ZeroHour
Product

Cisco Secure Firewall Adaptive Security Appliance

2 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

Cisco security advisory (AV26-932)

Cisco September 2026 updates fix flaws in ASA, FTD, FMC, ISE, and Nexus Dashboard; CISA added actively exploited CVE-2026-76460 to KEV.

Cisco's September 2026 hardening releases address vulnerabilities across Secure Firewall Threat Defense and Management Center, ASA, Identity Services Engine, ISE-PIC, and Nexus Dashboard, with fixes in branches such as FTD/FMC 7.0.10-10.1.0, ASA 9.16.4.103-9.24.1.26, and ISE 3.1 Patch 12-3.5 Patch 4. CISA added CVE-2026-76460, a Cisco Identity Services Engine authentication bypass, to its Known Exploited Vulnerabilities catalog on September 16, 2026. The Canadian Centre for Cyber Security urges users and administrators to review the advisories and apply the updates.

Canadian Centre for Cyber Securityupdated · 19h agofirst · 1d agoAdvisory in the wild 9 sourcesCVE-2026-76460

Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard

Cisco patches dozens of critical flaws in FMC, ISE and Nexus Dashboard, including ISE bugs and an authentication bypass already exploited in the wild.

Cisco released patches for dozens of critical-severity CVEs in Secure Firewall Management Center, Identity Services Engine and Nexus Dashboard. ISE updates cover 20 CVEs including 12 critical ones; three publicly disclosed flaws (CVE-2026-20282, CVE-2026-20283, CVE-2026-20284) enable SQL injection, data tampering and command execution but require administrative access. FMC patches fix 18 CVEs, eight critical, several shared with ASA and FTD, where CVE-2026-20079 and CVE-2026-20316 have been exploited since August. Cisco also warned of a critical-severity ISE authentication bypass exploited in the wild as a zero-day.

