Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2015-6420
n/a n/a — Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, …
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H H H 9.8 .1876 97.2 —
AFFECTED
Product Versions Fixed
n/a n/a – —
TIMELINE
Aug 17 Reserved by cisco
Dec 15 Published (CNA: cisco)
Oct 7 EXPLOIT PUBLISHED — CVE-2015-6420. Public exploit reference added.
Description
Serialized-object interfaces in certain Cisco Collaboration and Social Media; Endpoint Clients and Client Software; Network Application, Service, and Acceleration; Network and Content Security Devices; Network Management and Provisioning; Routing and Switching - Enterprise and Service Provider; Unified Computing; Voice and Unified Communications Devices; Video, Streaming, TelePresence, and Transcoding Devices; Wireless; and Cisco Hosted Services products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| August 17, 2015 | Reserved | Reserved by cisco |
| December 15, 2015 | Published | Published (CNA: cisco) |
| October 7, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2015-6420. Public exploit reference added. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| n/a | n/a | — | n/a | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2015-6420 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Thursday, October 8, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.