Exploitation timeline
Threadlinqs has recorded 36 Cisco CVEs published between and . The busiest month was 2026-02 (5 new CVEs). 19 of them (53%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.
Most exploited vulnerabilities
Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 36 of 36 tracked Cisco CVEs.
- CVE-2023-20198critical 10KEVEPSS 99.6%
- CVE-2018-0171high 7.5KEVEPSS 99.5%
- CVE-2021-44228critical 10KEVRansomwareEPSS 94.4%
- CVE-2026-20079critical 10KEVEPSS 88.2%
- CVE-2026-20182critical 10KEVRansomwareEPSS 77.3%
- CVE-2026-20230high 8.6KEVEPSS 41.7%
- CVE-2025-20333critical 9.9KEVEPSS 41.4%
- CVE-2026-20127critical 10KEVEPSS 39.7%
- CVE-2008-4128medium 4.3KEVEPSS 12%
- CVE-2024-20481medium 5.8KEVRansomwareEPSS 11.1%
- CVE-2026-20245high 7.8KEVEPSS 9.9%
- CVE-2017-6742high 8.8KEVEPSS 6.8%
- CVE-2026-76461critical 9.8KEVEPSS 2.2%
- CVE-2023-20269medium 5KEVRansomwareEPSS 0.9%
- CVE-2026-20349high 8.6KEVEPSS 0.9%
- CVE-2026-20131critical 10KEVRansomwareEPSS 0.8%
- CVE-2022-20775high 7.8KEVEPSS 0.4%
- CVE-2026-76460critical 10KEV
- CVE-2026-20316medium 5.3KEV
- CVE-2025-20362high 8.6EPSS 50.7%
- CVE-2025-20309critical 10EPSS 1.1%
- CVE-2026-20200high 8.8EPSS 0.8%
- CVE-2026-20191high 7.5EPSS 0.8%
- CVE-2026-20190high 7.5EPSS 0.4%
- CVE-2026-20146medium 5.5EPSS 0.3%
- CVE-2026-20220medium 6.3EPSS 0.2%
- CVE-2026-20160critical 9.8EPSS 0.2%
- CVE-2026-20129critical 9.8EPSS 0.2%
- CVE-2026-20246medium 6EPSS 0.1%
- CVE-2026-20223critical 10EPSS 0.1%
- CVE-2026-20184critical 9.8EPSS 0%
- CVE-2026-20126high 8.8EPSS 0%
- CVE-2026-20093critical 9.8EPSS 0%
- CVE-2026-20122medium 5.4EPSS 0%
- CVE-2026-20128high 7.5EPSS 0%
- CVE-2026-76504critical 9.8
Products affected
Threadlinqs normalises CPE and CNA product records across all 36 CVEs; 200 distinct Cisco products are affected. The most frequently affected (top 20):
- Catalyst Sd-wan Manager 9 CVEs
- Firepower Threat Defense 3 CVEs
- ISE Passive Identity Connector 3 CVEs
- Identity Services Engine Software 3 CVEs
- Ios 3 CVEs
- Unified Communications Manager 3 CVEs
- Adaptive Security Appliance (ASA) Software 2 CVEs
- Adaptive Security Appliance Software 2 CVEs
- Firepower Threat Defense Software 2 CVEs
- Sd-wan Vsmart Controller 2 CVEs
- Secure Firewall Management Center (FMC) 2 CVEs
- 1100 Integrated Services Router 1 CVE
- 1100-4g Integrated Services Router 1 CVE
- 1100-4p Integrated Services Router 1 CVE
- 1100-6g Integrated Services Router 1 CVE
- 1100-8p Integrated Services Router 1 CVE
- 1101 Integrated Services Router 1 CVE
- 1101-4p Integrated Services Router 1 CVE
- 1109 Integrated Services Router 1 CVE
- 1109-2p Integrated Services Router 1 CVE
Threat activity
70 tracked threat campaigns reference Cisco products or exploit Cisco CVEs; the 25 most recent are listed.
