ZeroHour
Story · 2 sources · 2 articlesfirst updated ()

Cisco's September 2026 Patch Wave: Dozens of Fixes for Secure Firewall Management Center, ISE and Nexus Dashboard, With Some Flaws Exploited in the Wild

What's new: Initial merged summary for this story (no prior summary existed). New developments: Cisco's September 2026 hardening release for Nexus Dashboard (announced 2026-09-16, following an internal security review) and its broader September 2026 patch wave covering FMC and ISE (reported 2026-09-17), with confirmed in-the-wild exploitation of ASA/FTD-class CVE-2026-20079 and CVE-2026-20316 since August…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Cisco's September 2026 security releases fix dozens of critical- and high-severity vulnerabilities across Secure Firewall Management Center (18 CVEs, 8 critical), Identity Services Engine (20 CVEs, 12 critical) and Nexus Dashboard (six critical- and…

Cisco released its September 2026 round of security fixes spanning Secure Firewall Management Center (FMC), Identity Services Engine (ISE) and Nexus Dashboard. The ISE update patches 20 CVEs, 12 of them critical, including three publicly disclosed flaws (CVE-2026-20282, CVE-2026-20283, CVE-2026-20284) that enable SQL injection, data tampering and command execution but require administrative access. The FMC update resolves 18 CVEs, eight critical, several of which are shared with Cisco ASA and FTD; the ASA/FTD-class flaws CVE-2026-20079 and CVE-2026-20316 have been exploited in the wild since August 2026. Cisco separately warned of a critical-severity ISE authentication bypass that has been exploited in the wild as a zero-day. For Nexus Dashboard, Cisco issued a proactive software hardening release covering six critical- and high-severity injection and bypass flaws. According to Cisco, these Nexus Dashboard issues were found during an internal security review rather than external research, were grouped by CWE class with a single CVE ID assigned per issue, and are not known to be actively exploited — distinguishing them from the in-the-wild exploitation reported for the ASA/FTD-class CVEs and the ISE zero-day bypass. An additional CVE, CVE-2026-20332, is referenced among the addressed vulnerabilities but the reports do not detail it.

  • Cisco released September 2026 patches covering Secure Firewall Management Center (FMC), Identity Services Engine (ISE) and Nexus Dashboard.
  • The ISE update patches 20 CVEs, including 12 critical-severity issues.
  • Three publicly disclosed ISE flaws — CVE-2026-20282, CVE-2026-20283 and CVE-2026-20284 — enable SQL injection, data tampering and command execution but require administrative access.
  • Cisco warned of a critical-severity ISE authentication bypass exploited in the wild as a zero-day.
  • The FMC update resolves 18 CVEs, eight of them critical; several flaws also affect Cisco ASA and FTD.
  • CVE-2026-20079 and CVE-2026-20316, in the ASA/FTD class, have been exploited in the wild since August 2026.
  • Nexus Dashboard patches cover six critical- and high-severity injection and bypass flaws.
  • Cisco says the Nexus Dashboard issues were found via an internal security review (not external research), grouped by CWE class with one CVE ID per issue, and are not known to be actively exploited.

Coverage timeline

  1. · 21h ago
    Cisco Security Advisories· 22
    Cisco Nexus Dashboard Software Security Hardening Release: September 2026

    Cisco released Nexus Dashboard hardening updates for multiple internally discovered vulnerabilities, grouped by CWE and not known to be exploited.

  2. · 1h ago
    SecurityWeek· 80
    Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard

    Cisco patches dozens of critical flaws in FMC, ISE and Nexus Dashboard, including ISE bugs and an authentication bypass already exploited in the wild.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-20079
Authentication bypass to root access in Cisco Secure Firewall Management Center

CVE-2026-20079 is an authentication bypass (CWE-288) in the web interface of Cisco Secure Firewall Management Center (FMC) Software, caused by an improper system process created at boot time. An unauthenticated, remote attacker can exploit it by sending crafted HTTP requests to the FMC web interface, which allows the execution of script files and commands on the device. A successful exploit grants the attacker root access to the underlying operating system, giving full control of the management platform (CVSS 3.1: 10.0, network-exploitable, no privileges or user interaction required, scope changed). The flaw affects Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management deployments. Cisco has confirmed the vulnerability is being exploited in active attacks, it carries a 35.9% EPSS score (98th percentile), and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-09.

