we_are_coded.by CODE · The world, decoded
БГ
CISA

A hole from 2008 made the list of actively exploited vulnerabilities

CISASecurity

CISA added a vulnerability disclosed eighteen years ago to its catalog: a CSRF in the web panel of Cisco IOS. Eighteen years later, it's an active attack. The catalog counts only witnessed attacks. The remediation deadline is July 16 - three days after the announcement.

In short
  • CVE-2008-4128 (Cisco IOS, CSRF in the web interface) entered CISA's KEV catalog on July 13, 2026.
  • It's the only addition for the day. The remediation deadline is July 16, 2026.
  • CSRF: if the administrator is logged into the web panel and opens a planted link, the actions execute with his privileges.
Checked on14 July 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

The KEV catalog isn't a list of dangerous holes. There are thousands of dangerous holes and they mean nothing on their own. KEV is a list of holes for which an attack has been WITNESSED. So once something lands there, the question isn't the score on the scale. The question is exactly where you have it turned on.

The facts: CVE-2008-4128 - Cross-Site Request Forgery in the web interface of Cisco IOS. Added to KEV on July 13, 2026, the only addition for the day. Remediation deadline: July 16, 2026. Source: the official catalog of CISA.

Eighteen years. Stop on that number for a second. Nobody discovered anything new - the hole has sat described since 2008. The only thing that changed is that somewhere there are now enough devices with the web panel turned on to make the attack worth it. This is the router in the corner of the office that's been running for years and nobody touches - precisely because it works.

The attack isn't new. What's new is that it's worth it again.

The practical move isn't a patch, it's an inventory. Check what you actually have turned on, and which administrative panel on it faces outward. CISA gives federal agencies three days. Not because closing it is hard - it's hard to find the devices in the first place.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→CISA - Known Exploited Vulnerabilities Catalog→NVD - CVE-2008-4128
Original: https://wearecoded.com/en/articles/cisco-ios-csrf-2008-v-kev.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news