FAIL › dossier
Cisco Systems Inc.
COMPANY FEDRAMP MARKETFedRAMP provider · · dossier confidence 80%
Cisco Systems Inc. is a major public technology vendor with a significant security track record in 2026 characterized by multiple critical zero-day vulnerabilities, particularly in SD-WAN Manager and Unified CM products, with some vulnerabilities remaining unpatched for extended periods.
PROFILE
CategoryTechnology VendorWhat they doCisco Systems Inc. is a global technology company that designs, manufactures, and sells networking hardware, software, and telecommunications equipment.Founded1984HQSan Jose, California, USAOwnershipPublic
Websitehttps://www.cisco.com ↗
SECURITY POSTURE
Cisco has demonstrated a pattern of releasing multiple critical and high-severity zero-day vulnerabilities in 2026, particularly within the SD-WAN Manager product line, with some vulnerabilities remaining unpatched for extended periods.
Notable failures
- CVE-2026-20230: Cisco Unified CM SSRF vulnerability allowing unauthenticated root escalation
- CVE-2026-20182: Cisco Catalyst SD-WAN Controller bypass authentication for admin privileges
- CVE-2026-20131: Cisco FMC and SCC critical RCE via Java deserialization
- CVE-2026-20245: Cisco SD-WAN Manager zero-day command injection with no patch available
- CVE-2026-20133: Cisco FMC and SCC critical RCE via untrusted data deserialization
- CVE-2026-20128: Cisco Catalyst SD-WAN Manager storing passwords in recoverable format
Patterns: Repeated unpatched zero-day vulnerabilities in SD-WAN Manager; High-severity RCE vulnerabilities in Cisco Unified CM and FMC; Authentication bypass vulnerabilities in SD-WAN Controller
FAILURE HISTORY · 60
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2026-02-25 | CVE-2022-20775 | high | Cisco SD-WAN CLI exposed to path traversal, allowing local attackers to escalate privileges and execute commands as root. |
| 2026-01-21 | CVE-2026-20045 | high | Cisco UC products allow remote code execution. |
| 2025-07-28 | CVE-2025-20337 | high | Cisco ISE API RCE |
| 2026-07-29 | CVE-2026-20316 | high | Cisco FMC shipped with a hardcoded password allowing unauthenticated remote login to sensitive data. |
| 2026-06-25 | CVE-2026-20230 | high | Cisco Unified CM SSRF vulnerability allows unauthenticated remote attackers to write files to the OS and escalate to root. |
| 2026-05-14 | CVE-2026-20182 | high | Cisco Catalyst SD-WAN Controller allows unauthenticated remote attackers to bypass authentication and gain administrative privileges. |
| 2026-03-19 | CVE-2026-20131 | critical | Cisco FMC and SCC allow unauthenticated remote attackers to execute arbitrary Java code as root via deserialization of untrusted data. |
| 2023-09-13 | CVE-2023-20269 | critical | Cisco ASA and Firepower Threat Defense suffered an unpatched unauthorized access vulnerability allowing remote brute-force attacks and clientless SSL VPN sessions. |
| 2022-10-24 | CVE-2020-3433 | critical | Cisco AnyConnect's IPC channel allowed attackers with valid Windows credentials to execute SYSTEM-level code via DLL hijacking. |
| 2022-10-24 | CVE-2020-3153 | critical | Cisco AnyConnect for Windows mishandles directory paths, allowing attackers with valid credentials to copy malicious files to arbitrary locations with system-level privileges. |
| 2022-03-25 | CVE-2017-3881 | high | Cisco IOS and IOS XE suffered a remote code execution vulnerability in the Cluster Management Protocol allowing unauthenticated attackers to execute elevated code or reload devices. |
| 2022-03-25 | CVE-2018-0125 | high | Cisco VPN routers had an unauthenticated remote code execution flaw in their web interface allowing attackers full system control. |
| 2022-03-03 | CVE-2022-20700 | high | Cisco Small Business RV routers suffered a stack-based buffer overflow allowing remote code execution and privilege escalation. |
| 2022-03-03 | CVE-2022-20699 | high | Cisco Small Business RV routers suffered a stack-based buffer overflow allowing remote code execution and privilege escalation. |
| 2022-03-03 | CVE-2018-0151 | high | An unauthenticated remote attacker could execute arbitrary code with elevated privileges in Cisco IOS and IOS XE QoS subsystems. |
| 2021-11-03 | CVE-2018-0171 | high | Cisco IOS and IOS XE Smart Install allows unauthenticated remote attackers to execute code, causing device reloads, DoS, or full compromise. |
| 2021-11-03 | CVE-2020-3118 | high | Cisco IOS XR improperly validates CDP input, allowing adjacent attackers to execute admin code or reload devices. |
| 2024-02-15 | CVE-2020-3259 | critical | Cisco ASA/FTD memory disclosure flaw leaked secrets via invalid URL parsing in specific AnyConnect/WebVPN setups. |
| 2022-03-25 | CVE-2018-0147 | high | Cisco ACS suffered an unpatched Java deserialization vulnerability allowing remote command execution, now on CISA's KEV list. |
