Vendor Security Posture Report Card: Cisco - Q2 2026
Explore Cisco's security posture in Q2 2026, covering disclosed vulnerabilities, critical security risks, patch management, exploitation trends, and key recommendations for enterprise security teams.
Vendor Security Posture Report Card: Cisco - Q2 2026
Reporting period: Q2 2026 (April 1 to June 30, 2026), covering Catalyst SD-WAN, Unified Communications Manager, Secure Firewall, IOS and IOS XE, and other products in Cisco's security advisories.
Vendor Summary
| Field | Notes |
|---|---|
| Vendor Name | Cisco |
| Product Lines Covered | Catalyst SD-WAN, Unified Communications Manager, Integrated Management Controller, Smart Software Manager On-Prem, Secure Firewall (ASA, FTD, and FMC), and IOS and IOS XE, as reflected in Cisco's published security advisories |
| Reporting Period | Q2 2026 (April 1 to June 30, 2026) |
| Overall Posture Rating | Concerning |
| Prior Period Rating | Unavailable (first report card for this vendor) |
| Total CVEs Disclosed (Period) | Unavailable. Cisco publishes advisories individually, and a complete, verified quarterly CVE tally was not compiled for this edition. |
| Critical and High Severity Count | Unavailable at quarter level. Critical-rated items identified in the period include CVE-2026-20182 (CVSS 10.0), CVE-2026-20093 (9.8), CVE-2026-20160 (9.8), and CVE-2026-20230. |
| CVEs With Confirmed In-the-Wild Exploitation | 4 CVEs published in the period are listed in the KEV catalog, 3 of them exploited zero-days in Catalyst SD-WAN. At least 7 Cisco CVEs were added to the catalog during the quarter. |
Rating Scale Reference
The rating scale applied consistently across every report card in this series, so that ratings remain comparable from one vendor and one period to the next:
| Rating | Criteria |
|---|---|
| Strong | Disclosure volume and severity trend stable or improving, advisories timely and complete, no unpatched critical exposure at time of writing. |
| Adequate | Posture broadly sound with isolated gaps, such as a delayed patch cycle or an incomplete advisory, that do not indicate a systemic pattern. |
| Needs Improvement | Recurring gaps across the period: repeated delayed patches, incomplete disclosures, or a rising severity trend. |
| Concerning | Evidence of a systemic issue: sustained critical exposure, exploitation preceding a patch, or a pattern of incomplete or delayed disclosure. |
This section is included in full on every post, unchanged, so the scale is never assumed to be self-evident.
Introduction
This report card assesses Cisco's security posture for the second quarter of 2026 across its networking, collaboration, and security product lines. Cisco receives an overall rating of Concerning. The factor most responsible is a repeated pattern of exploitation in Catalyst SD-WAN, where three zero-days were exploited in the quarter, including vulnerabilities exploited before fixed software was available.
Scope and Methodology
This selective assessment examines Cisco security advisories published between April 1 and June 30, 2026, together with KEV catalog listings dated in the same window. It is not a comprehensive inventory of every advisory across the product lines named. Because the rating rests mainly on exploitation, patch timing, and advisory quality, it concentrates on the advisories that carried confirmed or suspected exploitation, plus the critical advisories issued in early April.
- Included: Catalyst SD-WAN Manager and Controller, Unified Communications Manager, Integrated Management Controller, Smart Software Manager On-Prem, and the Secure Firewall ASA, FTD, and FMC line, which was the subject of an updated federal emergency directive in April.
- Excluded: Splunk, whose advisories Cisco publishes separately, and third-party and open-source component advisories.
- Data sources: Cisco's published security advisories and advisory notices, CVE and NVD records, and KEV catalog listings.
Data limitations. Cisco's advisory listing is not easily summarized by quarter, and no complete, verified Q2 tally of CVEs or of severity bands was compiled for this edition. The total CVE count and the Critical and High count are therefore reported as unavailable, and this post does not compare volume against the prior period. Cisco also announced a change to how it groups and publishes vulnerabilities that takes effect in July 2026, so counts across the change will not be directly comparable. The KEV figures were compiled from catalog notices and should be read as a minimum.
Vulnerability Disclosure Volume and Trend
The total number of CVEs disclosed in the period is unavailable, and no direction-and-magnitude comparison with Q1 can be stated with confidence. What can be said is structural. Cisco publishes bundled advisory packages twice a year for its firewall line (the most recent before this period was March 4, 2026, covering 48 vulnerabilities across 25 advisories) and for IOS and IOS XE (March 25, 2026). Neither bundle fell in Q2; the selected advisories examined here focus on individual critical and exploited issues rather than a scheduled batch.
