boxscore/security
VENDOR · referenceVendors · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

Cisco

Vendor reference — Cisco · sector: Network & Infrastructure. Cumulative disclosure record across the archive.

Follow Cisco — Atom feed

Career totals

Disclosures & known-exploited
All-timeYTD
CVEs17086
KEV entries9614
Rate & severity
KEV/100Med CVSSMed EPSSCHML
56.57.5.05662143280

KEV/100 = KEV entries ÷ CVEs × 100. Med CVSS / Med EPSS are medians over all disclosures. C/H/M/L = disclosures by CVSS severity band.

Monthly disclosures

Trend (by first-seen month, full archive): ▃▁▁▁█▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▃▄█

Last 12 months (new CVEs by first-seen day)
MonthNew CVEs
2025-093
2025-100
2025-110
2025-121
2026-011
2026-022
2026-032
2026-043
2026-055
2026-0610
2026-0717
2026-0846

Notable CVEs

Ranked by the published formula: KEV → EPSS → CVSS → CVE ID.

Notable (ranked)
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2021-1498100.0YES2021-11-03
CVE-2020-34527.5100.0HIGHYES2021-11-03
CVE-2021-1497100.0YES2021-11-03
CVE-2018-02967.5100.0HIGHYES2021-11-03
CVE-2019-1653100.0YES2021-11-03
CVE-2023-2019899.9YES2023-10-16
CVE-2018-017199.9YES2021-11-03
CVE-2017-388199.9YES2022-03-25
CVE-2025-2028199.9YES2025-07-28
CVE-2019-165299.9YES2022-03-03
CVE-2024-2043999.8YES2025-03-31
CVE-2026-2018299.8YES2026-05-14
CVE-2023-2027399.8YES2023-10-23
CVE-2026-2012799.8YES2026-02-25
CVE-2016-636699.7YES2022-05-24

Recent CVEs

Most recently seen
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2026-203145.0MEDIUM2026-08-19
CVE-2026-202325.4MEDIUM2026-08-19
CVE-2026-203026.1MEDIUM2026-08-19
CVE-2026-201775.3MEDIUM2026-08-19
CVE-2026-203276.5MEDIUM2026-08-19
CVE-2026-203207.5HIGH2026-08-19
CVE-2026-203599.9CRITICAL2026-08-19
CVE-2026-2035710.0CRITICAL2026-08-19
CVE-2026-203197.5HIGH2026-08-19
CVE-2026-2035810.0CRITICAL2026-08-19
CVE-2026-202319.9CRITICAL2026-08-19
CVE-2026-203189.6CRITICAL2026-08-19
CVE-2026-2031710.0CRITICAL2026-08-19
CVE-2026-2031510.0CRITICAL2026-08-19
CVE-2026-2003010.0CRITICAL2026-08-19

Products

This vendor's products with a reference page (≥2 disclosures), by CVE count. A monolithic vendor total dilutes signal; product pages sharpen it.

Products (by CVE count)
ProductCVEsKEV
Cisco Secure Endpoint140
IOS And IOS XE Software1414
Cisco IOS XE Software120
IOS Software1010
Cisco Catalyst SD-WAN Manager82
Cisco RoomOS Software80
Cisco Catalyst SD-WAN Controller61
Cisco Secure Workload60
IOS XR66
Adaptive Security Appliance (ASA) And Firepower Threat Defense (FTD)55
Cisco Identity Services Engine Software50
Small Business RV160, RV260, RV340, And RV345 Series Routers55
Adaptive Security Appliance (ASA)44
Cisco Crosswork Planning40
IOS And IOS XE44
Cisco ISE Passive Identity Connector30
Cisco Secure Firewall Management Center (FMC)32
Cisco Unified Computing System (Standalone)30
IOS32
IOS Software And Cisco IOS XE Software33
Catalyst SD-WAN Manager22
Cisco Adaptive Security Appliance (ASA) Software22
Cisco AnyConnect Secure Mobility Client22
Cisco Industrial Ethernet Switches20
Cisco ThousandEyes Enterprise Agent20
Cisco Unified Computing System E-Series Software (UCSE)20
HyperFlex HX22
IOS XE Software22
IOS, XR, And XE Software22
Identity Services Engine22
Secure Firewall Adaptive Security Appliance And Secure Firewall Threat Defense22

KEV entries

CISA Known Exploited Vulnerabilities (newest addition first)
CVEKEV addedCVSSEPSS %ileSeverity
CVE-2026-203492026-08-118.656.1HIGH
CVE-2026-203162026-07-295.353.4MEDIUM
CVE-2008-41282026-07-1398.2
CVE-2026-202302026-06-258.699.7HIGH
CVE-2026-202622026-06-156.598.0MEDIUM
CVE-2026-202452026-06-097.897.8HIGH
CVE-2026-201822026-05-1499.8
CVE-2026-201282026-04-2093.6
CVE-2026-201332026-04-2098.1
CVE-2026-201222026-04-2097.7
CVE-2026-201312026-03-1910.098.1CRITICAL
CVE-2026-201272026-02-2599.8
CVE-2022-207752026-02-2595.9
CVE-2026-200452026-01-2190.4
CVE-2025-203932025-12-1798.1
CVE-2025-203522025-09-2998.5
CVE-2025-203332025-09-259.998.5CRITICAL
CVE-2025-203622025-09-258.699.7HIGH
CVE-2025-202812025-07-2899.9
CVE-2025-203372025-07-2899.2
CVE-2024-204392025-03-3199.8
CVE-2023-201182025-03-0398.9
CVE-2014-21202024-11-1297.1
CVE-2024-204812024-10-245.896.6MEDIUM
CVE-2024-203992024-07-0290.4

KEV timing

Longest unpatched (KEV due date passed)
CVEDueDays over
CVE-2021-14972021-11-171736
CVE-2021-14982021-11-171736
CVE-2022-207082022-03-171616
CVE-2022-207032022-03-171616
CVE-2022-207012022-03-171616
CVE-2022-207002022-03-171616
CVE-2022-206992022-03-171616
CVE-2019-16522022-03-171616
CVE-2018-01802022-03-171616
CVE-2018-01792022-03-171616

Methodology

Rate statistics are arithmetic over published figures: KEV/100 = KEV entries ÷ CVEs × 100; medians are taken over this vendor's disclosures. Vendor names are normalized (case, punctuation, common aliases) before aggregation; monthly counts are keyed to first-seen day, the day this archive first observed the record, not the upstream publication date.

Raw counts are not comparable across vendors: disclosure practices, product breadth, and CNA conventions differ widely, so a larger number here does not mean less secure software. This is a reference page assembled from the public record — not a record of its own, and not a ranking of vendors by our judgment.

Sources. CVE records from the CVE Program (cvelistV5); enrichment from NVD (NIST); known-exploited status from the CISA KEV catalog; exploit probability from FIRST EPSS.