Exploited CVEs / By vendor / Cisco
Cisco vulnerabilities actively exploited
94 Cisco CVEs on the CISA Known Exploited Vulnerabilities catalog, newest first. Refreshed daily.
Every CVE below is confirmed exploited in the wild, not just theoretically severe. The newest addition is CVE-2008-4128 (IOS, added 2026-07-13). 6 of the 94 are used in ransomware campaigns. New CISA KEV entries appear here the day they are cataloged; the freshest across all vendors are on exploited this week.
Senserva AI Opinion and rich prompt for Cisco exploited CVEs
Copy this prompt into Claude, ChatGPT, or Copilot. The facts are included, sourced from this page.
IOS and IOS XE Software: 14 exploited CVEs
| CVE | Product | Added to KEV | Signals |
|---|---|---|---|
| CVE-2017-6742 | IOS and IOS XE Software | 2023-04-19 | CVSS 8.8, EPSS 21% |
| CVE-2017-12237 | IOS and IOS XE Software | 2022-03-03 | CVSS 7.5, EPSS 7% |
| CVE-2017-12240 | IOS and IOS XE Software | 2022-03-03 | CVSS 9.8, EPSS 14% |
| CVE-2017-6627 | IOS and IOS XE Software | 2022-03-03 | CVSS 7.5, EPSS 6% |
| CVE-2017-6663 | IOS and IOS XE Software | 2022-03-03 | CVSS 6.5, EPSS 2% |
| CVE-2017-6736 | IOS and IOS XE Software | 2022-03-03 | CVSS 8.8, EPSS 71% |
| CVE-2017-6737 | IOS and IOS XE Software | 2022-03-03 | CVSS 8.8, EPSS 43% |
| CVE-2017-6738 | IOS and IOS XE Software | 2022-03-03 | CVSS 8.8, EPSS 11% |
| CVE-2017-6739 | IOS and IOS XE Software | 2022-03-03 | CVSS 8.8, EPSS 11% |
| CVE-2017-6740 | IOS and IOS XE Software | 2022-03-03 | CVSS 8.8, EPSS 11% |
| CVE-2017-6743 | IOS and IOS XE Software | 2022-03-03 | CVSS 8.8, EPSS 11% |
| CVE-2018-0151 | IOS and IOS XE Software | 2022-03-03 | CVSS 9.8, EPSS 14% |
| CVE-2018-0172 | IOS and IOS XE Software | 2022-03-03 | CVSS 8.6, EPSS 8% |
| CVE-2018-0173 | IOS and IOS XE Software | 2022-03-03 | CVSS 8.6, EPSS 8% |
Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD): 6 exploited CVEs
| CVE | Product | Added to KEV | Signals |
|---|---|---|---|
| CVE-2024-20481 | Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | 2024-10-24 | CVSS 5.8, EPSS 16% |
| CVE-2024-20353 | Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | 2024-04-24 | CVSS 8.6, EPSS 71% |
| CVE-2024-20359 | Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | 2024-04-24 | CVSS 6.0, EPSS 19% |
| CVE-2020-3259 | Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | 2024-02-15 | ransomware, CVSS 7.5, EPSS 72% |
| CVE-2020-3452 | Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | 2021-11-03 | CVSS 7.5, EPSS 100% |
| CVE-2020-3580 | Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) | 2021-11-03 | ransomware, CVSS 6.1, EPSS 85% |
IOS XR: 6 exploited CVEs
| CVE | Product | Added to KEV | Signals |
|---|---|---|---|
| CVE-2022-20821 | IOS XR | 2022-05-23 | CVSS 6.5, EPSS 12% |
| CVE-2009-2055 | IOS XR | 2022-03-25 | CVSS 5.9, EPSS 3% |
| CVE-2010-3035 | IOS XR | 2022-03-25 | CVSS 7.5, EPSS 6% |
| CVE-2020-3118 | IOS XR | 2021-11-03 | CVSS 8.8, EPSS 12% |
| CVE-2020-3566 | IOS XR | 2021-11-03 | CVSS 8.6, EPSS 4% |
| CVE-2020-3569 | IOS XR | 2021-11-03 | CVSS 8.6, EPSS 3% |
IOS software: 6 exploited CVEs
| CVE | Product | Added to KEV | Signals |
|---|---|---|---|
| CVE-2017-12231 | IOS software | 2022-03-03 | CVSS 7.5, EPSS 7% |
| CVE-2017-12232 | IOS software | 2022-03-03 | CVSS 6.5, EPSS 2% |
| CVE-2017-12233 | IOS software | 2022-03-03 | CVSS 7.5, EPSS 7% |
| CVE-2017-12234 | IOS software | 2022-03-03 | CVSS 7.5, EPSS 7% |
| CVE-2017-12235 | IOS software | 2022-03-03 | CVSS 7.5, EPSS 7% |
| CVE-2017-6744 | IOS software | 2022-03-03 | CVSS 8.8, EPSS 7% |
Small Business RV160, RV260, RV340, and RV345 Series Routers: 5 exploited CVEs
| CVE | Product | Added to KEV | Signals |
|---|---|---|---|
| CVE-2022-20699 | Small Business RV160, RV260, RV340, and RV345 Series Routers | 2022-03-03 | CVSS 9.8, EPSS 72% |
| CVE-2022-20700 | Small Business RV160, RV260, RV340, and RV345 Series Routers | 2022-03-03 | CVSS 9.8, EPSS 6% |
| CVE-2022-20701 | Small Business RV160, RV260, RV340, and RV345 Series Routers | 2022-03-03 | CVSS 7.8, EPSS 10% |
| CVE-2022-20703 | Small Business RV160, RV260, RV340, and RV345 Series Routers | 2022-03-03 | CVSS 8.0, EPSS 9% |
| CVE-2022-20708 | Small Business RV160, RV260, RV340, and RV345 Series Routers | 2022-03-03 | CVSS 8.0, EPSS 15% |
Catalyst SD-WAN Manager: 4 exploited CVEs
| CVE | Product | Added to KEV | Signals |
|---|---|---|---|
| CVE-2026-20262 | Catalyst SD-WAN Manager | 2026-06-15 | CVSS 6.5, EPSS 8% |
| CVE-2026-20245 | Catalyst SD-WAN Manager | 2026-06-09 | CVSS 7.8, EPSS 25% |
| CVE-2026-20128 | Catalyst SD-WAN Manager | 2026-04-20 | CVSS 7.5, EPSS 5% |
| CVE-2026-20133 | Catalyst SD-WAN Manager | 2026-04-20 | CVSS 7.5, EPSS 10% |
IOS and IOS XE: 4 exploited CVEs
| CVE | Product | Added to KEV | Signals |
|---|---|---|---|
| CVE-2025-20352 | IOS and IOS XE | 2025-09-29 | CVSS 7.7, EPSS 38% |
| CVE-2023-20109 | IOS and IOS XE | 2023-10-10 | CVSS 6.6, EPSS 2% |
| CVE-2017-3881 | IOS and IOS XE | 2022-03-25 | CVSS 9.8, EPSS 99% |
| CVE-2018-0171 | IOS and IOS XE | 2021-11-03 | CVSS 9.8, EPSS 100% |
Adaptive Security Appliance (ASA): 4 exploited CVEs
| CVE | Product | Added to KEV | Signals |
|---|---|---|---|
| CVE-2014-2120 | Adaptive Security Appliance (ASA) | 2024-11-12 | CVSS 6.1, EPSS 14% |
| CVE-2016-6366 | Adaptive Security Appliance (ASA) | 2022-05-24 | CVSS 8.8, EPSS 88% |
| CVE-2016-6367 | Adaptive Security Appliance (ASA) | 2022-05-24 | CVSS 7.8, EPSS 23% |
| CVE-2018-0296 | Adaptive Security Appliance (ASA) | 2021-11-03 | CVSS 7.5, EPSS 100% |
IOS Software: 4 exploited CVEs
| CVE | Product | Added to KEV | Signals |
|---|---|---|---|
| CVE-2018-0154 | IOS Software | 2022-03-03 | CVSS 7.5, EPSS 7% |
| CVE-2018-0161 | IOS Software | 2022-03-03 | CVSS 6.3, EPSS 5% |
| CVE-2018-0179 | IOS Software | 2022-03-03 | CVSS 5.9, EPSS 5% |
| CVE-2018-0180 | IOS Software | 2022-03-03 | CVSS 5.9, EPSS 5% |
IOS Software and Cisco IOS XE Software: 3 exploited CVEs
| CVE | Product | Added to KEV | Signals |
|---|---|---|---|
| CVE-2018-0156 | IOS Software and Cisco IOS XE Software | 2022-03-03 | CVSS 7.5, EPSS 8% |
| CVE-2018-0158 | IOS Software and Cisco IOS XE Software | 2022-03-03 | CVSS 8.6, EPSS 7% |
| CVE-2018-0159 | IOS Software and Cisco IOS XE Software | 2022-03-03 | CVSS 7.5, EPSS 7% |
Other Cisco products
| CVE | Product | Added to KEV | Signals |
|---|---|---|---|
| CVE-2008-4128 | IOS | 2026-07-13 | CVSS 4.3, EPSS 24% |
| CVE-2026-20230 | Unified Communications Manager | 2026-06-25 | CVSS 8.6, EPSS 42% |
| CVE-2026-20182 | Catalyst SD-WAN | 2026-05-14 | CVSS 10.0, EPSS 89% |
| CVE-2026-20122 | Catalyst SD-WAN Manger | 2026-04-20 | CVSS 5.4, EPSS 7% |
| CVE-2026-20131 | Secure Firewall Management Center (FMC) | 2026-03-19 | ransomware, CVSS 10.0, EPSS 28% |
| CVE-2022-20775 | SD-WAN | 2026-02-25 | CVSS 7.8, EPSS 12% |
| CVE-2026-20127 | Catalyst SD-WAN Controller and Manager | 2026-02-25 | CVSS 10.0, EPSS 58% |
| CVE-2026-20045 | Unified Communications Manager | 2026-01-21 | CVSS 9.8, EPSS 4% |
| CVE-2025-20393 | Multiple Products | 2025-12-17 | CVSS 10.0, EPSS 30% |
| CVE-2025-20333 | Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense | 2025-09-25 | CVSS 9.9, EPSS 40% |
