Cisco's RV Routers Run Out: The Last Small Business RV Models Lose Support on September 30 and October 31, 2026, With No Replacement
The small-business VPN router in a great many branch offices is about to lose its last vendor support, and Cisco is not offering a successor. Per Cisco's bulletins, the RV160, RV160W, RV260, RV260W, RV260P, RV340W and RV345P reach their Last Date of Support on September 30, 2026, and the RV340 and RV345 on October 31, 2026. Both bulletins say the same thing about migration: there is no replacement available for the series at this time.
Two facts make this worse than a routine end of support. First, the security clock ran out four years earlier: Cisco's end of software maintenance and vulnerability support for these models was September 15, 2022 and October 28, 2022, so an RV340 on the newest firmware has had no vulnerability fixes since then. Second, the older generation is already in CISA's exploited list without a fix: CVE-2023-20118 on the RV016, RV042, RV042G, RV082, RV320 and RV325 was added to the Known Exploited Vulnerabilities catalog on March 3, 2025, and Cisco's advisory states that Cisco “has not released and will not release software updates to address the vulnerabilities.”
The verified dates
Every date below comes from the Cisco End-of-Sale and End-of-Life bulletin for the model, read on cisco.com, and is bound to our Cisco RV page, which records the bulletin behind each model. Cisco's Last Date of Support is the day after which, in its words, all support services for the product are unavailable and the product becomes obsolete.
| Models | Bulletin | End of sale | Vulnerability support ended | Last Date of Support | Replacement |
|---|---|---|---|---|---|
| RV160, RV160W, RV260, RV260W, RV260P, RV340W, RV345P | EOL14500 | September 15, 2021 | September 15, 2022 | September 30, 2026 | None stated |
| RV340, RV345 | RV340/RV345 series bulletin | October 28, 2021 | October 28, 2022 | October 31, 2026 | None stated |
| RV132W, RV134W | RV132W/RV134W bulletin | October 19, 2020 | October 19, 2021 | October 31, 2025 (passed) | None stated |
| RV320, RV325 | RV320/RV325 bulletin | January 30, 2020 | January 29, 2021 | January 31, 2025 (passed) | See bulletin |
| RV042, RV042G | RV042/RV042G bulletin | January 30, 2020 | January 29, 2021 | January 31, 2025 (passed) | See bulletin |
| RV110W, RV130, RV130W, RV215W | EOL13154 | December 2, 2019 | December 1, 2020 | November 30, 2024 (passed) | RV160 / RV160W (themselves ending September 30, 2026) |
| RV082 | EOL10819 | May 5, 2016 | May 5, 2016 | May 31, 2021 (passed) | None stated |
Nine entries in CISA's exploited list, and one Cisco will never fix
CISA's Known Exploited Vulnerabilities catalog holds nine entries against the RV line. The five added together on March 3, 2022 are the buffer-overflow wave against the RV160, RV260, RV340 and RV345, fixed in firmware at the time. The most recent is different in kind: it lands on models that were already past support, and Cisco's advisory closes the door on a fix.
| CVE | Added to KEV | Models | What it was |
|---|---|---|---|
| CVE-2023-20118 | Mar 3, 2025 | RV016, RV042, RV042G, RV082, RV320, RV325 | Command injection in the web management interface; Cisco: no software update, now or ever |
| CVE-2019-15271 | Jun 8, 2022 | RV series | Deserialization of untrusted data in the web management interface |
| CVE-2022-20699 | Mar 3, 2022 | RV160, RV260, RV340, RV345 | Stack-based buffer overflow, one of five added the same day |
| CVE-2022-20700 | Mar 3, 2022 | RV160, RV260, RV340, RV345 | Stack-based buffer overflow |
| CVE-2022-20701 | Mar 3, 2022 | RV160, RV260, RV340, RV345 | Stack-based buffer overflow |
| CVE-2022-20703 | Mar 3, 2022 | RV160, RV260, RV340, RV345 | Stack-based buffer overflow |
| CVE-2022-20708 | Mar 3, 2022 | RV160, RV260, RV340, RV345 | Stack-based buffer overflow |
| CVE-2019-1652 | Mar 3, 2022 | RV320, RV325 | Improper input validation in the web management interface |
| CVE-2019-1653 | Nov 3, 2021 | RV320, RV325 | Information disclosure through improper access controls on URLs |
The pattern for the models still on the calendar: every fix in that table for the RV160 to RV345 shipped before September and October 2022. Anything found after that date on those models has had the same answer as CVE-2023-20118 on the older ones, whether or not a bulletin says so. CISA's Binding Operational Directive 26-02 orders federal agencies to inventory end-of-support edge devices and retire them; from October 31, 2026 that covers every Cisco Small Business RV router ever sold.
