Cisco Advance Notification for Publication of July 15, 2026, Security Advisories
On July 15, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE ID Security Impact Rating CVSS Base Score Cisco RoomOS Security Hardening Release: July 2026 CVE-2026-20150 CVE-2026-20153 CVE-2026-20156 CVE-2026-20157 CVE-2026-20158 CVE-2026-20187 High 8.8 Cisco Identity Services Engine Path Traversal Vulnerability CVE-2026-20146 Medium 5.5 To fully remediate the vulnerabilities that were disclosed on July 15, 2026, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories. For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the Foundation: A Predictable, Customer-Focused Response to AI-Accelerated Vulnerability Discovery . Security Impact Rating: Informational
CSIRTS triage
- What
- Cisco will publish advisories for vulnerabilities in multiple products on July 15, 2026.
- Who is affected
- Users of Cisco products mentioned will be affected once advisories are published.
- Urgency
- Remediation will be necessary once vulnerabilities are disclosed.
- Action
- Users should prepare to upgrade to fixed software once advisories are released.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-201500.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-201530.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-201560.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-201570.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-201580.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-201870.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-201460.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-20150 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20153 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20156 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20157 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20158 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20187 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20146 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] Cisco Identity Services Engine (ISE): Vulnerability allows file manipulationcert-bund
- unknownMultiple vulnerabilities in Cisco RoomOS (July 16, 2026)cert-fr-avis
- highCVE-2026-20187: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Roo…nvd
- highCVE-2026-20158: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Roo…nvd
- highCVE-2026-20157: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Roo…nvd
- highCVE-2026-20156: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Roo…nvd
- highCVE-2026-20153: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Roo…nvd
- highCVE-2026-20150: As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Roo…nvd
- mediumCVE-2026-20146: A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connect…nvd
- highCisco RoomOS Security Hardening Release: July 2026cisco-psirt
- mediumCisco Identity Services Engine Path Traversal Vulnerabilitycisco-psirt
Recent advisories for Cisco Advance Notification
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalCisco Advance Notification for Publication of August 19, 2026, Security Advisoriescisco-psirt · 2026-08-19
- criticalCisco Advance Notification for Publication of August 5, 2026, Security Advisoriescisco-psirt · 2026-08-05
- highCisco Advance Notification for Publication of July 1, 2026, Security Advisoriescisco-psirt · 2026-07-01
More from Cisco Security Advisories
- criticalCisco Crosswork Security Hardening Release: August 20262026-08-21
- criticalCisco Advance Notification for Publication of August 19, 2026, Security Advisories2026-08-19
- mediumCisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Server-Side Request Forge…2026-08-19
- highCisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability2026-08-19
- criticalCisco Secure Workload Software Security Hardening Release: August 20262026-08-19