Early April brought two critical advisories, one for Integrated Management Controller (CVE-2026-20093, an authentication bypass) and one for Smart Software Manager On-Prem (CVE-2026-20160, a root command execution flaw), both with a CVSS score of 9.8. The remaining disclosures of note in the period were the SD-WAN and Unified Communications Manager issues covered below. The source material does not explain any spike or drop.
Severity Distribution Analysis
A complete CVSS-based breakdown into critical, high, medium, and low bands is not possible for this period, for the reasons given under Scope and Methodology. This is a deviation from the report-card template. The advisories that were identified fall as follows:
- CVSS 10.0: CVE-2026-20182, an authentication bypass in Catalyst SD-WAN that gives a remote attacker administrative access via crafted packets.
- CVSS 9.8: CVE-2026-20093 (Integrated Management Controller) and CVE-2026-20160 (Smart Software Manager On-Prem).
- Critical by Cisco's rating: CVE-2026-20230, an unauthenticated server-side request forgery in Unified Communications Manager, scored at CVSS 8.6.
- Exploited but lower-scored: CVE-2026-20245 (CVSS 7.8) and CVE-2026-20262 (CVSS 6.5), both in Catalyst SD-WAN Manager, were exploited to gain root access or push configuration changes despite mid-range scores.
The exploited issues in the period did not track CVSS closely, since two of the three SD-WAN zero-days carried scores below 8. Whether the distribution is weighted toward higher severity than the prior period or than Cisco's typical pattern cannot be determined from the data compiled.
Patch and Remediation Timeliness
Cisco ships fixes with most advisories and publishes bundled releases on a semiannual cycle, but it has not committed to a fixed monthly cadence for ad hoc advisories during this period. Cisco has announced a move to publishing advisories on the first and third Wednesday of each month from July 2026, which falls after this period and will make adherence measurable in future editions.
- CVE-2026-20182 (SD-WAN, CVSS 10.0): fixed on May 14, 2026. Federal evidence indicates exploitation began in April, so the flaw was exploited for roughly a month before the fix, and Cisco says it became aware of exploitation in May.
- CVE-2026-20245 (SD-WAN Manager): disclosed on June 4 as exploited, with no workaround and no fixed release identified in the initial advisory. Cisco subsequently updated its fixed-release guidance in June; its reference to a May 14 advisory concerned mitigating a related privilege-escalation attack path, not proof that CVE-2026-20245 itself was already fixed in May.
- CVE-2026-20262 (SD-WAN Manager): found during Cisco's internal testing, exploited in limited cases in June, and patched in mid-June.
- CVE-2026-20230 (Unified Communications Manager): patched on June 3; Cisco subsequently confirmed exploitation occurring in June, but the publicly available record does not establish when exploitation began.
Exploitation and Real-World Impact
At least seven Cisco CVEs were added to the KEV catalog during the quarter, and four of them were published in the period itself:
- April 20: three older Catalyst SD-WAN Manager flaws, CVE-2026-20122, CVE-2026-20128, and CVE-2026-20133. Cisco said it became aware of exploitation of the first two in March.
- May 14: CVE-2026-20182, the CVSS 10.0 SD-WAN authentication bypass, added immediately on disclosure.
- June 9: CVE-2026-20245, the SD-WAN zero-day disclosed without a fix.
- June 15: CVE-2026-20262, the SD-WAN Manager arbitrary file write flaw (classified as CWE-22).
- June 25: CVE-2026-20230, the Unified Communications Manager flaw patched on June 3.
Exploitation before fixed software was available is documented for CVE-2026-20182 and CVE-2026-20245. CVE-2026-20262 was also exploited in June, but the available dates do not establish whether its exploitation preceded availability of its fixed releases. The activity was concentrated in one product line and, in the May case, was linked by Cisco's threat research group to a single threat actor that chained flaws to deepen access. The exploitation rate relative to disclosure volume cannot be stated because the volume is unavailable, but the repeated concentration in Catalyst SD-WAN is the defining feature of the quarter.
