Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CISA’s July 13, 2026 bulletin says Russian FSB Center 16 actors have exploited two Cisco vulnerabilities: CVE-2018-0171 and CVE-2008-4128. The activity involves scanning for and exploiting poorly configured routers and other network devices. CISA advises device owners to strengthen configurations and authentication and monitor for suspicious activity.

Which Cisco vulnerabilities does CISA identify?

CISA’s July 13, 2026 bulletin names CVE-2018-0171 and CVE-2008-4128 as vulnerabilities observed being exploited in Cisco devices and network management portals. CISA says both are listed in its Known Exploited Vulnerabilities (KEV) catalog; its bulletin notes that CVE-2008-4128 was added to the catalog on July 13.

The bulletin does not identify affected software versions, provide indicators of compromise, or give exploit details. Do not assume a particular router is affected—or unaffected—from the CVE names alone. Check the model and software against the relevant Cisco advisory and the full CISA guidance.

Who is behind the activity, and who is being targeted?

CISA and its partners attribute the activity to Russian Federal Security Service (FSB) Center 16 actors. The joint advisory describes opportunistic targeting of critical infrastructure, including communications, the Defense Industrial Base, energy, financial services, government services and facilities, and healthcare and public health.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The accessible CISA summary says the actors scan for and exploit poorly configured routers and other network devices. It does not state how many devices have been compromised or provide an impact count.

What should Cisco router owners do?

CISA’s bulletin recommends improving device configurations, enabling stronger authentication protocols, and monitoring for suspicious activity. It encourages network defenders and device owners to review the full advisory’s mitigations and act promptly. The summary does not specify exact settings or a remediation deadline, so use the full guidance and the device-specific Cisco documentation to determine what applies.

Rank #2
Cisco ISR4331/K9 - ISR 4331 - Integrated Service Router (Renewed)
  • Aggregate Throughput: 100 Mbps to 300 Mbps
  • Total onboard WAN or LAN 10/100/1000 ports: 3
  • RJ-45-based ports: 2
  • SFP-based ports: 2
  • Enhanced service-module (SM-X) slot: 1
  • Review configuration: Check router and network-device settings against the manufacturer’s security guidance; pay particular attention to exposed management access.
  • Strengthen authentication: Enable stronger authentication protocols where supported and appropriate for the environment.
  • Monitor activity: Watch for suspicious activity using the logging and monitoring available in your environment, and follow the full advisory’s detection guidance.
  • Verify the device: Match the exact model and software version to current vendor guidance before deciding whether an update, configuration change, or replacement is needed.

How this warning differs from other Cisco security alerts

Several separate Cisco security incidents can be confused with the July 2026 warning. They involve different products, vulnerabilities, and responses.

Alert Products and vulnerabilities What the source says to do
CISA bulletin, July 13, 2026 Cisco devices and network management portals; CVE-2018-0171 and CVE-2008-4128. CISA says the vulnerabilities are being exploited. Improve device configuration, enable stronger authentication, monitor for suspicious activity, and consult the full advisory for detailed mitigations.
Cisco RV router advisory, first published January 11, 2023; updated March 7, 2025 RV016, RV042, RV042G, RV082, RV320, and RV325. CVE-2023-20025 affects RV016/RV042/RV042G/RV082; CVE-2023-20026 and CVE-2023-20118 concern remote command execution across the listed families. Cisco says no software updates will be released for these vulnerabilities. It recommends disabling remote management, blocking WAN access to ports 443 and 60443, and upgrading the end-of-life routers to Meraki or Cisco 1000 Series Integrated Services Routers.
CISA Emergency Directive ED 25-03, September 25, 2025 Cisco Adaptive Security Appliances (ASA) and Firepower devices; CVE-2025-20333 and CVE-2025-20362. The directive told federal agencies to identify deployed ASA and Firepower devices and investigate potential compromise. This is a firewall incident, not the July 2026 router warning.

CISA also published a separate April 18, 2023 alert about APT28 exploitation of CVE-2017-6742 in Cisco routers. That historical alert concerns a different vulnerability and should not be treated as evidence about the two CVEs in the July 2026 bulletin.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Cisco CISCO1921/k9 Series Integrated Services Routers (Renewed)
  • Dual Gigabit Ethernet Ports: Features 2 RJ45 10/100/1000 LAN/WAN ports for high-speed network connectivity and flexible deployment options
  • Enhanced High-Speed WAN Interface Card Slots: Equipped with 2 EHWIC slots for modular expansion and customization of network services
  • Security Feature Set: Includes SEC feature set with embedded hardware encryption acceleration and advanced security services for comprehensive network protection
  • Doublewide EWIC Slot: Provides 1 doublewide EWIC slot that occupies both standard EHWIC slots when used, offering flexibility for high-density interface requirements
  • USB Connectivity: Includes 1 USB port for external storage, configuration management, and additional connectivity options
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the available bulletin does not establish

CISA’s accessible July 2026 summary does not specify affected models or software versions, technical exploit mechanics, compromise indicators, remediation deadlines, or the number of affected devices. Those details should not be inferred from the summary. Use the full CISA advisory and applicable Cisco documentation for device-specific decisions.

Quick Recap

Bestseller No. 2
Cisco ISR4331/K9 - ISR 4331 - Integrated Service Router (Renewed)
Cisco ISR4331/K9 - ISR 4331 - Integrated Service Router (Renewed)
Aggregate Throughput: 100 Mbps to 300 Mbps; Total onboard WAN or LAN 10/100/1000 ports: 3; RJ-45-based ports: 2
$88.11
Bestseller No. 4
Cisco-Linksys E1000 Wireless-N Router
Cisco-Linksys E1000 Wireless-N Router
Use four Fast Ethernet (10/100 Mbps) ports to directly connect wired devices
$77.06
SaleBestseller No. 5
Best Value
Sale
TP-Link ER605, Wired Gigabit VPN Router
  • 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
  • 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
  • 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
  • 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
  • Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q
Rank #4
Cisco-Linksys E1000 Wireless-N Router
  • Enjoy the benefits of Wireless-N in your home--ideal for wireless Internet usage and home office productivity
  • Connect your computers, wireless printers, smartphones, and other wireless devices at up to 300 Mbps of transfer speed
  • Use four Fast Ethernet (10/100 Mbps) ports to directly connect wired devices

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.