Cisco Secure Web Appliance
15 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Cisco Secure Web Appliance, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
Cisco Secure Web Appliance CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 2 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 4 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 1 |
| 2026-03 | 0 |
| 2026-04 | 1 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 15 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High1
- Medium12
- Low1
Latest CVEs
The 15 most recently published vulnerabilities affecting Cisco Secure Web Appliance.
- CVE-2026-20152Cisco Secure Web Appliance Authentication Service Traffic Bypass Vulnerability5.3
- CVE-2026-20056Cisco Secure Web Appliance TBD Bypass Vulnerability4.0
- CVE-2025-20207Cisco Secure Email Gateway, Cisco Secure Email and Web Appliance and Cisco Secure Web Appliance SNMP Polling Information Disclosure Vulnerability4.3
- CVE-2025-20185Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance Privilege Escalation Vulnerability3.4
- CVE-2025-20184Cisco Secure Email and Web Manager and Secure Web Appliance Command Injection Vulnerability6.5
- CVE-2025-20183Cisco Secure Web Appliance Range Request Bypass Vulnerability5.8
- CVE-2022-20871Cisco Secure Web Appliance Privilege Escalation Vulnerability6.3
- CVE-2024-20504Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance Stored Cross-Site Scripting Vulnerabilities5.4
- CVE-2024-20435A vulnerability in the CLI of Cisco AsyncOS for Secure Web Appliance could allow an authenticated, local attacker to execute arbitrary commands and elevate privileges to root. This vulnerability...8.8
- CVE-2024-20256A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Web Appliance could allow an authenticated, remote attacker to cond...4.8
- CVE-2023-20215A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass a configured rule, allowing traffic onto a...5.8
- CVE-2022-20952A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an unauthenticated, remote attack...5.3
- CVE-2023-20032On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and e...9.8
- CVE-2022-20942A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance, formerly known as Cisco Web Securi...6.5
- CVE-2022-20868A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Manager and Cisco Secure Web Appliance could allow an authenticated, remote attac...4.7
Product grouping is registry-driven, with AI assist and human review. How it works