CISA KEV Catalog Addition: Cisco IOS CSRF Vulnerability (CVE-2008-4128)
First seen Jul 14, 2026 · Updated Jul 14, 2026
CISA added CVE-2008-4128, a Cross-Site Request Forgery vulnerability in Cisco IOS, to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation. Federal Civilian Executive Branch agencies must remediate this per BOD 26-04, and CISA recommends all organizations prioritize patching this vulnerability on publicly exposed assets.
Technical Analysis
CVE-2008-4128 is a Cross-Site Request Forgery vulnerability affecting Cisco IOS, allowing attackers to trick authenticated administrators into executing unauthorized commands on affected devices, potentially leading to configuration changes or full device compromise. This is a long-known, decade-old vulnerability now confirmed under active exploitation, underscoring that unpatched legacy network infrastructure remains a persistent attack vector. Exploitation typically involves social engineering combined with lack of anti-CSRF tokens in the device's web management interface, granting attackers the ability to alter routing, firewall, or access control configurations. Organizations running AI agent infrastructure that relies on Cisco IOS-based network devices for connectivity to LLM APIs, RAG data sources, or agent orchestration backends could face traffic interception, routing manipulation, or credential/API key exposure if these devices are compromised, making this agent-relevant for any deployment dependent on affected network gear.
Affected Systems
Cisco IOS devices with vulnerable web management/HTTP interfaces exposed to CSRF attacks (specific IOS versions per Cisco advisory for CVE-2008-4128)
Indicators of Compromise
- No specific IOCs (hashes, IPs, domains) provided in source advisory
Remediation Steps
- 1
Patch Cisco IOS
Apply Cisco's official patches or firmware updates addressing CVE-2008-4128 as referenced in Cisco's security advisory.
- 2
Disable unnecessary web management interfaces
Restrict or disable HTTP/HTTPS management interfaces on Cisco IOS devices, or limit access to trusted management networks only.
- 3
Implement anti-CSRF controls
Where patching is not immediately possible, use compensating controls such as VPN-only management access and session token validation.
- 4
Follow BOD 26-04 guidance
FCEB agencies should prioritize remediation of this KEV entry on publicly exposed assets and verify no prior compromise occurred before patching.
- 5
Audit network device exposure
Identify and inventory all Cisco IOS devices, especially those supporting critical infrastructure such as AI agent or RAG pipeline connectivity, and assess exposure to CSRF attack vectors.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.