# Cisco vulnerabilities & exploitation

**CISA KEV** · **Ransomware**

> As of 2026-10-05, Threadlinqs tracks 36 Cisco CVEs, 19 in the CISA Known Exploited Vulnerabilities catalog, 5 used in ransomware campaigns, linked to 70 tracked threat campaigns and 12 named threat actors.

**Data as of:** 2026-10-05

## Exploitation timeline

Threadlinqs has recorded 36 Cisco CVEs published between 2008-09-15 and 2026-09-15. The busiest month was 2026-02 (5 new CVEs). 19 of them (53%) are listed in CISA KEV, which means exploitation in the wild has been confirmed.

## Most exploited vulnerabilities

Ranked with CISA KEV listings first, then EPSS exploit probability, then CVSS score. Showing 36 of 36 tracked Cisco CVEs.

- [CVE-2023-20198](https://intel.threadlinqs.com/cve/CVE-2023-20198) — CRITICAL 10 · KEV · EPSS 99.6% · 2023-10-16
- [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171) — HIGH 7.5 · KEV · EPSS 99.5% · 2018-03-28
- [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228) — CRITICAL 10 · KEV · Ransomware · EPSS 94.4% · 2021-12-10
- [CVE-2026-20079](https://intel.threadlinqs.com/cve/CVE-2026-20079) — CRITICAL 10 · KEV · EPSS 88.2% · 2026-03-04
- [CVE-2026-20182](https://intel.threadlinqs.com/cve/CVE-2026-20182) — CRITICAL 10 · KEV · Ransomware · EPSS 77.3% · 2026-05-14
- [CVE-2026-20230](https://intel.threadlinqs.com/cve/CVE-2026-20230) — HIGH 8.6 · KEV · EPSS 41.7% · 2026-06-03
- [CVE-2025-20333](https://intel.threadlinqs.com/cve/CVE-2025-20333) — CRITICAL 9.9 · KEV · EPSS 41.4% · 2025-09-25
- [CVE-2026-20127](https://intel.threadlinqs.com/cve/CVE-2026-20127) — CRITICAL 10 · KEV · EPSS 39.7% · 2026-02-25
- [CVE-2008-4128](https://intel.threadlinqs.com/cve/CVE-2008-4128) — MEDIUM 4.3 · KEV · EPSS 12% · 2008-09-18
- [CVE-2024-20481](https://intel.threadlinqs.com/cve/CVE-2024-20481) — MEDIUM 5.8 · KEV · Ransomware · EPSS 11.1% · 2024-10-23
- [CVE-2026-20245](https://intel.threadlinqs.com/cve/CVE-2026-20245) — HIGH 7.8 · KEV · EPSS 9.9% · 2026-06-04
- [CVE-2017-6742](https://intel.threadlinqs.com/cve/CVE-2017-6742) — HIGH 8.8 · KEV · EPSS 6.8% · 2017-07-17
- [CVE-2026-76461](https://intel.threadlinqs.com/cve/CVE-2026-76461) — CRITICAL 9.8 · KEV · EPSS 2.2% · 2026-09-14
- [CVE-2023-20269](https://intel.threadlinqs.com/cve/CVE-2023-20269) — MEDIUM 5 · KEV · Ransomware · EPSS 0.9% · 2023-09-06
- [CVE-2026-20349](https://intel.threadlinqs.com/cve/CVE-2026-20349) — HIGH 8.6 · KEV · EPSS 0.9% · 2026-08-11
- [CVE-2026-20131](https://intel.threadlinqs.com/cve/CVE-2026-20131) — CRITICAL 10 · KEV · Ransomware · EPSS 0.8% · 2026-03-04
- [CVE-2022-20775](https://intel.threadlinqs.com/cve/CVE-2022-20775) — HIGH 7.8 · KEV · EPSS 0.4% · 2022-09-30
- [CVE-2026-76460](https://intel.threadlinqs.com/cve/CVE-2026-76460) — CRITICAL 10 · KEV · 2026-09-16
- [CVE-2026-20316](https://intel.threadlinqs.com/cve/CVE-2026-20316) — MEDIUM 5.3 · KEV · 2026-07-29
- [CVE-2025-20362](https://intel.threadlinqs.com/cve/CVE-2025-20362) — HIGH 8.6 · EPSS 50.7% · 2025-09-25
- [CVE-2025-20309](https://intel.threadlinqs.com/cve/CVE-2025-20309) — CRITICAL 10 · EPSS 1.1% · 2025-07-02
- [CVE-2026-20200](https://intel.threadlinqs.com/cve/CVE-2026-20200) — HIGH 8.8 · EPSS 0.8% · 2026-08-05
- [CVE-2026-20191](https://intel.threadlinqs.com/cve/CVE-2026-20191) — HIGH 7.5 · EPSS 0.8% · 2026-07-01
- [CVE-2026-20190](https://intel.threadlinqs.com/cve/CVE-2026-20190) — HIGH 7.5 · EPSS 0.4% · 2026-06-17
- [CVE-2026-20146](https://intel.threadlinqs.com/cve/CVE-2026-20146) — MEDIUM 5.5 · EPSS 0.3% · 2026-07-15
- [CVE-2026-20220](https://intel.threadlinqs.com/cve/CVE-2026-20220) — MEDIUM 6.3 · EPSS 0.2% · 2026-06-17
- [CVE-2026-20160](https://intel.threadlinqs.com/cve/CVE-2026-20160) — CRITICAL 9.8 · EPSS 0.2% · 2026-04-01
- [CVE-2026-20129](https://intel.threadlinqs.com/cve/CVE-2026-20129) — CRITICAL 9.8 · EPSS 0.2% · 2026-02-25
- [CVE-2026-20246](https://intel.threadlinqs.com/cve/CVE-2026-20246) — MEDIUM 6 · EPSS 0.1% · 2026-06-17
- [CVE-2026-20223](https://intel.threadlinqs.com/cve/CVE-2026-20223) — CRITICAL 10 · EPSS 0.1% · 2026-05-20
- [CVE-2026-20184](https://intel.threadlinqs.com/cve/CVE-2026-20184) — CRITICAL 9.8 · EPSS 0% · 2026-04-15
- [CVE-2026-20126](https://intel.threadlinqs.com/cve/CVE-2026-20126) — HIGH 8.8 · EPSS 0% · 2026-02-25
- [CVE-2026-20093](https://intel.threadlinqs.com/cve/CVE-2026-20093) — CRITICAL 9.8 · EPSS 0% · 2026-04-01
- [CVE-2026-20122](https://intel.threadlinqs.com/cve/CVE-2026-20122) — MEDIUM 5.4 · EPSS 0% · 2026-02-25
- [CVE-2026-20128](https://intel.threadlinqs.com/cve/CVE-2026-20128) — HIGH 7.5 · EPSS 0% · 2026-02-25
- [CVE-2026-76504](https://intel.threadlinqs.com/cve/CVE-2026-76504) — CRITICAL 9.8 · 2026-09-30