| CVE-2025-20362 | Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense | 2025-09-25 | CVSS 8.6, EPSS 86% |
| CVE-2025-20281 | Identity Services Engine | 2025-07-28 | CVSS 10.0, EPSS 97% |
| CVE-2025-20337 | Identity Services Engine | 2025-07-28 | CVSS 10.0, EPSS 65% |
| CVE-2024-20439 | Smart Licensing Utility | 2025-03-31 | CVSS 9.8, EPSS 92% |
| CVE-2023-20118 | Small Business RV Series Routers | 2025-03-03 | CVSS 7.2, EPSS 54% |
| CVE-2024-20399 | NX-OS | 2024-07-02 | CVSS 6.7, EPSS 4% |
| CVE-2023-20273 | Cisco IOS XE Web UI | 2023-10-23 | CVSS 7.2, EPSS 90% |
| CVE-2023-20198 | IOS XE Web UI | 2023-10-16 | CVSS 10.0, EPSS 100% |
| CVE-2023-20269 | Adaptive Security Appliance and Firepower Threat Defense | 2023-09-13 | ransomware, CVSS 9.1, EPSS 22% |
| CVE-2004-1464 | IOS | 2023-05-19 | CVSS 5.9, EPSS 5% |
| CVE-2016-6415 | IOS, IOS XR, and IOS XE | 2023-05-19 | CVSS 7.5, EPSS 87% |
| CVE-2020-3153 | AnyConnect Secure | 2022-10-24 | ransomware, CVSS 6.5, EPSS 28% |
| CVE-2020-3433 | AnyConnect Secure | 2022-10-24 | ransomware, CVSS 7.8, EPSS 10% |
| CVE-2019-15271 | RV Series Routers | 2022-06-08 | CVSS 8.8, EPSS 6% |
| CVE-2015-0666 | Prime Data Center Network Manager (DCNM) | 2022-03-25 | CVSS 7.5, EPSS 40% |
| CVE-2018-0125 | VPN Routers | 2022-03-25 | CVSS 9.8, EPSS 55% |
| CVE-2018-0147 | Secure Access Control System (ACS) | 2022-03-25 | CVSS 9.8, EPSS 18% |
| CVE-2017-12238 | Catalyst 6800 Series Switches | 2022-03-03 | CVSS 6.5, EPSS 2% |
| CVE-2017-12319 | IOS XE Software | 2022-03-03 | CVSS 5.9, EPSS 5% |
| CVE-2018-0155 | Catalyst 4500 Series Switches and Cisco Catalyst 4500-X Series Switches | 2022-03-03 | CVSS 8.6, EPSS 8% |
| CVE-2018-0167 | IOS, XR, and XE Software | 2022-03-03 | CVSS 8.8, EPSS 3% |
| CVE-2018-0174 | IOS XE Software | 2022-03-03 | CVSS 8.6, EPSS 8% |
| CVE-2018-0175 | IOS, XR, and XE Software | 2022-03-03 | CVSS 8.0, EPSS 4% |
| CVE-2019-1652 | Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers | 2022-03-03 | CVSS 7.2, EPSS 96% |
| CVE-2019-1653 | Small Business RV320 and RV325 Routers | 2021-11-03 | CVSS 7.5, EPSS 100% |
| CVE-2020-3161 | Cisco IP Phones | 2021-11-03 | CVSS 9.8, EPSS 84% |
| CVE-2021-1497 | HyperFlex HX | 2021-11-03 | CVSS 9.8, EPSS 100% |
| CVE-2021-1498 | HyperFlex HX | 2021-11-03 | CVSS 9.8, EPSS 100% |
Common questions about exploited Cisco CVEs
Which Cisco vulnerabilities are actively exploited?
As of July 2026, 94 Cisco CVEs are on the CISA Known Exploited Vulnerabilities catalog, meaning exploitation in the wild is confirmed. The most-listed products are IOS and IOS XE Software (14), Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) (6), IOS XR (6), IOS software (6). 6 are linked to ransomware campaigns.
What is the newest exploited Cisco CVE?
CVE-2008-4128, affecting IOS, added to the CISA KEV catalog on 2026-07-13. This page refreshes daily, so the newest entry is always first in the table.
How urgent are these Cisco CVEs?
KEV listing is the strongest fix-first signal there is: it means confirmed exploitation, not a prediction. Patch these ahead of higher-CVSS issues that nobody is exploiting. Check the vendor advisory (linked below) for fixed versions and workarounds.
Can I ask my own AI about exploited Cisco CVEs?
Yes. This page includes a free copy-paste AI prompt carrying the newest Cisco KEV entries, with CVSS, EPSS, and ransomware context, into Claude, ChatGPT, or Copilot. The data is refreshed three times a day (5 AM, 12:30 PM, and 7 PM US Central).
Authoritative references
All vendors, searchable with due dates and CSV export: the exploited-CVE tracker. Every vendor with a page: exploited by vendor.