CVE Tools

Cisco IOS

692 CVEs tracked. 40 of them are in CISA KEV.

This hub aggregates every CVE we track for Cisco IOS, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.

Cisco IOS CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Cisco IOS CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-028
2025-030
2025-040
2025-055
2025-060
2025-070
2025-082
2025-095
2025-100
2025-110
2025-120
2026-010
2026-020
2026-032
2026-040
2026-050
2026-060
2026-070
2026-081
2026-090

Severity

How the 692 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical375%
  • High36753%
  • Medium27640%
  • Low122%

Latest CVEs

The 15 most recently published vulnerabilities affecting Cisco IOS.

  1. CVE-2026-20301Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerability8.6
  2. CVE-2026-20125A vulnerability in the HTTP Server feature of Cisco IOS Software and Cisco IOS XE Software Release 3E could allow an authenticated, remote attacker to cause an affected device to reload unexpectedl...7.7
  3. CVE-2026-20012A vulnerability in the Internet Key Exchange version 2 (IKEv2) feature of Cisco IOS Software, Cisco IOS XE Software, Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, and Cisco Secu...8.6
  4. CVE-2025-20363A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software, Cisco IOS Software, Cisco IOS XE Softwa...9.0
  5. CVE-2025-20149A vulnerability in the CLI of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, local attacker to cause an affected device to reload unexpectedly, resulting in a denial of ...6.5
  6. CVE-2025-20327A vulnerability in the web UI of Cisco IOS Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vul...7.7
  7. CVE-2025-20352A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow the following: An authenticated, remote attacker with low...7.7
  8. CVE-2025-20160A vulnerability in the implementation of the TACACS+ protocol in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to view sensitive data or bypass authen...8.1
  9. CVE-2025-20239A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco IOS Software, IOS XE Software, Secure Firewall Adaptive Security Appliance (ASA) Software, and Secure Firewall Threat...8.6
  10. CVE-2025-20225A vulnerability in the Internet Key Exchange Version 2 (IKEv2) feature of Cisco IOS Software, IOS XE Software, Secure Firewall Adaptive Security Appliance (ASA) Software, and Secure Firewall Threat...5.8
  11. CVE-2025-20196A vulnerability in the Cisco IOx application hosting environment of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the Cisco IOx application h...5.3
  12. CVE-2025-20164A vulnerability in the Cisco Industrial Ethernet Switch Device Manager (DM) of Cisco IOS Software could allow an authenticated, remote attacker to elevate privileges. This vulnerability is due t...8.3
  13. CVE-2025-20181A vulnerability in Cisco IOS Software for Cisco Catalyst 2960X, 2960XR, 2960CX, and 3560CX Series Switches could allow an authenticated, local attacker with privilege level 15 or an unauthenticated...6.8
  14. CVE-2025-20137A vulnerability in the access control list (ACL) programming of Cisco IOS Software that is running on Cisco Catalyst 1000 Switches and Cisco Catalyst 2960L Switches could allow an unauthenticated, ...4.7
  15. CVE-2025-20154Cisco IOS, IOS XE and IOS XR Software TWAMP Denial of Service Vulnerability8.6

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store