Cisco secure web appliance
This hub aggregates every CVE we track for Cisco secure web appliance, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
15
CVEs tracked
1
Critical
1
High
0
In CISA KEV
Severity distribution
MEDIUM12LOW1HIGH1CRITICAL1
Monthly trend
0
0
2
0
0
4
0
0
0
0
0
0
0
0
0
0
0
1
0
1
0
0
0
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Cisco secure web appliance.
- CVE-2026-20152Cisco Secure Web Appliance Authentication Service Traffic Bypass Vulnerability5.3
- CVE-2026-20056Cisco Secure Web Appliance TBD Bypass Vulnerability4.0
- CVE-2025-20207Cisco Secure Email Gateway, Cisco Secure Email and Web Appliance and Cisco Secure Web Appliance SNMP Polling Information Disclosure Vulnerability4.3
- CVE-2025-20185Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance Privilege Escalation Vulnerability3.4
- CVE-2025-20184Cisco Secure Email and Web Manager and Secure Web Appliance Command Injection Vulnerability6.5
- CVE-2025-20183Cisco Secure Web Appliance Range Request Bypass Vulnerability5.8
- CVE-2022-20871Cisco Secure Web Appliance Privilege Escalation Vulnerability6.3
- CVE-2024-20504Cisco Secure Email and Web Manager, Secure Email Gateway, and Secure Web Appliance Stored Cross-Site Scripting Vulnerabilities5.4
- CVE-2024-20435A vulnerability in the CLI of Cisco AsyncOS for Secure Web Appliance could allow an authenticated, local attacker to execute arbitrary commands and elevate privileges to root. This vulnerability...8.8
- CVE-2024-20256A vulnerability in the web-based management interface of Cisco AsyncOS Software for Cisco Secure Email and Web Manager and Secure Web Appliance could allow an authenticated, remote attacker to cond...4.8
- CVE-2023-20215A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance could allow an unauthenticated, remote attacker to bypass a configured rule, allowing traffic onto a...5.8
- CVE-2022-20952A vulnerability in the scanning engines of Cisco AsyncOS Software for Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an unauthenticated, remote attack...5.3
- CVE-2023-20032On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and e...9.8
- CVE-2022-20942A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance, formerly known as Cisco Web Securi...6.5
- CVE-2022-20868A vulnerability in the web-based management interface of Cisco Email Security Appliance, Cisco Secure Email and Web Manager and Cisco Secure Web Appliance could allow an authenticated, remote attac...4.7
Product normalization is registry-driven with AI assist and human review. How it works