Working back from September 30
The destination is not an RV. Cisco's bulletins name no replacement, so the migration is to a different product line or vendor; that is a procurement decision this article does not make for you. What the dates do settle is the order: the RV160 and RV260 family and the RV340W and RV345P first, because their date is four weeks out, then the RV340 and RV345, then anything from the older generations that is still switched on.
The trap: treating the Last Date of Support as the moment risk begins. On this line, vulnerability support ended in 2022. A router on the newest RV firmware is not current; it is four years behind, and CISA's catalog shows what happens to this family when that is true.
The order of operations: (1) inventory every RV by model, including the RV042 and RV320 units at small sites that were never on a refresh list; (2) anything on the past-support rows above is already in CISA's “discontinue use” territory and comes out first; (3) replace the September 30 group before the date and the October 31 group before its date; (4) decommission rather than repurpose, because a retired RV that still answers on the internet with its web management interface exposed is the KEV pattern above waiting to repeat.
Frequently Asked Questions
When do the Cisco RV340 and RV345 reach end of support?
October 31, 2026 is Cisco's Last Date of Support for the RV340 and RV345, per the end-of-sale bulletin for the series. They left sale on October 28, 2021, and software maintenance and vulnerability support ended on October 28, 2022. Cisco states there is no replacement available for the series.
When do the RV160, RV260 and the RV340W and RV345P reach end of support?
September 30, 2026, per Cisco bulletin EOL14500, which covers the RV160, RV160W, RV260, RV260W, RV260P, RV340W and RV345P. End of sale was September 15, 2021 and software maintenance and vulnerability support ended on September 15, 2022. Cisco names no replacement.
Are the older RV320, RV325, RV042 and RV082 still supported?
No. The RV320, RV325, RV042 and RV042G reached their Last Date of Support on January 31, 2025, the RV132W and RV134W on October 31, 2025, the RV110W, RV130, RV130W and RV215W on November 30, 2024, and the RV082 on May 31, 2021.
What is CVE-2023-20118 and does it have a fix?
A command injection flaw in the web management interface of the RV016, RV042, RV042G, RV082, RV320 and RV325, added to CISA's Known Exploited Vulnerabilities catalog on March 3, 2025. Cisco's advisory states that Cisco has not released and will not release software updates to address it, because the routers are past end of life. CISA's required action includes discontinuing use of the product if mitigations are unavailable.
What should an RV router fleet do now?
Replace the routers. There is no supported RV successor, no fix path on any model past its Last Date of Support, and no vulnerability fixes on the newest models since 2022. Retire the old units rather than leaving them reachable from the internet.
How does this relate to CISA's edge-device directive?
CISA's Binding Operational Directive 26-02 orders federal agencies to inventory end-of-support edge devices and retire them. Every RV model past its Last Date of Support is such a device, and from October 31, 2026 that is the entire Cisco Small Business RV line.
Related
- Cisco Small Business RV Series Routers — every model with live status and its bulletin
- The ASA 5500-X is over — Cisco's other small-firewall line, out of support since August 31
- SonicWall's Gen 6 cliff: October 1, 2026 — the same month, the same class of device
- The EOS Edge Device List — every tracked platform, vendor-verified, machine-readable · Exploited & Unpatchable