017-3881 | high | A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges. |
| 2022-03-25 | CVE-2018-0125 | high | A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full control of an affected system. |
| 2022-03-25 | CVE-2018-0147 | high | A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affec |
| 2022-03-03 | CVE-2017-6737 | high | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code. |
| 2022-03-03 | CVE-2017-6736 | high | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code. |
| 2022-03-03 | CVE-2017-12240 | high | The Dynamic Host Configuration Protocol (DHCP) relay subsystem of Cisco IOS and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system. |
| 2022-03-03 | CVE-2017-6738 | high | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code. |
| 2022-03-03 | CVE-2017-6739 | high | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. |
| 2022-03-03 | CVE-2017-6740 | high | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. |
| 2022-03-03 | CVE-2022-20700 | high | A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsi |
| 2022-03-03 | CVE-2022-20699 | high | A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsi |
| 2022-03-03 | CVE-2019-1652 | high | A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands. |
| 2022-03-03 | CVE-2017-6743 | high | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code. |
| 2022-03-03 | CVE-2018-0175 | high | Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with |
| 2022-03-03 | CVE-2017-6744 | high | The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS 1 contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities |
| 2022-03-03 | CVE-2018-0167 | high | There is a buffer overflow vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software which could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute a |
| 2022-03-03 | CVE-2018-0151 | high | A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges. |
| 2022-03-03 | CVE-2022-20708 | high | A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsi |
| 2022-03-03 | CVE-2022-20703 | high | A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsi |
| 2022-03-03 | CVE-2022-20701 | high | A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsi |
| 2021-11-03 | CVE-2021-1498 | high | Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the tomcat8 user. |
| 2021-11-03 | CVE-2021-1497 | high | Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the root user. |
| 2021-11-03 | CVE-2018-0171 | high | Cisco IOS and IOS XE Software improperly validates packet data, allowing an unauthenticated, remote attacker to trigger a reload of an affected device, cause a denial-of-service (DoS) condition, or perform code execution on the affected device. |
| 2021-11-03 | CVE-2020-3161 | high | Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root privileges or cause a denial-of-service (DoS) condition. |
| 2025-03-31 | CVE-2024-20439 | high | Cisco's Smart Licensing Utility shipped with hardcoded credentials, allowing unauthorized remote access and administrative control. |
| 2022-03-25 | CVE-2009-2055 | high | Cisco IOS XR,when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS). |
| 2022-03-25 | CVE-2010-3035 | high | Cisco IOS XR, when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS). |
| 2022-03-25 | CVE-2015-0666 | high | Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) allows remote attackers to read arbitrary files. |
| 2022-03-03 | CVE-2018-0154 | high | A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition. |
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.70
…
synthesissevere-fallout-0.70
Significant concerns raised regarding Cisco's security practices due to the vulnerability and subsequent breach.
synthesisnegative-0.60
Acknowledged vulnerability, potential for significant impact.
synthesissevere-fallout-0.70
…
synthesissevere-fallout-0.70
Criticized for validation failure
synthesissevere-fallout-0.70
…
synthesissevere-fallout-0.70
…
synthesissevere-fallout-0.70
…
synthesissevere-fallout-0.70
…
synthesissevere-fallout-0.70
…
synthesissevere-fallout-0.70
…
Highlights validation failure
"Cisco IOS XR improperly validates string input..."
negative
"Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the root user."
negative
"Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers contain improper access controls for URLs. Exploitation could allow an attacker to download the router configuration or detailed diagnostic information."
FEDRAMP CATALOG PRODUCTS · 7
| PRODUCT | STATUS | IMPACT |
|---|---|---|
| Cisco Cloudlock for Government | Authorized | Moderate |
| Cisco Meraki for Government | In Process | Moderate |
| Cisco SD-WAN for Government | In Process | Moderate |
| Cisco Umbrella for Government | In Process | Moderate |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) | Authorized | Moderate |
| WebEx Contact Center Enterprise for Government (WxCCE-G) | In Process | Moderate |
| Webex for Government | Authorized | Moderate |
DOSSIER SOURCES
- Cisco - Wikipedia · en.wikipedia.org
- Cisco Systems | History & Facts | Britannica Money · www.britannica.com
- CISCO SYSTEMS, INC. (CSCO, US17275R1023) - Company Profile · financialdata.net
- Vulnerability Reports - Latest network security threats and zeroday ... · talosintelligence.com
- Cisco SD-WAN Manager Hit by 7th Zero-Day of 2026, No Patch · dailysecurityreview.com
- Secure Access Change Log for 2026-06-26 to 2026-07-02 · community.cisco.com
Open questions: Cisco's remediation timeline for the 2026-06-25 and 2026-05-14 vulnerabilities · Impact of these vulnerabilities on active CMMC compliance programs
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-13 14:07:37.641701+00:00