ZeroHour
SecurityWeekpublished ()ingested Ionut Arghire
Part of a story covered by 2 sources: “Cisco's September 2026 Patch Wave: Dozens of Fixes for Secure Firewall Management Center, ISE and Nexus Dashboard, With Some Flaws Exploited in the Wild” — merged summary and timeline →

Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard

AI summary · glm-5.3-flash

Cisco patches dozens of critical flaws in FMC, ISE and Nexus Dashboard, including ISE bugs and an authentication bypass already exploited in the wild.

Cisco released patches for dozens of critical-severity CVEs in Secure Firewall Management Center, Identity Services Engine and Nexus Dashboard. ISE updates cover 20 CVEs including 12 critical ones; three publicly disclosed flaws (CVE-2026-20282, CVE-2026-20283, CVE-2026-20284) enable SQL injection, data tampering and command execution but require administrative access. FMC patches fix 18 CVEs, eight critical, several shared with ASA and FTD, where CVE-2026-20079 and CVE-2026-20316 have been exploited since August. Cisco also warned of a critical-severity ISE authentication bypass exploited in the wild as a zero-day.

  • ISE update patches 20 CVEs including 12 critical, with three already publicly disclosed.
  • FMC update resolves 18 CVEs, eight critical, some also affecting ASA and FTD.
  • CVE-2026-20079 and CVE-2026-20316 in the ASA/FTD class have been exploited since August.
  • Cisco separately warns of an ISE authentication bypass exploited in the wild as a zero-day.
  • Nexus Dashboard patches cover six critical- and high-severity injection and bypass flaws.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-20079
Authentication bypass to root access in Cisco Secure Firewall Management Center

CVE-2026-20079 is an authentication bypass (CWE-288) in the web interface of Cisco Secure Firewall Management Center (FMC) Software, caused by an improper system process created at boot time. An unauthenticated, remote attacker can exploit it by sending crafted HTTP requests to the FMC web interface, which allows the execution of script files and commands on the device. A successful exploit grants the attacker root access to the underlying operating system, giving full control of the management platform (CVSS 3.1: 10.0, network-exploitable, no privileges or user interaction required, scope changed). The flaw affects Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management deployments. Cisco has confirmed the vulnerability is being exploited in active attacks, it carries a 35.9% EPSS score (98th percentile), and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-09.

Do: Upgrade FMC (and SCC Firewall Management tenants) to the fixed release specified in Cisco's advisory, prioritizing internet-exposed or externally reachable management interfaces; CISA KEV action applies to federal agencies under BOD 26-04. Until patching, restrict FMC web interface access to trusted management networks and VPNs and check devices for signs of exploitation such as unexpected script execution, unfamiliar processes, or root-level changes. Triage per CISA's Forensics Triage Requirements if compromise is suspected.

10.076% KEV PoC ×2
  • Cisco Secure Firewall Management Center (FMC) Software (web interface)
  • Cisco Security Cloud Control (SCC) Firewall Management
largeplausibly tens of thousands of FMC deployments worldwide (internet-exposed instances likely a smaller subset, likely thousands)
CVE-2026-20282
Authenticated OS Write-Access Flaw in Cisco Identity Services Engine

CVE-2026-20282 is a vulnerability in Cisco Identity Services Engine (ISE) caused by insufficient validation of user-supplied input. An attacker who already has valid administrative credentials can send a crafted HTTP request to an affected device and obtain write access to the underlying operating system. Cisco rated the flaw High despite the Medium CVSS score because an attacker can easily escalate from the achieved privilege level to root, effectively yielding full control of the appliance. Any organization running Cisco ISE is affected, though exploitation requires both network reachability to the device and stolen or malicious administrator credentials. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known.

Do: Review Cisco's advisory for CVE-2026-20282 and upgrade ISE to the fixed release it specifies, prioritizing the fix since Cisco rates the impact High due to the easy path to root. Restrict ISE administration interfaces to dedicated management networks and enforce strong credential hygiene/MFA for ISE admin accounts, since valid admin credentials are required for exploitation. Check ISE admin and audit logs for unexpected administrative sessions or unusual HTTP requests to management endpoints.

