Synced 16 Jun 2026 15:24 UTC Account
← Cisco IOS

Cisco IOS vulnerabilities: known CVEs & security history

Cisco · Network / Security · 615 tracked CVEs · 38 actively exploited · updated June 2026 · what is a CVE? →

This is the full list of known vulnerabilities (CVEs) across all Cisco IOS release lines — 615 in total, with 38 actively exploited in the wild. A CVE here doesn't mean your version is affected — check Cisco IOS's current status and the safe version to run.

615
known CVEs
38
actively exploited (KEV)
6
critical severity
0
ransomware-linked

Known Cisco IOS CVEs

Actively-exploited and most-severe first. Showing the top 80 of 615. Open any CVE for full details.

CVESeverityCVSSEPSSYear
CVE-2018-0171⚡ exploited critical 9.8 100% 2018
CVE-2017-12240⚡ exploited critical 9.8 14% 2017
CVE-2017-3881⚡ exploited critical 9.8 99% 2017
CVE-2018-0167⚡ exploited high 8.8 3% 2018
CVE-2017-6744⚡ exploited high 8.8 7% 2017
CVE-2017-6743⚡ exploited high 8.8 11% 2017
CVE-2017-6742⚡ exploited high 8.8 21% 2017
CVE-2017-6740⚡ exploited high 8.8 11% 2017
CVE-2017-6739⚡ exploited high 8.8 11% 2017
CVE-2017-6738⚡ exploited high 8.8 11% 2017
CVE-2017-6737⚡ exploited high 8.8 11% 2017
CVE-2017-6736⚡ exploited high 8.8 71% 2017
CVE-2018-0174⚡ exploited high 8.6 8% 2018
CVE-2018-0173⚡ exploited high 8.6 8% 2018
CVE-2018-0172⚡ exploited high 8.6 8% 2018
CVE-2018-0158⚡ exploited high 8.6 7% 2018
CVE-2018-0155⚡ exploited high 8.6 8% 2018
CVE-2018-0175⚡ exploited high 8 4% 2018
CVE-2025-20352⚡ exploited high 7.7 38% 2025
CVE-2018-0159⚡ exploited high 7.5 7% 2018
CVE-2018-0156⚡ exploited high 7.5 8% 2018
CVE-2018-0154⚡ exploited high 7.5 7% 2018
CVE-2017-12237⚡ exploited high 7.5 7% 2017
CVE-2017-12235⚡ exploited high 7.5 7% 2017
CVE-2017-12234⚡ exploited high 7.5 7% 2017
CVE-2017-12233⚡ exploited high 7.5 7% 2017
CVE-2017-12231⚡ exploited high 7.5 7% 2017
CVE-2017-6627⚡ exploited high 7.5 6% 2017
CVE-2016-6415⚡ exploited high 7.5 88% 2016
CVE-2023-20109⚡ exploited medium 6.6 2% 2023
CVE-2017-12238⚡ exploited medium 6.5 2% 2017
CVE-2017-12232⚡ exploited medium 6.5 2% 2017
CVE-2017-6663⚡ exploited medium 6.5 2% 2017
CVE-2018-0161⚡ exploited medium 6.3 4% 2018
CVE-2018-0180⚡ exploited medium 5.9 5% 2018
CVE-2018-0179⚡ exploited medium 5.9 5% 2018
CVE-2017-12319⚡ exploited medium 5.9 5% 2018
CVE-2004-1464⚡ exploited medium 5.9 5% 2004
CVE-2020-3258 critical 9.8 5% 2020
CVE-2020-3198 critical 9.8 4% 2020
CVE-2025-20363 critical 9 8% 2025
CVE-2011-3271 high 10 11% 2011
CVE-2011-0935 high 10 4% 2011
CVE-2010-1574 high 10 5% 2010
CVE-2010-0581 high 10 5% 2010
CVE-2010-0580 high 10 5% 2010
CVE-2008-0960 high 10 69% 2008
CVE-2006-4950 high 10 6% 2006
CVE-2002-1357 high 10 10% 2002
CVE-2002-1358 high 10 6% 2002
CVE-2002-1359 high 10 80% 2002
CVE-2002-1360 high 10 6% 2002
CVE-1999-0775 high 10 3% 1999
CVE-2015-6280 high 9.3 4% 2015
CVE-2011-4012 high 9.3 1% 2012
CVE-2008-3807 high 9.3 4% 2008
CVE-2008-4128 high 9.3 12% 2008
CVE-2007-5552 high 9.3 3% 2007
CVE-2007-5381 high 9.3 15% 2007
CVE-2007-4286 high 9.3 19% 2007
CVE-2007-4292 high 9.3 3% 2007
CVE-2007-2586 high 9.3 14% 2007
CVE-2006-3291 high 9.3 4% 2006
CVE-2005-3481 high 9.3 7% 2005
CVE-2003-1398 high 9.3 2% 2003
CVE-2001-0537 high 9.3 67% 2001
CVE-2015-0635 high 9 2% 2015
CVE-2007-4285 high 9 3% 2007
CVE-2019-16009 high 8.8 1% 2020
CVE-2020-3234 high 8.8 0% 2020
CVE-2020-3217 high 8.8 1% 2020
CVE-2020-3205 high 8.8 1% 2020
CVE-2020-3199 high 8.8 1% 2020
CVE-2019-12651 high 8.8 3% 2019
CVE-2019-12650 high 8.8 29% 2019
CVE-2019-12648 high 8.8 2% 2019
CVE-2018-0255 high 8.8 1% 2018
CVE-2025-20154 high 8.6 0% 2025
CVE-2024-20433 high 8.6 1% 2024
CVE-2024-20308 high 8.6 1% 2024

535 older / lower-severity CVEs not shown — see Cisco IOS's full record.

Is my Cisco IOS version affected?

The list above spans every release. To know whether your version is affected — and the minimum safe version to upgrade to — check it directly.

Check your Cisco IOS version → · Monitor Cisco IOS for new CVEs →

Cisco IOS vulnerabilities — frequently asked

How many known vulnerabilities does Cisco IOS have?

IsItPatched tracks 615 CVEs for Cisco IOS, 38 of which are actively exploited (CISA KEV). 6 are critical-severity and 356 high-severity. These span every release line — what matters is whether the version you run is affected.

Does Cisco IOS have any actively-exploited vulnerabilities?

Yes — 38 Cisco IOS CVEs are in CISA's Known Exploited Vulnerabilities catalog, meaning they are confirmed exploited in the wild. Patch these as a priority.

What is the most severe Cisco IOS vulnerability?

Among tracked issues, CVE-2018-0171 (CRITICAL, CVSS 9.8), which is actively exploited, ranks highest — a Improper input validation weakness.

Is Cisco IOS safe to use?

It depends on the version. The latest supported Cisco IOS release clears the known issues; older versions may still be affected. Check the exact version you run for a verdict.

CVE data aggregated from NVD, CISA KEV and EPSS (FIRST.org). Related: Cisco IOS security status · Cisco IOS end-of-life · actively-exploited CVEs. Always verify against Cisco's advisories — see our disclaimer.