Skip to content
You can now search across every topic, entity and event.What's new
Cisco
OrganisationUS

Cisco

US networking and cybersecurity giant; manufacturer of ASA and Firepower firewall appliances exploited by UAT-4356.

Cisco cut roughly 4,000 staff on 14 May 2026, the same day it reported a record $15.8 billion quarterly revenue, lifting its AI-hardware order target to about $9bn rather than citing weaker demand.

Last refreshed: 3 August 2026 · Appears in 2 active topics

Key Question

Seven SD-WAN CVEs in one calendar year: is Cisco's edge portfolio structurally compromised?

Timeline for Cisco

#12 28 Jul
#12 28 Jul

Mentioned in: KEV patch clocks fell to three days

Cybersecurity: Threats and Defences
#10 14 Jul

Mentioned in: A quiet KEV fortnight, then a 2008 bug

Cybersecurity: Threats and Defences
View full timeline →

Background

Cisco Systems, founded in 1984 in San Jose, California and listed on Nasdaq as CSCO, is the world's dominant enterprise networking vendor. It designs networking (Catalyst, Nexus), security (ASA, Firepower, OpenDNS), collaboration (Webex) and observability (AppDynamics) products, backed by its Talos threat-intelligence Arm, one of the largest commercial threat-research teams in the industry.

Cisco's own infrastructure has been a recurring target through 2026: UAT-4356 planted a boot-sequence implant, FIRESTARTER, in ASA and Firepower firewalls, with one confirmed US federal agency still compromised six months after patching . UNC6780 separately breached over 300 private Cisco GitHub repositories in May, stealing Cisco AI Assistant and Cisco AI Defense source code , and a China-linked actor has kept Cisco SD-WAN under active exploitation since April, reaching an 18-year-old router flaw by mid-July .

Cisco's products form the backbone of enterprise and government networks worldwide, making it simultaneously a critical-infrastructure dependency and a premium attack target, a status the concurrent exploitation across firewalls, AI-defence source code and SD-WAN infrastructure has only reinforced.

Key Issues
Job cuts

Cisco cuts staff on a record quarter

Cisco cut roughly 4,000 staff on 14 May 2026, the same day it reported a record $15.8 billion quarterly revenue. Chief executive Chuck Robbins used the results to lift the company's AI hardware order target to about $9bn, tying the cuts explicitly to an AI-infrastructure bet rather than a downturn .

Cboe and Cloudflare posted the same pattern the same fortnight, and Dell followed on 28 May with 11,000 cuts on record $113.5bn annual revenue. For Cisco specifically, a record quarter is now the trigger point for headcount reduction rather than a reason to hold steady, a pattern Goldman Sachs and CrowdStrike repeated through July.

Common Questions
How many Cisco SD-WAN vulnerabilities have been exploited in 2026?
Seven Cisco SD-WAN CVEs were added to the CISA Known Exploited Vulnerabilities catalogue in 2026 as of 9 June. The most severe is CVE-2026-20182 (CVSS 10.0), exploited by UAT-8616 via authentication bypass in the vdaemon service, which triggered Emergency Directive ED 26-03 with a three-day federal Deadline in May.Source: CISA KEV catalogue
What is Cisco AI Defense and why was its source code stolen?
Cisco AI Defense is Cisco's flagship product for detecting and blocking attacks on LLM-powered applications. In May 2026, UNC6780 (also tracked as TeamPCP) breached more than 300 private Cisco GitHub repositories using credentials stolen via the Trivy supply-chain vulnerability CVE-2026-33634, exfiltrating source code for AI Defense alongside Cisco AI Assistant and other unreleased security products.Source: Google GTIG
Which Cisco products are affected by the April 2026 CISA emergency deadline?
Three vulnerabilities in Cisco Catalyst SD-WAN Manager were added to the CISA Known Exploited Vulnerabilities catalogue on 20 April 2026 with a three-day remediation Deadline: CVE-2026-20122 (API privilege escalation), CVE-2026-20133 (sensitive information exposure), and CVE-2026-20128 (password storage weakness).Source: CISA KEV catalogue
Is Cisco being held responsible for the FIRESTARTER backdoor vulnerabilities?
Cisco patched the two initial-access vulnerabilities in September 2025 and co-operated with CISA and NCSC on the disclosure. The company is positioned as a victim and responder rather than liable party, though critics note the CVSS 9.9 severity and six-month post-patch persistence raise questions about detection tooling provided to customers.Source: CISA/NCSC AA26-113A
What is Cisco Talos and what role did it play in the FIRESTARTER discovery?
Cisco Talos is Cisco's in-house threat-intelligence research team, one of the largest commercial threat-Intel operations globally. Talos tracked the UAT-4356 threat actor and contributed attribution analysis to the FIRESTARTER joint advisory, having previously investigated the same actor's 2024 ArcaneDoor campaign against Cisco network devices.Source: Cisco Talos / CISA AA26-113A
How does the FIRESTARTER implant survive Cisco firewall patches?
FIRESTARTER embeds itself in the Cisco ASA and Firepower boot sequence via startup-configuration manipulation, self-backing-up before any shutdown. Ordinary patch or firmware updates do not touch the boot record where FIRESTARTER lives. The only confirmed removal method is a hard power cycle, which clears volatile memory structures the implant relies on.Source: CISA/NCSC AA26-113A
What is Cisco SD-WAN CVE-2026-20182 and how serious is it?
CVE-2026-20182 is a CVSS 10.0 authentication bypass in Cisco SD-WAN's vdaemon service actively exploited by UAT-8616. CISA added it to the Known Exploited Vulnerabilities catalogue on 14 May 2026 with a three-day federal remediation Deadline. It is the sixth Cisco SD-WAN CVE catalogued in 2026.Source: CISA ED 26-03
What Cisco source code did UNC6780 steal in May 2026?
UNC6780 breached more than 300 private Cisco GitHub repositories using credentials stolen via the Trivy supply-chain CVE (CVE-2026-33634), exfiltrating source code for Cisco AI Assistant and Cisco AI Defense (Cisco's flagship LLM-security product) as well as unreleased products across the security portfolio.Source: Google GTIG
Source Material