4.9
  • Cisco Identity Services Engine (ISE)
large≈10,000–100,000 enterprise ISE deployments/nodes worldwide (estimate), though only a small fraction have admin interfaces reachable by potential attackers
CVE-2026-20283
Authenticated OS command injection (RCE) in Cisco ISE IPsec Open API

Cisco Identity Services Engine (ISE) contains an operating system command injection flaw (CWE-78) in its IPsec Open API endpoint, caused by insufficient validation of user-supplied input in IPsec Open API calls. An authenticated, remote attacker who holds valid administrative credentials can send crafted input to the endpoint to execute arbitrary commands on the underlying operating system. Exploitation additionally requires the ISE node to have more than one network interface, one of which is configured as an active IPsec tunnel. Although the CVSS 3.1 base score is 6.5 (Medium), Cisco assigned a Security Impact Rating of High because it is easy to escalate from the achieved privilege level to root. No public proof-of-concept or confirmed in-the-wild exploitation is known, and the flaw is not listed in CISA's KEV catalog.

Do: Upgrade ISE to the fixed release identified in Cisco's advisory; the related-headline bundle indicates companion ISE RCE/API vulnerabilities fixed at the same time, so apply the full set of patches. Until patching, restrict access to the Open API to trusted management networks, disable the Open API or IPsec tunnel configuration where unused, and limit and rotate administrative credentials. Audit ISE deployments for multi-interface nodes with active IPsec tunnels, as those are the exploitable targets.

6.5
  • Cisco Identity Services Engine (ISE)
moderatelikely on the order of thousands of ISE deployments meet the preconditions, out of an ISE installed base plausibly in the tens of thousands
CVE-2026-20284
Authenticated SQL Injection in Cisco ISE SXP REST API

Cisco ISE (Identity Services Engine) contains a SQL injection flaw (CWE-943) in its SXP REST API, caused by insufficient validation of user-supplied input in REST API calls. To trigger it, an attacker must send crafted input to the affected device while holding valid administrative credentials, with the SXP service enabled and at least one SXP connection configured. A successful exploit could let the attacker read or modify data in the underlying ISE database, and in single-node deployments could crash the node, denying network access to endpoints that have not yet authenticated. Any organization running Cisco ISE with SXP/TrustSec in this configuration is affected, though the admin-credential requirement makes insider or compromised-credential scenarios the primary risk. No public proof-of-concept or confirmed in-the-wild exploitation is known, and the flaw is not in CISA's KEV catalog.

Do: Upgrade ISE nodes to the fixed release identified in Cisco's security advisory (not specified in the source data). As interim mitigation, restrict access to the ISE admin/REST API to trusted management networks, disable the SXP service on nodes that do not use it, and audit admin accounts for credential compromise. Monitor Cisco PSIRT for updated fixed-version guidance.

9.1
  • Cisco Identity Services Engine (ISE) — SXP REST API
large≈10,000–100,000 ISE nodes worldwide (subset of tens of thousands of enterprise ISE deployments that have SXP enabled)
CVE-2026-20316
Hard-Coded Password Vulnerability in Cisco Secure Firewall Management Center

Cisco Secure Firewall Management Center (FMC), formerly Firepower Management Center, contains a use of hard-coded password vulnerability (CWE-259) that allows an unauthenticated, remote attacker to log in to an affected system. By authenticating with the built-in hard-coded credentials for a low-privileged account, the attacker can gain access to sensitive data within the impacted systems. Any organization running an affected Cisco FMC deployment is exposed, particularly where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-29, indicating active exploitation in the wild, and related reporting describes active exploitation of FMC vulnerabilities. No CVSS score or public proof-of-concept is yet available, but EPSS assigns a 9.8% probability of exploitation within 30 days (95th percentile).

Do: Upgrade FMC to the fixed release per Cisco's security advisory, as no specific fixed version is provided in this data. Until patched, restrict access to the FMC management interface, audit recent logins against the affected low-privileged accounts, and rotate or remove any hard-coded credentials. Federal agencies must apply mitigations per CISA BOD 26-04 given the KEV listing dated 2026-07-29.

