Cisco is raising the baseline security of our products. Across upcoming software releases default protections will increase, insecure legacy features will be retired, and new security capabilities will be added. Most changes apply to new installations, but some will require action on the systems you run today. We're committed to making this transition as seamless and non-disruptive as possible and will continue to update this page for the latest guidance and resources.
While these changes are ongoing, here’s what you can do today:
Inventory your products against their End of Vulnerability Support (EoVSS) and Last Day of Support (LDOS) dates and plan upgrades to current releases.
Apply the relevant Cisco hardening guide today to reduce your attack surface now and smooth the path to future hardened releases.
Cisco and our trusted partners are here to help you navigate this new reality. We offer professional services and support to help your organization, including Cisco Resilient Infrastructure Services. This unified approach is built on three pillars to harden your foundation.
Phasing out insecure capabilities
A core tenet of resilient infrastructure is disabling unused features by default and requiring customers to explicitly enable desired features. To reduce your attack surface and protect sensitive data, insecure features and protocols will be systematically deprecated and eventually removed from identified Cisco products. Our phased removal strategy is planned to span three feature releases to minimize disruption:
You will receive warnings when configuring key insecure features. We strongly recommend discontinuing their use immediately.
In subsequent releases, key insecure features will be disabled by default or require explicit administrator action to enable. Existing deployments will continue to function, but new installations will require intentional enablement. Some features on specific platforms may not have a restriction phase, with only warnings continuing for several releases before removal.
Obsolete features are planned to be removed entirely from future software releases. The timing of removal will vary based on user impact and adoption (e.g., widely adopted features like SNMPv2 will phase out slower than less-used ones).
Resources
Reducing risk, enhancing posture
Enhanced visibility for rapid response
Fortifying access management
Reduce your attack surface today
You can act today as we rollout product enhancements. Hardening guides provide detailed recommendations and best practices to protect sensitive data and enhance device resilience.
These are actions can and should be taken by customers today to protect your network and prepare for upcoming changes.
Cisco strongly recommends running the latest software releases to ensure the strongest security. Avoid using products near or past their End of Vulnerability Support (EoVSS), as no new security fixes are provided beyond this point, leaving your systems exposed. The Last Day of Support (LDOS) marks the final date for any updates or support. Proactive patching and lifecycle management are essential to keep your environment protected.