Cisco Advance Notification for Publication of July 1, 2026, Security Advisories
On July 1, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco Security Advisory CVE-ID Security Impact Rating CVSS Base Score Cisco Catalyst Center Arbitrary File Read Vulnerability CVE-2026-20191 High 7.5 ClamAV Vulnerabilities Affecting Cisco Products: July 2026 CVE-2026-20216 CVE-2026-20213 CVE-2026-20214 CVE-2026-20215 CVE-2026-20217 CVE-2026-20243 CVE-2026-20244 High 7.5 To fully remediate the vulnerabilities that were disclosed on July 1, 2026, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories. For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the Foundation: A Predictable, Customer-Focused Response to AI-Accelerated Vulnerability Discovery . Security Impact Rating: Informational
CSIRTS triage
- What
- Cisco published advisories for multiple vulnerabilities requiring remediation.
- Who is affected
- Customers using Cisco products.
- Urgency
- Remediation is necessary as the vulnerabilities have a high severity rating.
- Action
- Upgrade to the fixed software as indicated in the advisories.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-201910.91% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 57% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-202160.57% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-202130.57% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-202140.57% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-202150.57% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-202170.57% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-202430.57% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-202440.57% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 45% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-20191 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20216 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20213 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20214 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20215 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20217 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20243 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20244 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[UPDATE] [medium] ClamAV: Multiple vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Microsoft Azure Linux (July 15, 2026)cert-fr-avis
- highCVE-2026-20244: ClamAV DMG File Processing Denial of Service Vulnerabilitymsrc
- highCVE-2026-20214: ClamAV FSG File Format Processing Out-of-Bounds Memory Corruption Vulnerabilitymsrc
- highCVE-2026-20213: ClamAV PE File Format Processing Out-of-Bounds Memory Corruption Vulnerabilitymsrc
- highCVE-2026-20217: ClamAV PESpin File Format Processing Out-of-Bounds Memory Corruption Vulnerabilitymsrc
- highCVE-2026-20216: ClamAV InstallShield File Format Processing Resource Exhaustion Vulnerabilitymsrc
- highCVE-2026-20243: ClamAV ALZ Archive Processing Denial of Service Vulnerabilitymsrc
- highCVE-2026-20215: ClamAV 7Zip File Format Processing Out-of-Bounds Memory Corruption Vulnerabilitymsrc
- unknownUSN-8517-1: ClamAV vulnerabilitiesubuntu
- highCisco Catalyst Center Arbitrary File Read Vulnerabilitycisco-psirt
- medium[UPDATE] [medium] Cisco Catalyst Center: Vulnerability Allows Information Disclosurecert-bund
More from Cisco Security Advisories
- criticalCisco Crosswork Security Hardening Release: August 20262026-08-21
- criticalCisco Advance Notification for Publication of August 19, 2026, Security Advisories2026-08-19
- mediumCisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Server-Side Request Forge…2026-08-19
- highCisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability2026-08-19
- criticalCisco Secure Workload Software Security Hardening Release: August 20262026-08-19