LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2008-4128: Cisco IOS Cross-Site Request Forgery Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 13, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jul 16, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2008-4128 to its Known Exploited Vulnerabilities catalog on Jul 13, 2026, with a federal patch deadline of Jul 16, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI…

This vulnerability is a cross-site request forgery issue in Cisco IOS that lets remote attackers execute arbitrary commands on affected devices. It matters because successful abuse can grant attackers control over network infrastructure without direct authentication in some cases.

How it works

The weakness is categorized as CWE-352, cross-site request forgery. An attacker crafts requests that an authenticated administrative session processes as legitimate commands.

Confirm the precise request mechanics and any additional affected URIs against the vendor advisory.

Am I affected? How to find it in your systems

Cisco IOS devices that expose the web management interface are the primary concern. Inventory all routers, switches, and appliances running Cisco IOS, paying particular attention to version 12.4.

How to remediate

Apply the vendor update referenced in the advisory as the primary step. After patching, review and harden the web interface configuration for this class of weakness.

If you can't patch immediately

Until the update can be applied, reduce exposure through network controls and monitoring.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to device compromise and subsequent data exposure. You can run a free exposure scan of your email addresses to check known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCisco · IOS
WeaknessCWE-352
Added to CISA KEVJul 13, 2026
Federal patch deadlineJul 16, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities