Vendor advisories

Cisco Security Advisories

Browse 34 advisories from this official source. Search by product, CVE, severity, or advisory ID.

Current Checked 12 minutes ago Checked every 15 minutes

34 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Cisco Security Advisoriescisco-sa-hardening-iosxe-V8NMuMZJ
CriticalPriority signal

Cisco IOS XE Software Security Hardening Release: August 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered v...

Vendor guidance

To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class ��� Common Weakness Enumeration (CWE) ��� and assigned a single Common V...

Cisco Security Advisoriescisco-sa-cimc-arg-inject-upSHdMfU
High

Cisco Integrated Management Controller Argument Injection Vulnerabilities

Multiple vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root. F...

Vendor guidance

Cisco has released software updates that address these vulnerabilities.

Cisco Security Advisoriescisco-sa-ios-xmcp-thbAr34t
High

Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerability

A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected dev...

Vendor guidance

Cisco has released software updates that address this vulnerability.

Cisco Security Advisoriescisco-sa-iosxe-snmp-dos-ZAqNm4MD
High

Cisco IOS XE Software SNMP Denial of Service Vulnerability

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to improper erro...

Vendor guidance

Cisco has released software updates that address this vulnerability.

Cisco Security Advisoriescisco-sa-iosxe-bing-MGHrFAkd
High

Cisco IOS XE Software Blocks Extensible Exchange Protocol Denial of Service Vulnerability

A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling when parsing a ...

Vendor guidance

Cisco has released software updates that address this vulnerability.

Cisco Security Advisoriescisco-sa-webui-dos-qdc7qx3
Medium

Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerability

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device. This vulnerability is due to insufficient input validation. ...

Vendor guidance

Cisco has released software updates that address this vulnerability.

Cisco Security Advisoriescisco-sa-ts-agent-fw-bypass-MYBTMrev
Medium

Cisco Terminal Services Agent Firewall Rules Bypass Vulnerability

A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker to bypass firewall rules that are associated with the account of the attacker. This vulnerability is due to an incorrect mapping of network connections to u...

Vendor guidance

Cisco has released software updates that address this vulnerability.

Cisco Security Advisoriescisco-sa-roomos-infodisc-qBXjfmWm
Medium

Cisco RoomOS Logging Subsystem Information Disclosure Vulnerability

A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive information. This vulnerability is due to the logging of sensitive information. An attacker could exploit this vulnerability by enablin...

Vendor guidance

Cisco has released software updates that address this vulnerability.

Cisco Security Advisoriescisco-sa-cimc-xss-7EhBFxBp
Medium

Cisco Integrated Management Controller Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validat...

Vendor guidance

Cisco has released software updates that address this vulnerability.

Cisco Security Advisoriescisco-sa-xe-webui-dos-PtAODAWW
Medium

Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerability

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient error handling in the ...

Vendor guidance

Cisco has released software updates that address this vulnerability.

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.