- Cisco Catalyst SD-WAN Manager API authentication bypass zero-day (CVE-2026-76504) exploited in the wildCRITICAL
- Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt Typhoon)HIGH
- Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE CVE-2026-20079, CVE-2026-76460; SonicWall SMA 1000 CVE-2026-83548/83549; Linux Kernel CopyFail CVE-2026-31431)CRITICAL
- CISA KEV Catalog Addition: Active Exploitation of Cisco ISE Authentication Bypass (CVE-2026-76460) and Acronis Backup Privilege Escalation (CVE-2026-87886)CRITICAL
- CISA Adds Actively Exploited Cisco Secure Email Gateway SQL Injection (CVE-2026-76461) to KEV CatalogCRITICAL
- DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD Files with Defense Mil-Spec ReferencesCRITICAL
- Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON Steganographic Webshell in Multi-Country Espionage CampaignHIGH
- Recorded Future H1 2026 Report: Actively Exploited CVEs Up 34%, Ransomware Adopts BYOVD and Post-Quantum CryptoHIGH
- CVE-2026-20212: Critical Unauthenticated RCE in Cisco Nexus 9000 Series Switches (Silicon One ASIC)CRITICAL
- LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)HIGH
- Cisco Secure Firewall ASA/FTD Zero-Day (CVE-2026-20349) Exploited for DoS via Crafted HTTP Requests to Remote Access SSL VPNHIGH
- NatJack: NAT Connection-Tracking Manipulation Attacks Hijack TCP Sessions Across Windows, Linux, and macOS (CVE-2026-56181, CVE-2026-63913)HIGH
- GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting Business Managers: 351 Victims Across 334 OrganizationsHIGH
- Multiple Critical Vulnerabilities in Cisco Catalyst SD-WAN Software (CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20312, CVE-2026-20313)CRITICAL
- Critical Cisco IMC Argument Injection (CVE-2026-20200) Enables Root RCE on UCS C-Series M7/M8 Standalone Servers — Public PoC (CIMCown)CRITICAL
- CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEVCRITICAL
- AI-Generated Extortion: Fabricated Data-Leak Sites 0APT and ALP-001 Impersonate Ransomware GroupsMEDIUM
- Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote AccessMEDIUM
- Multiple Vulnerabilities in Cisco Identity Services Engine, ISE Passive Identity Connector, and RoomOS (GovCERT.HK A26-07-32)MEDIUM
- UAT-11795 (Russian) Trojanizes WebEx, Zoom, MobaXterm, DBeaver, FaceIT Installers to Deploy Starland RAT and Bespoke WLDR C2 ImplantHIGH
- US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller for Enabling Ransomware Operations (linked to FSB Center 16 Router Exploitation via CVE-2018-0171/CVE-2008-4128)MEDIUM
- CVE-2008-4128 — Decades-Old Cisco IOS CSRF Vulnerability Added to CISA KEV After Active ExploitationHIGH
- FSB Center 16 (Static Tundra) Exploits SNMP Config Exfiltration and Cisco Smart Install RCE (CVE-2018-0171) Against RoutersCRITICAL
- Microsoft July 2026 Patch Tuesday: 570 Flaws Fixed, 3 Zero-Days Including AD FS and SharePoint Privilege EscalationCRITICAL
- CVE-2008-4128 Cisco IOS CSRF Vulnerability Added to CISA KEV — Exploited by Russian FSB Center 16 (Static Tundra / Berserk Bear) in Ongoing Router-Hygiene Espionage CampaignHIGH
Threat actors targeting Cisco
Named threat actors attributed to campaigns that involve Cisco products or CVEs, with the number of linked campaigns:
How to prioritise Cisco patching
This order follows the data Threadlinqs holds for Cisco, not a generic severity checklist:
- 19 of 36 Cisco CVEs (53%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with CVE-2023-20198, CVE-2018-0171, CVE-2021-44228.
- 5 CVEs are known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are CVE-2025-20362 (50.7%), CVE-2025-20309 (1.1%), CVE-2026-20200 (0.8%).
- 16 CVEs score Critical and 12 High on CVSS v3 (maximum 10, average 8.3); sequence these after KEV and high-EPSS items.
- 8 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.
About this data
Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.