Do: Upgrade FMC (and SCC Firewall Management tenants) to the fixed release specified in Cisco's advisory, prioritizing internet-exposed or externally reachable management interfaces; CISA KEV action applies to federal agencies under BOD 26-04. Until patching, restrict FMC web interface access to trusted management networks and VPNs and check devices for signs of exploitation such as unexpected script execution, unfamiliar processes, or root-level changes. Triage per CISA's Forensics Triage Requirements if compromise is suspected.

10.076% KEV PoC ×2
  • Cisco Secure Firewall Management Center (FMC) Software (web interface)
  • Cisco Security Cloud Control (SCC) Firewall Management
largeplausibly tens of thousands of FMC deployments worldwide (internet-exposed instances likely a smaller subset, likely thousands)
CVE-2026-20282
Authenticated OS Write-Access Flaw in Cisco Identity Services Engine

CVE-2026-20282 is a vulnerability in Cisco Identity Services Engine (ISE) caused by insufficient validation of user-supplied input. An attacker who already has valid administrative credentials can send a crafted HTTP request to an affected device and obtain write access to the underlying operating system. Cisco rated the flaw High despite the Medium CVSS score because an attacker can easily escalate from the achieved privilege level to root, effectively yielding full control of the appliance. Any organization running Cisco ISE is affected, though exploitation requires both network reachability to the device and stolen or malicious administrator credentials. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known.

Do: Review Cisco's advisory for CVE-2026-20282 and upgrade ISE to the fixed release it specifies, prioritizing the fix since Cisco rates the impact High due to the easy path to root. Restrict ISE administration interfaces to dedicated management networks and enforce strong credential hygiene/MFA for ISE admin accounts, since valid admin credentials are required for exploitation. Check ISE admin and audit logs for unexpected administrative sessions or unusual HTTP requests to management endpoints.

4.9
  • Cisco Identity Services Engine (ISE)
large≈10,000–100,000 enterprise ISE deployments/nodes worldwide (estimate), though only a small fraction have admin interfaces reachable by potential attackers
CVE-2026-20283
Authenticated OS command injection (RCE) in Cisco ISE IPsec Open API

Cisco Identity Services Engine (ISE) contains an operating system command injection flaw (CWE-78) in its IPsec Open API endpoint, caused by insufficient validation of user-supplied input in IPsec Open API calls. An authenticated, remote attacker who holds valid administrative credentials can send crafted input to the endpoint to execute arbitrary commands on the underlying operating system. Exploitation additionally requires the ISE node to have more than one network interface, one of which is configured as an active IPsec tunnel. Although the CVSS 3.1 base score is 6.5 (Medium), Cisco assigned a Security Impact Rating of High because it is easy to escalate from the achieved privilege level to root. No public proof-of-concept or confirmed in-the-wild exploitation is known, and the flaw is not listed in CISA's KEV catalog.

Do: Upgrade ISE to the fixed release identified in Cisco's advisory; the related-headline bundle indicates companion ISE RCE/API vulnerabilities fixed at the same time, so apply the full set of patches. Until patching, restrict access to the Open API to trusted management networks, disable the Open API or IPsec tunnel configuration where unused, and limit and rotate administrative credentials. Audit ISE deployments for multi-interface nodes with active IPsec tunnels, as those are the exploitable targets.

