Skip to content
COOEY

FAIL › dossier

Cisco Systems Inc.

COMPANY FEDRAMP MARKET

FedRAMP provider · · dossier confidence 80%

Cisco Systems Inc. is a major public technology vendor with a significant security track record in 2026 characterized by multiple critical zero-day vulnerabilities, particularly in SD-WAN Manager and Unified CM products, with some vulnerabilities remaining unpatched for extended periods.

PROFILE
CategoryTechnology VendorWhat they doCisco Systems Inc. is a global technology company that designs, manufactures, and sells networking hardware, software, and telecommunications equipment.Founded1984HQSan Jose, California, USAOwnershipPublic Websitehttps://www.cisco.com ↗
SECURITY POSTURE

Cisco has demonstrated a pattern of releasing multiple critical and high-severity zero-day vulnerabilities in 2026, particularly within the SD-WAN Manager product line, with some vulnerabilities remaining unpatched for extended periods.

Notable failures
  • CVE-2026-20230: Cisco Unified CM SSRF vulnerability allowing unauthenticated root escalation
  • CVE-2026-20182: Cisco Catalyst SD-WAN Controller bypass authentication for admin privileges
  • CVE-2026-20131: Cisco FMC and SCC critical RCE via Java deserialization
  • CVE-2026-20245: Cisco SD-WAN Manager zero-day command injection with no patch available
  • CVE-2026-20133: Cisco FMC and SCC critical RCE via untrusted data deserialization
  • CVE-2026-20128: Cisco Catalyst SD-WAN Manager storing passwords in recoverable format
Patterns: Repeated unpatched zero-day vulnerabilities in SD-WAN Manager; High-severity RCE vulnerabilities in Cisco Unified CM and FMC; Authentication bypass vulnerabilities in SD-WAN Controller
FAILURE HISTORY · 60
DATEEVENTSEVSUMMARY
2026-02-25 CVE-2022-20775 high Cisco SD-WAN CLI exposed to path traversal, allowing local attackers to escalate privileges and execute commands as root.
2026-01-21 CVE-2026-20045 high Cisco UC products allow remote code execution.
2025-07-28 CVE-2025-20337 high Cisco ISE API RCE
2026-07-29 CVE-2026-20316 high Cisco FMC shipped with a hardcoded password allowing unauthenticated remote login to sensitive data.
2026-06-25 CVE-2026-20230 high Cisco Unified CM SSRF vulnerability allows unauthenticated remote attackers to write files to the OS and escalate to root.
2026-05-14 CVE-2026-20182 high Cisco Catalyst SD-WAN Controller allows unauthenticated remote attackers to bypass authentication and gain administrative privileges.
2026-03-19 CVE-2026-20131 critical Cisco FMC and SCC allow unauthenticated remote attackers to execute arbitrary Java code as root via deserialization of untrusted data.
2023-09-13 CVE-2023-20269 critical Cisco ASA and Firepower Threat Defense suffered an unpatched unauthorized access vulnerability allowing remote brute-force attacks and clientless SSL VPN sessions.
2022-10-24 CVE-2020-3433 critical Cisco AnyConnect's IPC channel allowed attackers with valid Windows credentials to execute SYSTEM-level code via DLL hijacking.
2022-10-24 CVE-2020-3153 critical Cisco AnyConnect for Windows mishandles directory paths, allowing attackers with valid credentials to copy malicious files to arbitrary locations with system-level privileges.
2024-02-15 CVE-2020-3259 critical Cisco ASA/FTD memory disclosure flaw leaked secrets via invalid URL parsing in specific AnyConnect/WebVPN setups.
2022-05-24 CVE-2016-6366 high Cisco ASA's SNMP code had a buffer overflow allowing remote code execution or system reloads.
2022-05-23 CVE-2022-20821 high Cisco IOS XR software health check opens TCP port 6379 by default, allowing attackers to access the Redis instance running within the NOSi container.
2026-02-25 CVE-2026-20127 high Cisco's SD-WAN devices had an unpatched authentication bypass flaw allowing remote attackers to gain admin access.
2025-12-17 CVE-2025-20393 high Cisco gear with AsyncOS, Web Manager, and Secure Email suffered remote code execution due to improper input validation, allowing root access on affected systems.
2025-09-29 CVE-2025-20352 high Cisco IOS and IOS XE SNMP RCE DoS
2025-09-25 CVE-2025-20362 high Cisco firewalls with missing auth vuln exploited in wild
2025-09-25 CVE-2025-20333 high Cisco ASA and FTD suffered remote code execution due to a buffer overflow, actively exploited in the wild.
2025-07-28 CVE-2025-20281 high Cisco ISE API flaw allows RCE and root privileges
2023-10-23 CVE-2023-20273 high Cisco IOS XE Web UI Command Injection Vulnerability
2023-10-16 CVE-2023-20198 high Cisco IOS XE Web UI privilege escalation vulnerability allows remote, unauthenticated attackers to gain control of devices.
2023-10-10 CVE-2023-20109 high Cisco IOS and IOS XE Group Encrypted Transport VPN out-of-bounds write vulnerability allows remote code execution.
2023-05-19 CVE-2016-6415 high Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability
2023-05-19 CVE-2004-1464 high Cisco IOS Denial-of-Service Vulnerability
2023-04-19 CVE-2017-6742 high Cisco IOS and IOS XE SNMP RCE vulnerability exploited in the wild
2021-11-03 CVE-2020-3580 critical Cisco ASA/FTD devices were vulnerable to XSS, actively exploited and linked to ransomware attacks.
2026-07-13 CVE-2008-4128 high Cisco IOS 12.4 devices are actively exploited in the wild via a cross-site request forgery vulnerability enabling remote command execution.
2026-04-20 CVE-2026-20128 high Cisco Catalyst SD-WAN Manager stores passwords in a recoverable format, allowing local attackers to escalate privileges by reading credential files.
2025-03-03 CVE-2023-20118 high Cisco Small Business routers have a command injection vulnerability actively exploited by attackers to gain root access remotely.
2022-06-08 CVE-2019-15271 high Cisco RV Series routers had a remotely exploitable deserialization vulnerability allowing code execution with root privileges, actively exploited in the wild.