## Products affected

Threadlinqs normalises CPE and CNA product records across all 36 CVEs; 200 distinct Cisco products are affected. The most frequently affected (top 20):

- Catalyst Sd-wan Manager — 9 CVEs
- Firepower Threat Defense — 3 CVEs
- ISE Passive Identity Connector — 3 CVEs
- Identity Services Engine Software — 3 CVEs
- Ios — 3 CVEs
- Unified Communications Manager — 3 CVEs
- Adaptive Security Appliance (ASA) Software — 2 CVEs
- Adaptive Security Appliance Software — 2 CVEs
- Firepower Threat Defense Software — 2 CVEs
- Sd-wan Vsmart Controller — 2 CVEs
- Secure Firewall Management Center (FMC) — 2 CVEs
- 1100 Integrated Services Router — 1 CVE
- 1100-4g Integrated Services Router — 1 CVE
- 1100-4p Integrated Services Router — 1 CVE
- 1100-6g Integrated Services Router — 1 CVE
- 1100-8p Integrated Services Router — 1 CVE
- 1101 Integrated Services Router — 1 CVE
- 1101-4p Integrated Services Router — 1 CVE
- 1109 Integrated Services Router — 1 CVE
- 1109-2p Integrated Services Router — 1 CVE

## Threat activity

70 tracked threat campaigns reference Cisco products or exploit Cisco CVEs; the 25 most recent are listed.

