CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Cisco Advance Notification for Publication of July 15, 2026, Security Advisories

highCVE-2026-20150CVE-2026-20153CVE-2026-20156CVE-2026-20157CVE-2026-20158CVE-2026-20187
On July 15, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco RoomOS Security Hardening Release: July 2026 CVE-2026-20150 CVE-2026-20153 CVE-2026-20156 CVE-2026-20157 CVE-2026-20158 CVE-2026-20187 High 8.8 Cisco Identity Services Engine Path Traversal Vulnerability CVE-2026-20146 Medium 5.5 To fully remediate the vulnerabilities that were disclosed on July 15, 2026, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories. For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the Foundation: A Predictable, Customer-Focused Response to AI-Accelerated Vulnerability Discovery . Security Impact Rating: Informational

CSIRTS triage

What
Cisco will publish advisories for vulnerabilities in multiple products on July 15, 2026.
Who is affected
Users of Cisco products mentioned will be affected once advisories are published.
Urgency
Remediation will be necessary once vulnerabilities are disclosed.
Action
Users should prepare to upgrade to fixed software once advisories are released.

AI-assisted analysis generated from the source advisory — verify against the original.

Details

Source
Cisco Security Advisories (INTL · vendor-psirt · site)
Severity
high
Published
2026-07-15
Exploitation
Not in CISA KEV at last sync

Original advisory: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-ILh3ZrP5?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Advance%20Notification%20for%20Publication%20of%20July%2015,%202026,%20Security%20Advisories%26vs_k=1

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-20150coverage & exploitation statusNVD · CVE.org
CVE-2026-20153coverage & exploitation statusNVD · CVE.org
CVE-2026-20156coverage & exploitation statusNVD · CVE.org
CVE-2026-20157coverage & exploitation statusNVD · CVE.org
CVE-2026-20158coverage & exploitation statusNVD · CVE.org
CVE-2026-20187coverage & exploitation statusNVD · CVE.org
CVE-2026-20146coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Cisco Advance Notification

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from Cisco Security Advisories