25 marca 2026 r. firma Cisco opublikowała komunikat bezpieczeństwa w celu usunięcia luk w zabezpieczeniach następujących produktów:

  • Cisco Catalyst 9300 Series Switches
  • Cisco Catalyst 9200 Series Switches
  • Cisco Catalyst 9000 Series Switches
  • Cisco Catalyst ESS9300 Embedded Series Switches
  • Cisco IOS Software
  • Cisco IOS XE Software
  • Cisco Secure Firewall ASA Software
  • Cisco Secure FTD Software
  • Cisco Catalyst IE9310 and IE9320 Rugged Series Switches
  • Cisco IE3500 and IE3505 Rugged Series Switches
  • Cisco Catalyst CW9800H Wireless Controllers
  • Cisco Catalyst CW9800M Wireless Controllers
  • Cisco Catalyst CW9800H1 Wireless Controllers
  • Cisco Meraki MS390
  • Cisco Catalyst SD-WAN Manager
OpisNumer CVEKrytycznośćCVSS
Cisco IOS XE Software for Catalyst 9000 Series Switches DHCP Snooping Denial of Service VulnerabilityCVE-2026-20084Wysoka8.6
Cisco IOS XE Wireless Controller Software for the Catalyst CW9800 Family CAPWAP Denial of Service VulnerabilityCVE-2026-20086Wysoka8.6
Cisco IOS, IOS XE, Secure Firewall Adaptive Security Appliance, and Secure Firewall Threat Defense Software IKEv2 Denial of Service VulnerabilityCVE-2026-20012Wysoka8.6
Cisco IOS Software and IOS XE Software Release 3E HTTP Server Denial of Service VulnerabilityCVE-2026-20125Wysoka7.7
Cisco IOS XE Software TLS Memory Exhaustion Denial of Service VulnerabilityCVE-2026-20004Wysoka7.4
Cisco IOS XE Software for Cisco Catalyst and Rugged Series Switches Secure Boot Bypass VulnerabilityCVE-2026-20104Wysoka6.1
Cisco IOS XE Software Denial of Service VulnerabilityCVE-2026-20110Średnia6.5
Cisco IOS XE Software Secure Copy Protocol Server Denial of Service VulnerabilityCVE-2026-20083Średnia6.5
Cisco IOS XE Software Secure Channel for Meraki Information Disclosure VulnerabilityCVE-2026-20115Średnia6.1
Cisco IOS XE Software Lobby Ambassador Privilege Escalation VulnerabilityCVE-2026-20114Średnia5.4
Cisco IOx Application Hosting Environment Carriage Return Line Feed Injection VulnerabilityCVE-2026-20113Średnia5.3
Cisco IOx Application Hosting Environment Stored Cross-Site Scripting VulnerabilityCVE-2026-20112Średnia4.8