By vendor

Cisco vulnerabilities

Known CVEs affecting Cisco products, prioritized by severity, with SEC.co remediation and detection guidance.

16 published vulnerabilities

  • CVE-2026-20190HIGH 7.5

    Cisco Identity Services Engine (ISE) and ISE-PIC contain a flaw that allows unauthenticated attackers to remotely access sensitive information without proper authorization. The vulnerability stems from inadequate permission checks when resources are requested. By crafting and sending specific traffic to an affected device, an attacker can retrieve sensitive data including hashed credentials—material that could enable follow-on attacks such as password cracking or lateral movement within the network.

  • CVE-2026-20213HIGH 7.5

    ClamAV, a widely-used open-source antivirus engine, contains a flaw in how it processes PE (Portable Executable) files during scanning. An attacker can craft a malicious PE file that, when scanned, causes ClamAV to crash due to improper memory handling. This disrupts the scanning service and prevents legitimate threat detection from functioning. While the primary impact is denial of service, the underlying memory corruption could potentially enable more severe attacks depending on how the vulnerability is exploited.

  • CVE-2026-20214HIGH 7.5

    ClamAV, a widely deployed open-source antivirus engine used in products like Cisco Secure Endpoint, contains a flaw in how it parses FSG-compressed executable files. An attacker can craft a malicious FSG file that triggers an out-of-bounds memory write when scanned, crashing the scanning process and disrupting threat detection. This is a network-reachable denial-of-service vulnerability requiring no authentication or user interaction.

  • CVE-2026-20215HIGH 7.5

    ClamAV, an open-source antivirus engine widely integrated into Cisco Secure Endpoint and other security products, contains a flaw in how it parses 7z compressed files. When scanning a specially crafted 7z file, the parser fails to properly validate memory boundaries, allowing an attacker to write data outside allocated buffer space. This memory corruption causes the ClamAV scanning process to crash, disrupting antivirus protection on affected systems. An attacker needs only to submit a malicious 7z file for scanning—no authentication or user interaction required—making this a remote denial-of-service threat to organizations relying on ClamAV for file scanning.

  • CVE-2026-20216HIGH 7.5

    ClamAV, an open-source antivirus engine widely deployed in enterprise environments, contains a flaw in how it parses InstallShield installer files. When ClamAV scans a specially crafted InstallShield file, the parser mismanages temporary resources, causing the scanning process to crash and consuming system memory and CPU in the process. An attacker can trigger this remotely by uploading or submitting a malicious file to any system running ClamAV, resulting in service disruption without needing credentials or user interaction.

  • CVE-2026-20217HIGH 7.5

    ClamAV's PESpin file format parser contains a memory safety flaw that allows remote attackers to crash the scanning engine by submitting a specially crafted file. When ClamAV processes the malicious file, improper boundary validation causes a buffer to be written beyond its allocated memory, terminating the scanner and disrupting security operations. The attacker needs only network access and no credentials; the vulnerable software will automatically process the file if scanned.

  • CVE-2026-20243HIGH 7.5

    ClamAV's parser for ALZ archive files contains a flaw that fails to properly validate file boundaries during scanning. This allows an attacker to craft a malicious ALZ file that, when scanned, causes the antivirus engine to write data outside allocated memory regions. The result is typically a crash of the scanning process, disrupting the ability of the affected system to scan files until the service is restarted. While the vulnerability is currently characterized as causing denial of service, memory corruption of this nature can sometimes enable deeper system compromise depending on the specifics of exploitation.

  • CVE-2026-20244HIGH 7.5

    ClamAV's DMG file parser contains a flaw that allows remote attackers to crash the scanning engine by submitting specially crafted DMG archive files. The vulnerability stems from inadequate boundary validation when processing DMG content, leading to integer overflow on 32-bit systems. An attacker needs only to send a malicious DMG file to a ClamAV instance; no authentication or user interaction is required. Successful exploitation terminates the scanning process, effectively disabling antivirus protection on the affected device until the service restarts.

  • CVE-2026-24697HIGH 7.2

    Cisco's small-business routers (RV130, RV130W, and RV110W) contain a command injection flaw in their configuration handling. An attacker with administrative access to the device can manipulate the WAN hostname setting to inject and execute arbitrary operating system commands with root-level privileges. This is a serious post-authentication vulnerability because once an attacker has logged in—whether through credential compromise, phishing, or insider threat—they can escalate to full system control.

  • CVE-2026-24698HIGH 7.2

    A command injection flaw in Cisco small-business routers (RV130, RV130W, and RV110W) allows authenticated administrators to execute arbitrary system commands with root-level privileges by manipulating the model_name configuration parameter. An attacker with valid credentials could bypass normal access controls and take full control of the router's operating system.

  • CVE-2026-24699HIGH 7.2

    A command injection flaw in Cisco's small business routers (RV130, RV130W, and RV110W) allows authenticated administrators to inadvertently execute arbitrary system commands with root privileges by manipulating the LAN IPv6 prefix length configuration parameter. An attacker with administrative access could leverage this to compromise the entire router and potentially the networks it protects.

  • CVE-2026-24700HIGH 7.2

    A command injection flaw in Cisco small business routers allows authenticated administrators to execute arbitrary commands with root-level privileges by injecting malicious input into the machine name configuration field. An attacker with valid admin credentials can manipulate this parameter to break out of the intended configuration context and run arbitrary OS commands on the affected router.

  • CVE-2026-20220MEDIUM 6.3

    Cisco Crosswork Network Controller's web management interface contains a flaw in how it validates input to its configuration template engine. An authenticated user with template write permissions can send specially crafted requests to execute arbitrary commands on the underlying operating system, but only within directories where the template user account has write access. This is a post-authentication attack requiring valid credentials and specific permission levels.

  • CVE-2026-20233MEDIUM 6.1

    Cisco Webex Meetings contained a cross-site scripting (XSS) vulnerability in its web interface that could allow an attacker to inject malicious scripts if a user clicked a crafted link. The vulnerability resulted from weak input validation. Cisco has already patched the service, and users do not need to take action—the fix has been deployed automatically.

  • CVE-2026-20246MEDIUM 6.0

    Cisco Umbrella Virtual Appliance contains a privilege escalation flaw in its vmadmin command-line interface. An authenticated attacker with vmadmin-level access can run specially crafted commands to gain full root privileges on the device. The vulnerability stems from insufficient input validation and requires local access and existing elevated privileges to exploit, limiting its immediate blast radius but creating a critical post-compromise risk for affected deployments.

  • CVE-2026-20178MEDIUM 4.3

    A vulnerability in Cisco's browser-based Webex App could allow attackers to trick users into visiting malicious websites. The flaw involves inadequate validation of URL parameters, meaning a crafted link sent to a user could redirect them elsewhere if clicked. Cisco has already patched the issue, and users do not need to take action—the fix is applied server-side or through automatic updates.