Cisco released security updates for 14 vulnerabilities in Cisco IOS and Cisco IOS XE, including the actively exploited zero-day CVE-2025-20352. The flaw is a stack overflow in the SNMP subsystem that can be triggered with crafted SNMP packets over IPv4 or IPv6. Cisco said a remote authenticated attacker can cause a denial of service, while an authenticated attacker with administrator privileges can escalate to remote code execution and full device compromise.
Affected products include unpatched Cisco IOS and IOS XE devices, along with Meraki MS390 and Cisco Catalyst 9300 Series switches running Meraki CS 17 or earlier when SNMP is enabled and vulnerable OIDs have not been explicitly disabled. Cisco urged organizations to use its Software Checker to identify exposure and apply fixes immediately; where patching is not yet possible, recommended mitigations include restricting SNMP access to trusted sources, disabling SNMP, or disabling vulnerable OIDs through device configuration.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Cisco released security updates for 14 vulnerabilities in Cisco IOS and Cisco IOS XE, including CVE-2025-20352, a zero-day in the SNMP subsystem that was being actively exploited. The updates addressed affected Cisco IOS, IOS XE, Meraki MS390, and Catalyst 9300 devices under the conditions described by Cisco and CSIRT.SK.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.