Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
CRITICAL 9.8
CVE-2026-20272
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehen…
Ios Xe
No fix yet
CRITICAL 9.0
CVE-2026-20267
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehen…
Ios Xe
No fix yet
CRITICAL 9.8
CVE-2026-20156
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive inte…
Roomos
11.32.6.0 / 11.39.1.1+
CRITICAL 9.8
CVE-2026-20157
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive inte…
Roomos
11.32.6.0 / 11.39.1.1+
CRITICAL 9.1
CVE-2026-20181
A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating syst…
Identity Services Engine
3.3.0+
CRITICAL 10.0
CVE-2026-20223
A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to acces…
Secure Workload
3.10.8.3 / 4.0.3.17+
CRITICAL 10.0
CVE-2026-20182 KEVEPSS 92%
May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed …
Catalyst Sd Wan Manager
20.9.9.1 / 20.12.5.4+
CRITICAL 9.9
CVE-2026-20180EPSS 6%
A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying…
Identity Services Engine
3.2.0+
CRITICAL 9.9
CVE-2026-20186EPSS 6%
A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying…
Identity Services Engine
3.2.0+
CRITICAL 9.9
CVE-2026-20147EPSS 12%
A vulnerability in Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operatin…
Identity Services Engine Passive Identity Connector
3.1.0+
CRITICAL 9.8
CVE-2026-20160
A vulnerability in Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to execute arbitrary commands o…
Smart Software Manager On Prem
9-202601+
CRITICAL 10.0
CVE-2026-20131 KEVEPSS 31%
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remot…
Secure Firewall Management Center
Mitigation only
CRITICAL 9.8
CVE-2026-20129
A vulnerability in the API user authentication of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to gain access to an …
Catalyst Sd Wan Manager
20.9.8.2 / 20.12.5.3+
CRITICAL 10.0
CVE-2026-20127 KEVEPSS 88%
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD…
Catalyst Sd Wan Manager
20.9.8.2 / 20.12.5.3+
CRITICAL 9.1
CVE-2026-26057
Skill Scanner is a security scanner for AI Agent Skills that detects prompt injection, data exfiltration, and malicious code patterns. A vulnerabilit…
Skill Scanner
1.0.2+
CRITICAL 9.8
CVE-2026-20045 KEV
A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME…
Unified Communications Manager
14su5+
CRITICAL 10.0
CVE-2025-20393 KEVEPSS 30%
A vulnerability in the Spam Quarantine feature of Cisco AsyncOS Software for Cisco Secure Email Gateway and Cisco Secure Email and Web Manager could …
Asyncos
15.0.2-007 / 15.0.5-016+
CRITICAL 9.8
CVE-2025-20358
A vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified CCX could allow an unauthenticated, remote attacker to bypass…
Unified Contact Center Express
12.5+
CRITICAL 9.8
CVE-2025-20354
A vulnerability in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX could allow an unauthenticated, remote attacker to upload arb…
Unified Contact Center Express
12.5+
CRITICAL 9.9
CVE-2025-20333 KEVEPSS 40%
A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (F…
Adaptive Security Appliance Software
7.0.8.1 / 7.2.9+
CRITICAL 9.0
CVE-2025-20363EPSS 8%
A vulnerability in the web services of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) S…
Ios Xr
7.0.8 / 7.2.10+
CRITICAL 10.0
CVE-2025-20265EPSS 15%
A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remo…
Secure Firewall Management Center
Mitigation only
CRITICAL 10.0
CVE-2025-20337 KEVEPSS 66%
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the und…
Identity Services Engine
Mitigation only
CRITICAL 10.0
CVE-2025-20309
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM …
Unified Communications Manager
Patch available
CRITICAL 10.0
CVE-2025-20282EPSS 27%
A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upload arbitrary files to an aff…
Identity Services Engine
Mitigation only
CRITICAL 10.0
CVE-2025-20281 KEVEPSS 97%
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the und…
Identity Services Engine
Mitigation only
CRITICAL 9.8
CVE-2025-20286
A vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Eng…
Identity Services Engine
Mitigation only
CRITICAL 9.1
CVE-2025-20242EPSS 6%
A vulnerability in the Cloud Connect component of Cisco Unified Contact Center Enterprise (CCE) could allow an unauthenticated, remote attacker to re…
Unified Contact Center Enterprise
Mitigation only
CRITICAL 9.1
CVE-2025-20221
A vulnerability in the packet filtering features of Cisco IOS XE SD-WAN Software could allow an unauthenticated, remote attacker to bypass Layer 3 an…
Ios Xe
Mitigation only
CRITICAL 10.0
CVE-2025-20188EPSS 27%
A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco…
Ios Xe
Mitigation only