Cisco is shifting to a scheduled, twice-monthly security release model starting July, driven by AI-accelerated vulnerability discovery that has outpaced traditional ad-hoc patching. Releases will occur on the 1st and 3rd Wednesdays of each month, with 7-day advance notice of affected products. CVEs will be bundled by CWE category rather than assigned individually. Core network OS products (IOS XE, IOS XR, NX-OS, Firepower/ASA, SD-WAN) will follow a quarterly release schedule. Cisco's agentic discovery framework uses multiple specialized agents for static analysis, live testing, and exploit simulation to identify and fix entire classes of defects across the portfolio. Emergency out-of-band patches for zero-days and active exploitation remain unchanged.

7m read timeFrom blogs.cisco.com
Post cover image
Table of contents
Why we are changing our cadenceWhat is changingWhat this means for youWhat PSIRT will publishWhat stays the sameHow we are prioritizing engineering capacityEasing the Patching ProcessClosing
74 Impressions