Advisory and Communication Quality
Cisco's advisories are detailed and consistently structured. Each carries a Security Impact Rating, a CVSS score and vector, a weakness classification, bug identifiers, workaround status, and a fixed-release table, and Cisco provides a software checker and machine-readable feeds. Cisco also gives advance notice of publications. The gaps this quarter concern how quickly advisories reflected exploitation:
- When CVE-2026-20133 entered the KEV catalog on April 20, Cisco had not yet revised its advisory to reflect exploitation.
- Cisco said it became aware of exploitation of CVE-2026-20122 and CVE-2026-20128 in March, but the public catalog listing followed on April 20.
- When CVE-2026-20230 was added to the catalog on June 25, Cisco's advisory had not been updated to show exploitation, and Cisco confirmed it on July 2, a week later.
- The initial CVE-2026-20245 advisory did not identify fixed software; Cisco updated its fixed-release information later in June. References to May fixes for related access paths need to be distinguished from a fix for this CVE itself.
Notable Incidents This Period
The Catalyst SD-WAN exploitation sequence shaped this period's rating. It began with older Manager flaws in April, continued with the CVSS 10.0 authentication bypass in May, and ended with two Manager zero-days in June, each chained to deepen access after initial entry. A separate April update to a federal emergency directive covering Secure Firewall ASA and FTD products indicates that earlier firewall compromises also remained under active response during the quarter. A full technical analysis belongs in a dedicated post.
Historical Trend Comparison
Unavailable, as this is the first report card for Cisco. Catalyst SD-WAN also produced an exploited vulnerability in the first quarter (CVE-2026-20127, disclosed in February), which makes the Q2 pattern a continuation rather than a new development. The Q2 figures serve as the baseline for the next edition.
Risk Context for Organizations
For organizations that rely on Cisco products, a Concerning rating supports closer monitoring and accelerated patch prioritization, concentrated on the product lines where exploitation has repeated. Catalyst SD-WAN Manager and Controller deployments that are reachable from untrusted networks carry the highest exposure, because the quarter's exploitation chained one flaw to another and because one zero-day was disclosed before a fix existed.
Two further points matter for planning. The Unified Communications Manager case involved exploitation confirmed in June after a June 3 fix, though the date exploitation began is unknown, so a patch window measured in months may leave a period of exposure. Cisco's coming switch to a twice-monthly schedule with advance notice should make change windows easier to plan, but it will also group many findings under single umbrella CVE identifiers, which weakens CVE count as a measure of workload.
Overall Posture Rating and Rationale
Cisco's Q2 2026 rating is . Three factors most influenced it:
- Exploitation preceding a patch: Catalyst SD-WAN vulnerabilities including the CVSS 10.0 flaw CVE-2026-20182 and CVE-2026-20245 were exploited before fixed software was available, with the latter initially disclosed without a fixed release identified (see Patch and Remediation Timeliness and Exploitation and Real-World Impact).
- Sustained concentration in one product line: at least five of the quarter's seven KEV additions are Catalyst SD-WAN flaws, following an exploited SD-WAN issue in Q1 (see Notable Incidents This Period).
- Lagging advisory updates: advisories were not revised to show exploitation for several days to weeks (see Advisory and Communication Quality).
Cisco's prompt fixes, clear advisory structure, and planned move to a predictable schedule count in its favor, and the rating reflects the incomplete volume data compiled for this edition. The exploitation pattern in a single product line is what places Cisco at Concerning rather than Needs Improvement.
Key Takeaways
- Cisco's overall rating for Q2 2026 is Concerning, driven by repeated exploitation in Catalyst SD-WAN.
- At least seven Cisco CVEs were added to the KEV catalog in the quarter, and three exploited zero-days in Catalyst SD-WAN were disclosed in May and June.
- CVE-2026-20182, rated CVSS 10.0, was reportedly exploited for about a month before its May 14 fix, and CVE-2026-20245 was disclosed with no patch available.
- Unified Communications Manager flaw CVE-2026-20230 was patched on June 3 and subsequently confirmed exploited in June; the exact start of exploitation is unknown, and Cisco updated its advisory after the catalog listing.
- Cisco's twice-monthly advisory schedule begins in July 2026, which will make future cadence easier to assess.
Conclusion
Cisco's second quarter combined detailed advisories and prompt fixes with a sustained run of exploitation in Catalyst SD-WAN that outpaced patching in two cases. These findings feed the ongoing vendor and compliance monitoring work behind this series. The Q3 2026 report card for Cisco is expected after the third-quarter reporting window closes.
Instantly Fix Risks with Saner Patch Management
Saner patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.
It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.
Experience the fastest and most accurate patching software here.