6.5
  • Cisco Identity Services Engine (ISE)
moderatelikely on the order of thousands of ISE deployments meet the preconditions, out of an ISE installed base plausibly in the tens of thousands
CVE-2026-20284
Authenticated SQL Injection in Cisco ISE SXP REST API

Cisco ISE (Identity Services Engine) contains a SQL injection flaw (CWE-943) in its SXP REST API, caused by insufficient validation of user-supplied input in REST API calls. To trigger it, an attacker must send crafted input to the affected device while holding valid administrative credentials, with the SXP service enabled and at least one SXP connection configured. A successful exploit could let the attacker read or modify data in the underlying ISE database, and in single-node deployments could crash the node, denying network access to endpoints that have not yet authenticated. Any organization running Cisco ISE with SXP/TrustSec in this configuration is affected, though the admin-credential requirement makes insider or compromised-credential scenarios the primary risk. No public proof-of-concept or confirmed in-the-wild exploitation is known, and the flaw is not in CISA's KEV catalog.

Do: Upgrade ISE nodes to the fixed release identified in Cisco's security advisory (not specified in the source data). As interim mitigation, restrict access to the ISE admin/REST API to trusted management networks, disable the SXP service on nodes that do not use it, and audit admin accounts for credential compromise. Monitor Cisco PSIRT for updated fixed-version guidance.

9.1
  • Cisco Identity Services Engine (ISE) — SXP REST API
large≈10,000–100,000 ISE nodes worldwide (subset of tens of thousands of enterprise ISE deployments that have SXP enabled)
CVE-2026-20316
Hard-Coded Password Vulnerability in Cisco Secure Firewall Management Center

Cisco Secure Firewall Management Center (FMC), formerly Firepower Management Center, contains a use of hard-coded password vulnerability (CWE-259) that allows an unauthenticated, remote attacker to log in to an affected system. By authenticating with the built-in hard-coded credentials for a low-privileged account, the attacker can gain access to sensitive data within the impacted systems. Any organization running an affected Cisco FMC deployment is exposed, particularly where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-29, indicating active exploitation in the wild, and related reporting describes active exploitation of FMC vulnerabilities. No CVSS score or public proof-of-concept is yet available, but EPSS assigns a 9.8% probability of exploitation within 30 days (95th percentile).

Do: Upgrade FMC to the fixed release per Cisco's security advisory, as no specific fixed version is provided in this data. Until patched, restrict access to the FMC management interface, audit recent logins against the affected low-privileged accounts, and rotate or remove any hard-coded credentials. Federal agencies must apply mitigations per CISA BOD 26-04 given the KEV listing dated 2026-07-29.

5.311% KEV ransomware
  • Cisco Secure Firewall Management Center (FMC)
largeplausibly tens of thousands of FMC deployments worldwide (no published install base)
CVE-2026-20332
Improper Access Control in Cisco ASA, FTD, and Firewall Management Center

CVE-2026-20332 covers improper access control issues (CWE-284) in Cisco Secure Adaptive Security Appliance (ASA), Secure Firewall Threat Defense (FTD), and Secure Firewall Management Center (FMC) software, discovered during Cisco's internal security review and addressed in a dedicated software hardening release. A remote attacker who already holds a low-privileged account or session (CVSS PR:L over the network, no user interaction) can trigger the flaw. Because the attack scope is changed and confidentiality, integrity, and availability impacts are all rated high, successful exploitation crosses a security boundary, giving the attacker high-impact control over the device or access to data it protects. Any organization running affected ASA, FTD, or FMC releases is exposed, though exploitation requires valid low-privileged credentials. No public proof-of-concept or known exploitation exists; the flaw was internally discovered by Cisco and is not yet in CISA's Known Exploited Vulnerabilities catalog.

Do: Upgrade ASA, FTD, and FMC devices to the Cisco software hardening release cited in the Cisco PSIRT advisory (specific fixed version numbers should be confirmed there). Until patched, restrict management-plane and VPN access to trusted users and networks, and audit low-privileged accounts and their permissions for access-boundary gaps. Monitor Cisco PSIRT for updates, as exploitation requires a valid low-privileged credential and no public exploit is currently known.

9.9
  • Cisco Secure Adaptive Security Appliance (ASA) Software
  • Cisco Secure Firewall Threat Defense (FTD) Software
  • Cisco Secure Firewall Management Center (FMC) Software
masshundreds of thousands of internet-exposed Cisco ASA/FTD devices; total deployed base likely in the millions