5.311% KEV ransomware
  • Cisco Secure Firewall Management Center (FMC)
largeplausibly tens of thousands of FMC deployments worldwide (no published install base)
CVE-2026-20332
Improper Access Control in Cisco ASA, FTD, and Firewall Management Center

CVE-2026-20332 covers improper access control issues (CWE-284) in Cisco Secure Adaptive Security Appliance (ASA), Secure Firewall Threat Defense (FTD), and Secure Firewall Management Center (FMC) software, discovered during Cisco's internal security review and addressed in a dedicated software hardening release. A remote attacker who already holds a low-privileged account or session (CVSS PR:L over the network, no user interaction) can trigger the flaw. Because the attack scope is changed and confidentiality, integrity, and availability impacts are all rated high, successful exploitation crosses a security boundary, giving the attacker high-impact control over the device or access to data it protects. Any organization running affected ASA, FTD, or FMC releases is exposed, though exploitation requires valid low-privileged credentials. No public proof-of-concept or known exploitation exists; the flaw was internally discovered by Cisco and is not yet in CISA's Known Exploited Vulnerabilities catalog.

Do: Upgrade ASA, FTD, and FMC devices to the Cisco software hardening release cited in the Cisco PSIRT advisory (specific fixed version numbers should be confirmed there). Until patched, restrict management-plane and VPN access to trusted users and networks, and audit low-privileged accounts and their permissions for access-boundary gaps. Monitor Cisco PSIRT for updates, as exploitation requires a valid low-privileged credential and no public exploit is currently known.

9.9
  • Cisco Secure Adaptive Security Appliance (ASA) Software
  • Cisco Secure Firewall Threat Defense (FTD) Software
  • Cisco Secure Firewall Management Center (FMC) Software
masshundreds of thousands of internet-exposed Cisco ASA/FTD devices; total deployed base likely in the millions
Full article422 words · extracted from securityweek.com · click to collapse

Cisco on Wednesday announced patches for dozens of critical-severity CVEs in Secure Firewall Management Center (FMC), Identity Services Engine (ISE), and Nexus Dashboard.

The ISE security updates stand out with patches for 20 CVEs, including 12 critical-severity flaws. Three of the issues have already been publicly disclosed, Cisco warned.

Tracked as CVE-2026-20282, CVE-2026-20283, and CVE-2026-20284, they can be exploited by remote attackers for SQL injection, data tampering, and arbitrary command execution. Administrative access is required for all three.

CVE-2026-20282 and CVE-2026-20283 are medium-severity bugs, but Cisco considers them high risk, as they provide attackers with a level of privileges that could easily lead to root access.

CVE-2026-20284 is a critical-severity insufficient validation of user-supplied input that can allow attackers to view or modify data and cause a denial-of-service (DoS) condition.

“The Cisco PSIRT is aware that a public announcement is available for the vulnerabilities that are described in this advisory,” the company notes.

Advertisement. Scroll to continue reading.

Cisco’s advisories detail six other critical-severity ISE vulnerabilities: three remote code execution (RCE) issues, two command injection flaws leading to command execution with root privileges, and an authentication bypass in the REST API.

Multiple other critical-severity flaws related to injection, XSS, bypass, information disclosure, path traversal, and related attacks that are collectively tracked under five CVEs were also patched in ISE.

Cisco’s FMC updates resolve 18 CVEs, including eight critical-severity bugs that could allow remote attackers to execute arbitrary commands as root, obtain root privileges, bypass protections and authentication, and perform other types of attacks.

Four of the critical-severity CVEs address multiple vulnerabilities grouped based on their underlying class, and also affect Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD).

Of these, CVE-2026-20332 stands out, as two vulnerabilities in the same class have been exploited in the wild: CVE-2026-20079 and CVE-2026-20316, disclosed in March and July, respectively, and exploited since August.

Cisco also rolled out patches for six critical- and high-severity CVEs covering multiple authentication, code/command injection, cleartext storage, SQL injection, and path traversal vulnerabilities in Nexus Dashboard.

On Wednesday, Cisco also warned of a critical-severity authentication bypass in ISE that has been exploited in the wild as a zero-day.

Additional information is available on the company’s security advisories page and in the September 16 notification.

Related: Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation

Related: Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities

Related: Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities

Related: Cisco Patches Firewall Zero-Day Exploited for DoS Attacks

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.securityweek.com/cisco-fixes-dozens-of-flaws-across-fmc-ise-and-nexus-dashboard/