- [Cisco Catalyst SD-WAN Manager API authentication bypass zero-day (CVE-2026-76504) exploited in the wild](https://intel.threadlinqs.com/threat/TL-2026-2820) — CRITICAL — 2026-09-30
- [Nation-State Intrusions into Telecom Infrastructure via SS7, BGP Hijacking, and Router Compromise (Salt Typhoon)](https://intel.threadlinqs.com/threat/TL-2026-2649) — HIGH — 2026-09-25
- [Eclypsium InfraTrust Report: Mass Active Exploitation of Network Management Systems (Cisco FMC/ISE CVE-2026-20079, CVE-2026-76460; SonicWall SMA 1000 CVE-2026-83548/83549; Linux Kernel CopyFail CVE-2026-31431)](https://intel.threadlinqs.com/threat/TL-2026-2630) — CRITICAL — 2026-09-23
- [CISA KEV Catalog Addition: Active Exploitation of Cisco ISE Authentication Bypass (CVE-2026-76460) and Acronis Backup Privilege Escalation (CVE-2026-87886)](https://intel.threadlinqs.com/threat/TL-2026-2542) — CRITICAL — 2026-09-16
- [CISA Adds Actively Exploited Cisco Secure Email Gateway SQL Injection (CVE-2026-76461) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2508) — CRITICAL — 2026-09-14
- [DragonForce Ransomware Attack on RubberMill, Inc. — ~340GB Data Exfiltration Including PII, Credentials, CAD Files with Defense Mil-Spec References](https://intel.threadlinqs.com/threat/TL-2026-2364) — CRITICAL — 2026-09-06
- [Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON Steganographic Webshell in Multi-Country Espionage Campaign](https://intel.threadlinqs.com/threat/TL-2026-2325) — HIGH — 2026-09-04
- [Recorded Future H1 2026 Report: Actively Exploited CVEs Up 34%, Ransomware Adopts BYOVD and Post-Quantum Crypto](https://intel.threadlinqs.com/threat/TL-2026-2310) — HIGH — 2026-09-03
- [CVE-2026-20212: Critical Unauthenticated RCE in Cisco Nexus 9000 Series Switches (Silicon One ASIC)](https://intel.threadlinqs.com/threat/TL-2026-2319) — CRITICAL — 2026-09-03
- [LockBit 5.0 Ransomware Extortion Claim Against US Bank (U.S. Bancorp)](https://intel.threadlinqs.com/threat/TL-2026-2094) — HIGH — 2026-08-21
- [Cisco Secure Firewall ASA/FTD Zero-Day (CVE-2026-20349) Exploited for DoS via Crafted HTTP Requests to Remote Access SSL VPN](https://intel.threadlinqs.com/threat/TL-2026-1993) — HIGH — 2026-08-12
- [NatJack: NAT Connection-Tracking Manipulation Attacks Hijack TCP Sessions Across Windows, Linux, and macOS (CVE-2026-56181, CVE-2026-63913)](https://intel.threadlinqs.com/threat/TL-2026-1927) — HIGH — 2026-08-07
- [GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting Business Managers: 351 Victims Across 334 Organizations](https://intel.threadlinqs.com/threat/TL-2026-1917) — HIGH — 2026-08-06
- [Multiple Critical Vulnerabilities in Cisco Catalyst SD-WAN Software (CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20312, CVE-2026-20313)](https://intel.threadlinqs.com/threat/TL-2026-1905) — CRITICAL — 2026-08-06
- [Critical Cisco IMC Argument Injection (CVE-2026-20200) Enables Root RCE on UCS C-Series M7/M8 Standalone Servers — Public PoC (CIMCown)](https://intel.threadlinqs.com/threat/TL-2026-1912) — CRITICAL — 2026-08-06
- [CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-1759) — CRITICAL — 2026-07-29
- [AI-Generated Extortion: Fabricated Data-Leak Sites 0APT and ALP-001 Impersonate Ransomware Groups](https://intel.threadlinqs.com/threat/TL-2026-1761) — MEDIUM — 2026-07-29
- [Sen. Wyden Urges Binding Federal Mandate to Purge Internet-Facing Legacy VPNs for Zero-Trust Remote Access](https://intel.threadlinqs.com/threat/TL-2026-1774) — MEDIUM — 2026-07-27
- [Multiple Vulnerabilities in Cisco Identity Services Engine, ISE Passive Identity Connector, and RoomOS (GovCERT.HK A26-07-32)](https://intel.threadlinqs.com/threat/TL-2026-1500) — MEDIUM — 2026-07-18
- [UAT-11795 (Russian) Trojanizes WebEx, Zoom, MobaXterm, DBeaver, FaceIT Installers to Deploy Starland RAT and Bespoke WLDR C2 Implant](https://intel.threadlinqs.com/threat/TL-2026-1411) — HIGH — 2026-07-16
- [US Treasury Sanctions 1VPNS VPN Service and Cryptor Seller for Enabling Ransomware Operations (linked to FSB Center 16 Router Exploitation via CVE-2018-0171/CVE-2008-4128)](https://intel.threadlinqs.com/threat/TL-2026-1290) — MEDIUM — 2026-07-14
- [CVE-2008-4128 — Decades-Old Cisco IOS CSRF Vulnerability Added to CISA KEV After Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-1301) — HIGH — 2026-07-14
- [FSB Center 16 (Static Tundra) Exploits SNMP Config Exfiltration and Cisco Smart Install RCE (CVE-2018-0171) Against Routers](https://intel.threadlinqs.com/threat/TL-2026-1312) — CRITICAL — 2026-07-14
- [Microsoft July 2026 Patch Tuesday: 570 Flaws Fixed, 3 Zero-Days Including AD FS and SharePoint Privilege Escalation](https://intel.threadlinqs.com/threat/TL-2026-1324) — CRITICAL — 2026-07-14
- [CVE-2008-4128 Cisco IOS CSRF Vulnerability Added to CISA KEV — Exploited by Russian FSB Center 16 (Static Tundra / Berserk Bear) in Ongoing Router-Hygiene Espionage Campaign](https://intel.threadlinqs.com/threat/TL-2026-1272) — HIGH — 2026-07-13

