Cisco IOS XE ↗
Summary iPlain-English security verdict for Cisco IOS XE, generated from its current health score, actively-exploited vulnerabilities, and latest supported version.
Cisco IOS XE currently scores 23/100 — high risk. 1 of its known vulnerability is being actively exploited in the wild (CISA KEV), including CVE-2023-44487. Upgrade soon — serious vulnerabilities are open and a fix usually exists. Note: this product is assessed at the product level on recent (365-day) activity rather than an exact per-version match, so it is never marked a confident "healthy".
Disclosure trend iNew CVEs published for Cisco IOS XE each year (NVD). A higher bar means more disclosures that year — more scrutiny, not necessarily less safe.
Patch priority — what to act on iThe issues to fix first — actively exploited (CISA KEV) first, then by exploitation probability (EPSS), then severity. Each row's "→ fixed in" is the earliest version that patches it; "see advisory" means no fixed version is published.
Most urgent first — actively exploited, then likeliest to be exploited.
CVE-2023-44487 HIGH exploited Uncontrolled resource consumption EPSS 100% → fixed in 17.15.1 CVE-2025-20363 CRITICAL CWE-122 EPSS 8% → see advisory CVE-2026-20272 CRITICAL Injection EPSS 0% → see advisory CVE-2026-20267 CRITICAL Improper access control EPSS 0% → see advisoryGet alerted about Cisco IOS XE
Be emailed the moment Cisco IOS XE gets a newly exploited vulnerability (CISA KEV) or a release reaches end of life. Free · double opt-in · unsubscribe anytime.
We email only on real events for Cisco IOS XE — no marketing, no sharing, and we never know what you run. Track your whole stack →
Versions & lifecycle iWhen each release line stops receiving security patches (end-of-life). After EOL there are no more fixes — plan upgrades before these dates.
How long each Cisco IOS XE release line is supported — and when it sunsets.
Full Cisco IOS XE end-of-life dates & support timeline →
Frequently asked
Is Cisco IOS XE safe and patched?
Cisco IOS XE currently scores 23/100 — high risk. 1 of its known vulnerability is being actively exploited in the wild (CISA KEV), including CVE-2023-44487. Upgrade soon — serious vulnerabilities are open and a fix usually exists. Note: this product is assessed at the product level on recent (365-day) activity rather than an exact per-version match, so it is never marked a confident "healthy".
What should I do about Cisco IOS XE now?
Review the patch-priority list, apply the available fixes (or move to the latest release), and confirm against Cisco's official advisory. Some issues are under active exploitation, so treat this as urgent.
Which versions of Cisco IOS XE are still receiving security updates?
Supported Cisco IOS XE release lines: 17.18, 17.15, 17.12. End-of-life releases no longer receive security patches.
product-level posture (last 365d); exact per-version verdict pending precise version mapping
Latest security news for Cisco IOS XE BETA
Attributed third-party reporting linked to Cisco IOS XE — newest first. We surface and link the source; we don’t assert our own findings. About Emerging →
More across all tracked software on the Emerging feed →
Informational only, from public data (NVD · CISA KEV · EPSS · endoflife.date), and can lag or miss vendor-specific fixes. Always confirm against Cisco's official advisory before you patch or upgrade — Cisco IOS XE official site ↗