Related CVEs

  • Authentication bypass to root access in Cisco Secure Firewall Management Center
    CVE-2026-20079 is an authentication bypass (CWE-288) in the web interface of Cisco Secure Firewall Management Center (FMC) Software, caused by an improper system process created at boot time. An unauthenticated, remote attacker can exploit it by sending crafted HTTP requests to the FMC web interface, which allows the execution of script files and commands on the device. A successful exploit grants the attacker root access to the underlying operating system, giving full control of the management platform (CVSS 3.1: 10.0, network-exploitable, no privileges or user interaction required, scope changed). The flaw affects Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management deployments. Cisco has confirmed the vulnerability is being exploited in active attacks, it carries a 35.9% EPSS score (98th percentile), and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-09.
    · Cisco Secure Firewall Management Center (FMC) Software (web interface) · Cisco Security Cloud Control (SCC) Firewall Management KEV PoC ×2large
  • Unauthenticated Management Interface Bypass in Cisco ISE and ISE-PIC
    Cisco Identity Services Engine (ISE) and the Cisco ISE Passive Identity Connector (ISE-PIC) contain an incorrect use of privileged APIs flaw (CWE-648) affecting the web-based management interface. An unauthenticated, remote attacker with network access to that interface can send requests that invoke privileged APIs without authenticating, bypassing the interface's access controls. Successful exploitation grants the attacker unauthorized access to the affected device, presumably with the administrative capabilities available through the management interface, such as control over network access policy and visibility into identity data. Any organization running an affected Cisco ISE or ISE-PIC release is potentially affected, with risk highest where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-16, indicating exploitation in the wild, though no public proof-of-concept is known and CVSS scoring is pending.
    · Cisco Identity Services Engine (ISE) · Cisco ISE Passive Identity Connector (ISE-PIC) KEV PoC large
  • Hard-Coded Password Vulnerability in Cisco Secure Firewall Management Center
    Cisco Secure Firewall Management Center (FMC), formerly Firepower Management Center, contains a use of hard-coded password vulnerability (CWE-259) that allows an unauthenticated, remote attacker to log in to an affected system. By authenticating with the built-in hard-coded credentials for a low-privileged account, the attacker can gain access to sensitive data within the impacted systems. Any organization running an affected Cisco FMC deployment is exposed, particularly where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-29, indicating active exploitation in the wild, and related reporting describes active exploitation of FMC vulnerabilities. No CVSS score or public proof-of-concept is yet available, but EPSS assigns a 9.8% probability of exploitation within 30 days (95th percentile).
    · Cisco Secure Firewall Management Center (FMC) KEV ransomwarelarge
  • Improper Access Control in Cisco ASA, FTD, and Firewall Management Center
    CVE-2026-20332 covers improper access control issues (CWE-284) in Cisco Secure Adaptive Security Appliance (ASA), Secure Firewall Threat Defense (FTD), and Secure Firewall Management Center (FMC) software, discovered during Cisco's internal security review and addressed in a dedicated software hardening release. A remote attacker who already holds a low-privileged account or session (CVSS PR:L over the network, no user interaction) can trigger the flaw. Because the attack scope is changed and confidentiality, integrity, and availability impacts are all rated high, successful exploitation crosses a security boundary, giving the attacker high-impact control over the device or access to data it protects. Any organization running affected ASA, FTD, or FMC releases is exposed, though exploitation requires valid low-privileged credentials. No public proof-of-concept or known exploitation exists; the flaw was internally discovered by Cisco and is not yet in CISA's Known Exploited Vulnerabilities catalog.
    · Cisco Secure Adaptive Security Appliance (ASA) Software · Cisco Secure Firewall Threat Defense (FTD) Softwaremass
  • Authenticated SQL Injection in Cisco ISE SXP REST API
    Cisco ISE (Identity Services Engine) contains a SQL injection flaw (CWE-943) in its SXP REST API, caused by insufficient validation of user-supplied input in REST API calls. To trigger it, an attacker must send crafted input to the affected device while holding valid administrative credentials, with the SXP service enabled and at least one SXP connection configured. A successful exploit could let the attacker read or modify data in the underlying ISE database, and in single-node deployments could crash the node, denying network access to endpoints that have not yet authenticated. Any organization running Cisco ISE with SXP/TrustSec in this configuration is affected, though the admin-credential requirement makes insider or compromised-credential scenarios the primary risk. No public proof-of-concept or confirmed in-the-wild exploitation is known, and the flaw is not in CISA's KEV catalog.
    · Cisco Identity Services Engine (ISE) — SXP REST APIlarge
  • Authenticated OS command injection (RCE) in Cisco ISE IPsec Open API
    Cisco Identity Services Engine (ISE) contains an operating system command injection flaw (CWE-78) in its IPsec Open API endpoint, caused by insufficient validation of user-supplied input in IPsec Open API calls. An authenticated, remote attacker who holds valid administrative credentials can send crafted input to the endpoint to execute arbitrary commands on the underlying operating system. Exploitation additionally requires the ISE node to have more than one network interface, one of which is configured as an active IPsec tunnel. Although the CVSS 3.1 base score is 6.5 (Medium), Cisco assigned a Security Impact Rating of High because it is easy to escalate from the achieved privilege level to root. No public proof-of-concept or confirmed in-the-wild exploitation is known, and the flaw is not listed in CISA's KEV catalog.
    · Cisco Identity Services Engine (ISE)moderate
  • Authenticated OS Write-Access Flaw in Cisco Identity Services Engine
    CVE-2026-20282 is a vulnerability in Cisco Identity Services Engine (ISE) caused by insufficient validation of user-supplied input. An attacker who already has valid administrative credentials can send a crafted HTTP request to an affected device and obtain write access to the underlying operating system. Cisco rated the flaw High despite the Medium CVSS score because an attacker can easily escalate from the achieved privilege level to root, effectively yielding full control of the appliance. Any organization running Cisco ISE is affected, though exploitation requires both network reachability to the device and stolen or malicious administrator credentials. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known.
    · Cisco Identity Services Engine (ISE)large

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.