2022-05-24 CVE-2016-6367 high Cisco ASA CLI parser flaw allowed authenticated local attackers to cause DoS or execute code.
2022-03-25 CVE-2017-3881 high A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges.
2022-03-25 CVE-2018-0125 high A vulnerability in the web interface of the Cisco VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code as root and gain full control of an affected system.
2022-03-25 CVE-2018-0147 high A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affec
2022-03-03 CVE-2017-6737 high The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.
2022-03-03 CVE-2017-6736 high The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.
2022-03-03 CVE-2017-12240 high The Dynamic Host Configuration Protocol (DHCP) relay subsystem of Cisco IOS and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system.
2022-03-03 CVE-2017-6738 high The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.
2022-03-03 CVE-2017-6739 high The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.
2022-03-03 CVE-2017-6740 high The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.
2022-03-03 CVE-2022-20700 high A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsi
2022-03-03 CVE-2022-20699 high A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsi
2022-03-03 CVE-2019-1652 high A vulnerability in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker with administrative privileges on an affected device to execute arbitrary commands.
2022-03-03 CVE-2017-6743 high The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code.
2022-03-03 CVE-2018-0175 high Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with
2022-03-03 CVE-2017-6744 high The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS 1 contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities
2022-03-03 CVE-2018-0167 high There is a buffer overflow vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software which could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute a
2022-03-03 CVE-2018-0151 high A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges.
2022-03-03 CVE-2022-20708 high A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsi
2022-03-03 CVE-2022-20703 high A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsi
2022-03-03 CVE-2022-20701 high A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsi
2021-11-03 CVE-2021-1498 high Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the tomcat8 user.
2021-11-03 CVE-2021-1497 high Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the root user.
2021-11-03 CVE-2018-0171 high Cisco IOS and IOS XE Software improperly validates packet data, allowing an unauthenticated, remote attacker to trigger a reload of an affected device, cause a denial-of-service (DoS) condition, or perform code execution on the affected device.
2021-11-03 CVE-2020-3161 high Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root privileges or cause a denial-of-service (DoS) condition.
2025-03-31 CVE-2024-20439 high Cisco's Smart Licensing Utility shipped with hardcoded credentials, allowing unauthorized remote access and administrative control.
2022-03-25 CVE-2009-2055 high Cisco IOS XR,when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).
2022-03-25 CVE-2010-3035 high Cisco IOS XR, when BGP is the configured routing feature, allows remote attackers to cause a denial-of-service (DoS).
2022-03-25 CVE-2015-0666 high Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) allows remote attackers to read arbitrary files.
2022-03-03 CVE-2018-0154 high A vulnerability in the crypto engine of the Cisco Integrated Services Module for VPN (ISM-VPN) running Cisco IOS Software could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition.
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.70
synthesissevere-fallout-0.70
Significant concerns raised regarding Cisco's security practices due to the vulnerability and subsequent breach.
synthesisnegative-0.60
Acknowledged vulnerability, potential for significant impact.
synthesissevere-fallout-0.70
synthesissevere-fallout-0.70
Criticized for validation failure
synthesissevere-fallout-0.70
synthesissevere-fallout-0.70
synthesissevere-fallout-0.70
synthesissevere-fallout-0.70
synthesissevere-fallout-0.70
synthesissevere-fallout-0.70
cooey ↗severe-fallout-0.70
Highlights validation failure
"Cisco IOS XR improperly validates string input..."
cooey ↗severe-fallout-1.00
"…"
CISA ↗severe-fallout-1.00
"…"
www.cvefind.com ↗severe-fallout-1.00
"…"
app.opencve.io ↗severe-fallout-1.00
"…"
cvefeed.io ↗severe-fallout-1.00
"…"
xposedornot.com ↗severe-fallout-1.00
"…"
www.securitricks.com ↗severe-fallout-1.00
"…"
cooey ↗severe-fallout-1.00
negative
"…"
cooey ↗severe-fallout-1.00
negative
"Cisco HyperFlex HX Installer Virtual Machine contains an insufficient input validation vulnerability which could allow an attacker to execute commands on an affected device as the root user."
cooey ↗severe-fallout-1.00
negative
"…"
www.cvefind.com ↗severe-fallout-1.00
neutral
"…"
app.opencve.io ↗severe-fallout-1.00
neutral
"…"
cvefeed.io ↗severe-fallout-1.00
neutral
"…"
xposedornot.com ↗severe-fallout-1.00
neutral
"…"
CISA ↗severe-fallout-1.00
neutral
"…"
cve.akaoma.com ↗severe-fallout-1.00
neutral
"…"
cooey ↗severe-fallout-0.70
"…"
cooey ↗severe-fallout-1.00
negative
"Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers contain improper access controls for URLs. Exploitation could allow an attacker to download the router configuration or detailed diagnostic information."
Open questions: Cisco's remediation timeline for the 2026-06-25 and 2026-05-14 vulnerabilities · Impact of these vulnerabilities on active CMMC compliance programs
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-13 14:07:37.641701+00:00