## Threat actors targeting Cisco

Named threat actors attributed to campaigns that involve Cisco products or CVEs, with the number of linked campaigns:

- [Static Tundra](https://intel.threadlinqs.com/actor/Static%20Tundra) — 6 campaigns
- [UAT-8616](https://intel.threadlinqs.com/actor/UAT-8616) — 6 campaigns
- [FSB Center 16](https://intel.threadlinqs.com/actor/FSB%20Center%2016) — 3 campaigns
- [Interlock](https://intel.threadlinqs.com/actor/Interlock) — 3 campaigns
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 2 campaigns
- [Interlock Ransomware Group](https://intel.threadlinqs.com/actor/Interlock%20Ransomware%20Group) — 2 campaigns
- [StrikeShark](https://intel.threadlinqs.com/actor/StrikeShark) — 2 campaigns
- [UAT-9686](https://intel.threadlinqs.com/actor/UAT-9686) — 2 campaigns
- [Akira](https://intel.threadlinqs.com/actor/Akira) — 1 campaign
- [APT36](https://intel.threadlinqs.com/actor/APT36) — 1 campaign
- [BlueDelta](https://intel.threadlinqs.com/actor/BlueDelta) — 1 campaign
- [Cl0p](https://intel.threadlinqs.com/actor/Cl0p) — 1 campaign

## How to prioritise Cisco patching

This order follows the data Threadlinqs holds for Cisco, not a generic severity checklist:

- 19 of 36 Cisco CVEs (53%) are in CISA KEV: treat them as actively exploited and remediate them first, starting with [CVE-2023-20198](https://intel.threadlinqs.com/cve/CVE-2023-20198), [CVE-2018-0171](https://intel.threadlinqs.com/cve/CVE-2018-0171), [CVE-2021-44228](https://intel.threadlinqs.com/cve/CVE-2021-44228).
- 5 CVEs are known to be used in ransomware campaigns; patch these ahead of other KEV entries on internet-facing systems.
- Outside KEV, the highest EPSS scores are [CVE-2025-20362](https://intel.threadlinqs.com/cve/CVE-2025-20362) (50.7%), [CVE-2025-20309](https://intel.threadlinqs.com/cve/CVE-2025-20309) (1.1%), [CVE-2026-20200](https://intel.threadlinqs.com/cve/CVE-2026-20200) (0.8%).
- 16 CVEs score Critical and 12 High on CVSS v3 (maximum 10, average 8.3); sequence these after KEV and high-EPSS items.
- 8 CVEs have a public exploit or proof of concept recorded, which shortens the time from disclosure to attack.

## About this data

Vendor attribution comes from the CNA and CPE product records of each CVE, folded to one vendor name; CVSS, EPSS and KEV status are read from the Threadlinqs CVE catalog; campaign and actor links come from tracked threat records. Counts reflect the data as of 2026-10-05 and refresh daily.

Canonical: https://intel.threadlinqs.com/vendors/cisco
All vendors: https://intel.threadlinqs.com/vendors
Full detection coverage and IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