| 2022-03-03 | CVE-2017-6740 | high | An authenticated remote attacker could execute code on Cisco IOS and IOS XE devices via an SNMP vulnerability. |
| 2022-03-03 | CVE-2017-12240 | high | An unauthenticated remote attacker could execute arbitrary code and gain full control of Cisco IOS and IOS XE systems via a DHCP relay subsystem vulnerability. |
| 2022-03-03 | CVE-2017-6736 | high | Cisco IOS and IOS XE software contained an SNMP remote code execution vulnerability allowing authenticated attackers to execute arbitrary code remotely. |
| 2022-03-03 | CVE-2017-6738 | high | Cisco IOS and IOS XE SNMP subsystems allowed authenticated remote attackers to execute arbitrary code via CVE-2017-6738. |
| 2022-03-03 | CVE-2017-6739 | high | An authenticated remote attacker could execute code or reload a Cisco IOS/XE device via an SNMP vulnerability. |
| 2022-03-03 | CVE-2017-6743 | high | An authenticated remote attacker could execute code via the SNMP subsystem in Cisco IOS and IOS XE software. |
| 2022-03-03 | CVE-2018-0167 | high | An unauthenticated adjacent attacker could exploit a buffer overflow in Cisco IOS XR LLDP to execute arbitrary code or cause a DoS. |
| 2022-03-03 | CVE-2018-0175 | high | A format string vulnerability in Cisco IOS XR/IOS XE LLDP allowed unauthenticated adjacent attackers to execute arbitrary code with elevated privileges. |
| 2022-03-03 | CVE-2018-0180 | high | A decades-old Cisco IOS DoS vulnerability (CVE-2018-0180) remains actively exploited in the wild, proving that unpatched legacy hardware is a critical compliance failure. |
| 2022-03-03 | CVE-2019-1652 | high | Cisco Small Business RV320/RV325 routers had an improper input validation flaw allowing authenticated remote attackers to execute arbitrary commands. |
| 2022-03-03 | CVE-2022-20701 | high | Cisco Small Business RV routers suffered a stack-based buffer overflow allowing remote code execution and privilege escalation. |
| 2022-03-03 | CVE-2022-20703 | high | Cisco Small Business RV routers suffered a stack-based buffer overflow allowing arbitrary code execution and privilege escalation. |
| 2022-03-03 | CVE-2022-20708 | high | Cisco Small Business RV Series routers suffered a stack-based buffer overflow allowing arbitrary code execution and privilege escalation. |
| 2021-11-03 | CVE-2020-3161 | high | Cisco IP phones had an unpatched remote code execution vulnerability exploited in the wild, allowing attackers to gain root access. |
| 2021-11-03 | CVE-2021-1497 | high | Cisco HyperFlex HX installer VM suffered a command injection flaw allowing root-level code execution. |
| 2021-11-03 | CVE-2021-1498 | high | Cisco HyperFlex HX installer VM had insufficient input validation allowing command execution as tomcat8 user. |
| 2022-05-24 | CVE-2016-6366 | high | Cisco ASA's SNMP code had a buffer overflow allowing remote code execution or system reloads. |
| 2022-05-23 | CVE-2022-20821 | high | Cisco IOS XR software health check opens TCP port 6379 by default, allowing attackers to access the Redis instance running within the NOSi container. |
| 2022-03-03 | CVE-2017-6744 | high | Cisco IOS software contained an SNMP remote code execution vulnerability allowing authenticated attackers to execute arbitrary code or reload systems via crafted packets. |
| 2022-03-03 | CVE-2017-6737 | high | Cisco IOS and IOS XE software suffered a remote code execution vulnerability in its SNMP subsystem that allowed authenticated attackers to execute arbitrary code remotely. |
| 2026-02-25 | CVE-2026-20127 | high | Cisco's SD-WAN devices had an unpatched authentication bypass flaw allowing remote attackers to gain admin access. |
| 2025-12-17 | CVE-2025-20393 | high | Cisco gear with AsyncOS, Web Manager, and Secure Email suffered remote code execution due to improper input validation, allowing root access on affected systems. |
| 2025-09-29 | CVE-2025-20352 | high | Cisco IOS and IOS XE SNMP RCE DoS |
| 2025-09-25 | CVE-2025-20333 | high | Cisco ASA and FTD suffered remote code execution due to a buffer overflow, actively exploited in the wild. |
| 2025-09-25 | CVE-2025-20362 | high | Cisco firewalls with missing auth vuln exploited in wild |
| 2025-07-28 | CVE-2025-20281 | high | Cisco ISE API flaw allows RCE and root privileges |
| 2023-10-23 | CVE-2023-20273 | high | Cisco IOS XE Web UI Command Injection Vulnerability |
| 2023-10-16 | CVE-2023-20198 | high | Cisco IOS XE Web UI privilege escalation vulnerability allows remote, unauthenticated attackers to gain control of devices. |
| 2023-10-10 | CVE-2023-20109 | high | Cisco IOS and IOS XE Group Encrypted Transport VPN out-of-bounds write vulnerability allows remote code execution. |
| 2023-05-19 | CVE-2016-6415 | high | Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability |
| 2023-05-19 | CVE-2004-1464 | high | Cisco IOS Denial-of-Service Vulnerability |
| 2023-04-19 | CVE-2017-6742 | high | Cisco IOS and IOS XE SNMP RCE vulnerability exploited in the wild |
| 2022-03-03 | CVE-2017-6627 | high | Cisco IOS and IOS XE software suffered a high-severity unauthenticated remote denial-of-service vulnerability in UDP packet processing that was actively exploited in the wild. |
| 2022-03-03 | CVE-2018-0174 | high | Cisco IOS XE DHCP option 82 improper input validation allows denial-of-service via unpatched, actively exploited vulnerability. |
| 2022-03-03 | CVE-2018-0173 | high | Cisco IOS and IOS XE Software suffered an unpatched improper input validation vulnerability in DHCPv4 packet handling that caused denial-of-service and was actively exploited in the wild. |
| 2021-11-03 | CVE-2020-3580 | critical | Cisco ASA/FTD devices were vulnerable to XSS, actively exploited and linked to ransomware attacks. |
| 2026-08-11 | CVE-2026-20349 | high | Cisco ASA/FTD devices have an unpatched heap inspection vulnerability allowing remote denial of service. |
| 2026-07-13 | CVE-2008-4128 | high | Cisco IOS 12.4 devices are actively exploited in the wild via a cross-site request forgery vulnerability enabling remote command execution. |
| 2026-04-20 | CVE-2026-20128 | high | Cisco Catalyst SD-WAN Manager stores passwords in a recoverable format, allowing local attackers to escalate privileges by reading credential files. |
| 2025-03-03 | CVE-2023-20118 | high | Cisco Small Business routers have a command injection vulnerability actively exploited by attackers to gain root access remotely. |
| 2022-06-08 | CVE-2019-15271 | high | Cisco RV Series routers had a remotely exploitable deserialization vulnerability allowing code execution with root privileges, actively exploited in the wild. |
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.70
…
synthesissevere-fallout-0.70
…
synthesissevere-fallout-0.70
Significant concerns raised regarding Cisco's security practices due to the vulnerability and subsequent breach.
synthesisnegative-0.60
Acknowledged vulnerability, potential for significant impact.
synthesissevere-fallout-0.70
…
synthesissevere-fallout-0.70
Criticized for validation failure
synthesissevere-fallout-0.70
…
synthesissevere-fallout-0.70
…
synthesissevere-fallout-0.70
…
synthesissevere-fallout-0.70
…
synthesissevere-fallout-0.70
…
synthesissevere-fallout-0.60
Cisco faced criticism for a critical directory traversal flaw in its ASA/FTD web services, allowing unauthenticated attackers to read/delete sensitive files, though the impact was contained to the web
synthesissevere-fallout-0.60
Criticism for severe root-privilege command injection flaw in enterprise NFV infrastructure, though no direct press condemnation found in provided sources.
synthesissevere-fallout-0.60
Vulnerability allows unauthenticated remote access to admin VNC console; insufficient auth mechanism; no praise for handling.
synthesissevere-fallout-0.60
Cisco faced severe fallout due to a critical remote code execution vulnerability in its SSL VPN functionality, allowing unauthenticated attackers to reload systems or execute arbitrary code, impacting
negative
"Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the root user."
negative
"Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers contain improper access controls for URLs. Exploitation could allow an attacker to download the router configuration or detailed diagnostic information."
FEDRAMP CATALOG PRODUCTS · 7
| PRODUCT | STATUS | IMPACT |
|---|---|---|
| Cisco Cloudlock for Government | Authorized | Moderate |
| Cisco Meraki for Government | In Process | Moderate |
| Cisco SD-WAN for Government | In Process | Moderate |
| Cisco Umbrella for Government | In Process | Moderate |
| Cisco Unified Communications Manager Cloud for Government (Cisco UCM Cloud for Government) | Authorized | Moderate |
| WebEx Contact Center Enterprise for Government (WxCCE-G) | In Process | Moderate |
| Webex for Government | Authorized | Moderate |
DOSSIER SOURCES
- Cisco - Wikipedia · en.wikipedia.org
- Cisco Systems | History & Facts | Britannica Money · www.britannica.com
- CISCO SYSTEMS, INC. (CSCO, US17275R1023) - Company Profile · financialdata.net
- Vulnerability Reports - Latest network security threats and zeroday ... · talosintelligence.com
- Cisco SD-WAN Manager Hit by 7th Zero-Day of 2026, No Patch · dailysecurityreview.com
- Secure Access Change Log for 2026-06-26 to 2026-07-02 · community.cisco.com
Open questions: Cisco's remediation timeline for the 2026-06-25 and 2026-05-14 vulnerabilities · Impact of these vulnerabilities on active CMMC compliance programs
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-13 14:07:37.641701+00:00