Cisco IOS XE
598 CVEs tracked. 30 of them are in CISA KEV.
This hub aggregates every CVE we track for Cisco IOS XE, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
Cisco IOS XE CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 8 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 21 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 11 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 10 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 9 |
| 2026-09 | 0 |
Severity
How the 598 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical23
- High342
- Medium232
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting Cisco IOS XE.
- CVE-2026-20301Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerability8.6
- CVE-2026-20273Cisco IOS XE Software Security Hardening Release8.6
- CVE-2026-20272Cisco IOS XE Software Security Hardening Release9.8
- CVE-2026-20271Cisco IOS XE Software Security Hardening Release8.6
- CVE-2026-20270Cisco IOS XE Software Security Hardening Release8.6
- CVE-2026-20269Cisco IOS XE Software Security Hardening Release8.6
- CVE-2026-20268Cisco IOS XE Software Security Hardening Release8.6
- CVE-2026-20267Cisco IOS XE Software Security Hardening Release9.0
- CVE-2026-20124Cisco IOS XE Software SNMP Denial of Service Vulnerability7.7
- CVE-2026-20112A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an authenticated, remote attacker to conduct a stored cross-site...4.8
- CVE-2026-20113A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software could allow an unauthenticated, remote attacker to perform a carriage return...5.3
- CVE-2026-20114A vulnerability in the Lobby Ambassador web-based management API of Cisco IOS XE Software could allow an authenticated, remote attacker to elevate their privileges and access management APIs that w...5.4
- CVE-2026-20115A vulnerability in Cisco IOS XE Software for Cisco Meraki could allow a remote, unauthenticated attacker to view confidential device information. This vulnerability is due to a device configurat...6.1
- CVE-2026-20110A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability exists bec...6.5
- CVE-2026-20104A vulnerability in the bootloader of Cisco IOS XE Software for Cisco Catalyst 9200 Series Switches, Cisco Catalyst ESS9300 Embedded Series Switches, Cisco Catalyst IE9310 and IE9320 Rugged Series S...6.1
Product grouping is registry-driven, with AI assist and human review. How it works