Vendor advisories

Cisco Security Advisories

Browse 34 advisories from this official source. Search by product, CVE, severity, or advisory ID.

Current Checked 16 minutes ago Checked every 15 minutes

34 advisories

Each date says whether the vendor published or updated the bulletin. A vendor bulletin describes products that may be affected. It does not prove that the vulnerable product or version is installed in your environment.

RSS for these results
Cisco Security Advisoriescisco-sa-hardening-iosxr-qg64NcM
CriticalPriority signal

Cisco IOS XR Software Security Hardening Release: September 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered v...

Vendor guidance

To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class - Common Weakness Enumeration (CWE) - and assigned a single Common Vulnerab...

Cisco Security Advisoriescisco-sa-onprem-fmc-authbypass-5JPp45V2
Critical

Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This...

Vendor guidance

Cisco has released software updates that address this vulnerability.

Cisco Security Advisoriescisco-sa-ucs-uefi-sb-bypass-eb6xC5GW
High

Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability

A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or admin or an unauthenticated attacker ...

Vendor guidance

Cisco has released software updates that address this vulnerability.

Cisco Security Advisoriescisco-sa-esa-smime-disc-dzw4rEdY
Medium

Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities

Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficie...

Cisco Security Advisoriescisco-sa-notice-f2SiMFxl
Informational

Cisco Advance Notification for Publication of September 2, 2026, Security Advisories

On September 2, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco IOS XR Software Security Hardening Release: September 2026 CVE-2026-20277CVE-2026-202...

Cisco Security Advisoriescisco-sa-n9k-s1-rce-EH8dEtr
Critical

Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability

A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges. This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virt...

Vendor guidance

Cisco has released software updates that address this vulnerability.

Cisco Security Advisoriescisco-sa-phone-dos-txMYNRzv
High

Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability

A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session Initiation Protocol (SIP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an...

Vendor guidance

Cisco has released software updates that address this vulnerability.

Cisco Security Advisoriescisco-sa-hardening-crosswork-UzDTU9Vh
CriticalPriority signal

Cisco Crosswork Security Hardening Release: August 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vuln...

Vendor guidance

To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class - Common Weakness Enumeration (CWE) - and assigned a single Common Vulne...

Cisco Security Advisoriescisco-sa-notice-LDquvx5d
Informational

Cisco Advance Notification for Publication of August 19, 2026, Security Advisories

On August 19, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco Crosswork Security Hardening Release: August 2026 CVE-2026-20030CVE-2026-20357CVE-2026-...

Cisco Security Advisoriescisco-sa-hardening-csw1-shSvndWP
CriticalPriority signal

Cisco Secure Workload Software Security Hardening Release: August 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Workload engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered v...

Vendor guidance

To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class - Common Weakness Enumeration (CWE) - and assigned a single Common Vulne...

Cisco Security Advisoriescisco-sa-bworks-xxe-uwUd7CEt
High

Cisco BroadWorks Out-of-Band Blind XML External Entity Injection Vulnerability

A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system. This vulnerability exists because XML entries are improperly parsed due to exter...

Vendor guidance

Cisco has released software updates that address this vulnerability.

Cisco Security Advisoriescisco-sa-roomos-bof-vTMANZgu
Medium

Cisco RoomOS Stack Overflow Vulnerability

A vulnerability in the USB driver of Cisco RoomOS could allow an unauthenticated, local attacker with physical access to the USB port on an affected device to execute arbitrary code with root privileges. This vulnerability is due to insufficient boundary checks for specific da...

Vendor guidance

Cisco has released software updates that address this vulnerability.

Cisco Security Advisoriescisco-sa-ie1k-uxq86Lnx
Medium

Cisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability

A vulnerability in the handling of management plane packets by Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an unauthenticated, remote attacker to cause the device manager, SSH, or API to become inaccessible.This vulnerability is due to insufficient protecti...

Vendor guidance

Cisco has released software updates that address this vulnerability.

Cisco Security Advisoriescisco-sa-cuic-sql-inject-2qbfWSm5
Medium

Cisco Unified Intelligence Center SQL Injection Vulnerability

A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, local attacker to perform a blind SQL injection attack against an affected device. This vulnerability is due to insufficient validation of user-supplied inp...

Vendor guidance

Cisco has released software updates that address this vulnerability.

Cisco Security Advisoriescisco-sa-ucce-pcce-ssrf-TghHxD
Medium

Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Server-Side Request Forgery Vulnerability

A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerabili...

Vendor guidance

Cisco has released software updates that address this vulnerability.

Cisco Security Advisoriescisco-sa-ie1k-NgXUFF52
Medium

Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerability

A vulnerability in the web-based management interface of Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insuff...

Vendor guidance

Cisco has released software updates that address this vulnerability.

Cisco Security Advisoriescisco-sa-clamav-WuuvVd26
High

ClamAV Vulnerabilities Affecting Cisco Products: August 2026

Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations. For more information about these vulnerabilities, see the Details section of this advisory. For additional information on these vuln...

Vendor guidance

Cisco has released software updates that address these vulnerabilities in affected Cisco platforms.

Cisco Security Advisoriescisco-sa-fmc-static-cred-BET3Cjh
High

Cisco Secure Firewall Management Center Software Static Credential Vulnerability

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerabilit...

Vendor guidance

Cisco has released software updates that address this vulnerability.

Cisco Security Advisoriescisco-sa-asaftd-vpn-dos-dzv4mQFF
High

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulti...

Vendor guidance

Cisco has released software updates that address this vulnerability.

Cisco Security Advisoriescisco-sa-sdwan-infodis-SPuJBDCe
Medium

Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficient access control enforcement for spec...

Vendor guidance

Cisco has released software updates that address this vulnerability.

Cisco Security Advisoriescisco-sa-notice-L4XfJg8S
Informational

Cisco Advance Notification for Publication of August 5, 2026, Security Advisories

On August 5, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026 CVE-2026-20303CVE-2026-...

Cisco Security Advisoriescisco-sa-hardening-iosxe-V8NMuMZJ
CriticalPriority signal

Cisco IOS XE Software Security Hardening Release: August 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered v...

Vendor guidance

To assist customers in patching and to streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class ��� Common Weakness Enumeration (CWE) ��� and assigned a single Common V...

Cisco Security Advisoriescisco-sa-hardening-sdwan-faLcR3K
CriticalPriority signal

Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally dis...

Vendor guidance

To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class - Common Weakness Enumeration (CWE) - and assigned a single Common Vulnerab...

Before you act

Start with the vendor's bulletin.

We normalize the fields that vendors publish so you can search and compare advisories in one place. We do not replace the original bulletin or turn a product-name match into proof that a system is vulnerable.

Confirm the installed product and version, read the linked vendor guidance, and test the recommended update or mitigation through your normal change process.

Read how SecurityAlert collects and checks threat intelligence.