Cisco Security Advisories · July 2025 — Cisco Security Advisories
8 advisories 10 CVEs

PSIRT bulletins (cisco-sa-*) and cross-source CVEs naming Cisco for 2025-07. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

cisco-sa-cucm-ssh-m4UBdpE7

Cisco PSIRTActive exploitation (sightings)HIGH2025-07-02

Cisco Unified Communications Manager Static SSH Credentials Vulnerability

CVEs:CVE-2025-20309

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-88444 affected Cisco
Upstream advisory

cisco-sa-cuis-file-upload-UhNEtStm

Cisco PSIRTActive exploitation (sightings)HIGH2025-07-16

Cisco Unified Intelligence Center Arbitrary File Upload Vulnerability

CVEs:CVE-2025-20274

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-198393 affected Cisco
CVRFPID-92631 affected Cisco
Upstream advisory

cisco-sa-cuis-ssrf-JSuDjeV

Cisco PSIRTActive exploitation (sightings)HIGH2025-07-16

Cisco Unified Intelligence Center Server-Side Request Forgery Vulnerability

CVEs:CVE-2025-20288

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-198393 affected Cisco
CVRFPID-92631 affected Cisco
Upstream advisory

cisco-sa-ece-xss-CbtKtEYc

Cisco PSIRTActive exploitation (sightings)HIGH2025-07-02

Cisco Enterprise Chat and Email Stored Cross-Site Scripting Vulnerability

CVEs:CVE-2025-20310

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-256410 affected Cisco
Upstream advisory

cisco-sa-piepnm-bsi-25JJqsbb

Cisco PSIRTCoalition ESS < 30%HIGH2025-07-16

Cisco Prime Infrastructure and Evolved Programmable Network Manager Blind SQL Injection Vulnerability

CVEs:CVE-2025-20272

Affected products

ProductStatusVendorPackageEcosystem
CVRFPID-190324 affected Cisco
CVRFPID-213688 affected Cisco
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.