Cisco Products Multiple Vulnerabilities
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
CSIRTS triage
- What
- Cisco products contain multiple unspecified vulnerabilities.
- Who is affected
- Cisco product deployments with the affected CVE versions.
- Urgency
- High; multiple CVEs suggest active vulnerability surface but exploitation status unclear.
- Action
- Consult Cisco security advisories for CVE-2026-20349, CVE-2026-20294, CVE-2026-20316, CVE-2026-20337, CVE-2026-20338, CVE-2026-20339, CVE-2026-20345, and CVE-2026-20346 for product-specific patches.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://www.hkcert.org/security-bulletin/cisco-products-multiple-vulnerabilities_20260812
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-20349Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 56% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-202940.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Exploitation confirmedCVE-2026-20316Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 53% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-203370.36% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 29% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-203380.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-203390.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-203450.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-203460.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-203470.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-203480.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-20349 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20294 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20316 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20337 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20338 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20339 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20345 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20346 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20347 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-20348 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highClamAV Vulnerabilities Affecting Cisco Products: August 2026cisco-psirt
- highexploitedAL26-018 - Vulnerability affecting Cisco ASA and Secure Firewall Threat Defense Software Remote Access SSL VPN…cccs
- unknownexploitedNCSC-2026-0295 [1.00] [M/H] Vulnerability patched in Cisco Secure Firewall ASA and FTD softwarencsc-nl
- unknownexploitedCisco security advisory (AV26-807)cccs
- highexploited[NEW] [high] Cisco ASA (Adaptive Security Appliance) and Secure Firewall Threat Defense: Vulnerability enables…cert-bund
- unknownexploitedVulnerability in Cisco products (August 12, 2026)cert-fr-avis
- highexploitedCisco Secure Firewall Management Center Software Static Credential Vulnerabilitycisco-psirt
- highexploitedCVE-2026-20349: A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Securi…nvd
- highexploitedCisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SS…cisco-psirt
- highexploitedCISA Adds Three Known Exploited Vulnerabilities to Catalogcisa
- high[NEW] [high] ClamAV: Multiple vulnerabilities allow Denial of Service and disclosure of informationcert-bund
- highCVE-2026-20339: ClamAV PESpin File Format Processing Integer Overflow Vulnerabilitymsrc
More from HKCERT Security Bulletins
- unknownMicrosoft Edge Multiple Vulnerabilities2026-08-17
- unknownVMWare Products Multiple Vulnerabilities2026-08-14
- unknownPalo Alto Products Multiple Vulnerabilities2026-08-14
- unknownMongoDB Multiple Vulnerabilities2026-08-13
- unknownIBM WebSphere Products Multiple Vulnerabilities2026-08-13