Cisco released emergency fixes for more than 20 vulnerabilities across Identity Services Engine (ISE/ISE-PIC), Secure Firewall Management Center (FMC), Nexus Dashboard, and Secure Firewall ASA/FTD. Five flaws carry a maximum CVSS 10.0 rating: FMC vulnerability CVE-2026-20079 allows unauthenticated remote attackers to send crafted HTTP requests and gain root privileges, while CVE-2026-20130, CVE-2026-20192, CVE-2026-76423, and CVE-2026-76460 in ISE can permit authentication bypass, privileged administrative or system access, and in some cases code execution. A successful FMC compromise could allow attackers to modify firewall policies or disable security controls.
Cisco reports active exploitation of flaws in FMC and ISE, and CISA added the ISE privileged-API vulnerability CVE-2026-76460 to its Known Exploited Vulnerabilities catalog. Active exploitation has also been reported for ASA/FTD vulnerabilities CVE-2026-20329 and CVE-2026-20330. No workarounds are available; organizations should urgently upgrade to Cisco's fixed releases and restrict management interfaces to trusted networks while patching. ISE 3.0 and earlier are unsupported and must first be upgraded to a supported version before fixes can be applied.

See which actors are running it and whether you're in range.
21 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security issued Alert AL26-021 on vulnerabilities CVE-2026-20192, CVE-2026-76423, and actively exploited CVE-2026-76460 affecting Cisco ISE and ISE-PIC. The alert detailed authentication-bypass and administrative-access risks, identified fixed releases, and advised urgent remediation and re-imaging of potentially compromised nodes.
The Canadian Centre for Cyber Security published advisory AV26-932 covering vulnerabilities affecting Cisco FTD, FMC, ISE, ISE-PIC, Nexus Dashboard, and ASA products. The advisory directed organizations to review Cisco security advisories and apply available updates, while noting CISA's addition of CVE-2026-76460 to KEV.
Cisco published patches for CVE-2026-20322, CVE-2026-20325, CVE-2026-20326, CVE-2026-20360, CVE-2026-20361, and CVE-2026-76409 in Nexus Dashboard. CVE-2026-20322 can be exploited over the network and is rated for high confidentiality, integrity, and availability impact.
Cisco disclosed and released updates for six independent ISE and ISE-PIC vulnerabilities, CVE-2026-76423 through CVE-2026-76428. The most severe, CVE-2026-76423, is a CVSS 10.0 unauthenticated REST API authorization-bypass flaw that can grant remote administrative access; Cisco said no workarounds were available.
Cisco disclosed and released fixes for CVE-2026-76424, CVE-2026-76425, CVE-2026-76426, and CVE-2026-76427 in ISE and, for one issue, ISE-PIC. Authenticated administrators could exploit the flaws for root command execution via file upload, SQL database access, arbitrary file reading, or SSRF; no public exploits were known.
Cisco published fixes for SQL-injection vulnerabilities CVE-2026-20247 and CVE-2026-20300 in Cisco Identity Services Engine. CVE-2026-20247 is network-accessible, requires no authentication or user interaction, and can cause high integrity impact; no known exploits were reported.
Cisco disclosed and released updates for CVE-2026-20307, a CVSS 9.9 insecure Java deserialization vulnerability in Cisco ISE's web management interface. An authenticated attacker with low-privileged administrative credentials could execute arbitrary code and escalate to root; Cisco said no workaround is available.
Cisco published fixes for CVE-2026-20176, an input-validation flaw in Cisco ISE that allows authenticated high-privileged administrators to execute operating-system commands via crafted HTTP requests. Exploitation can provide system-level access and potential root elevation, and may make single-node ISE deployments unavailable; no public exploits were known.
Cisco published an advisory and fixes for CVE-2026-20211, an insecure Java deserialization vulnerability in Cisco ISE that allows authenticated high-privileged administrators to execute commands on the underlying operating system. Exploitation can yield user-level OS access with possible elevation to root and can make a single-node deployment unavailable; no known exploits were reported.
Cisco published patches for CVE-2026-20282, CVE-2026-20283, and CVE-2026-20284 in Cisco ISE. The flaws can permit operating-system write access, IPsec Open API command injection, or SXP REST API SQL injection to authenticated administrators; no public exploits were known.
Cisco published an advisory and patch for CVE-2026-20305, a CVSS 8.8 command-injection vulnerability in Cisco Identity Services Engine. Exploitation is network-accessible and requires high privileges; the Nessus plugin reported no known exploits.
CISA added CVE-2026-76460, a CVSS 10.0 Cisco ISE privileged-API vulnerability that can provide unauthenticated full system access, to its Known Exploited Vulnerabilities catalog, indicating active exploitation.
Cisco disclosed CVE-2026-76460, a CVSS 10.0 authentication-bypass flaw in Cisco ISE and ISE-PIC that was actively exploited and could ultimately allow root command execution. Cisco released fixed patches for supported releases and said no complete workaround was available.
Cisco disclosed CVE-2026-76461, a CVSS 9.8 vulnerability under active exploitation affecting Secure Email Gateway and Secure Email and Web Manager appliances. Successful exploitation can result in root access.
Cisco released coordinated September 2026 updates addressing more than 20 vulnerabilities in ISE/ISE-PIC, FMC, Nexus Dashboard, and ASA/FTD software. The release included four CVSS 10.0 ISE flaws and fixed FMC and Nexus Dashboard issues; Cisco said no workarounds were available.
Cisco stated that CVE-2026-20079 and CVE-2026-20316, vulnerabilities in the same class as CVE-2026-20332, had been exploited in the wild since August 2026.
The critical unauthenticated remote vulnerability CVE-2026-20079 affecting Cisco Secure Firewall Management Center was known by March 2026. Crafted HTTP requests can yield root privileges on vulnerable FMC systems.
Cisco remediated 41 additional critical vulnerabilities affecting ISE and ISE-PIC, including flaws enabling command execution, authentication and authorization bypass, remote code execution, SQL injection, XXE, and sensitive-information exposure. Cisco advised affected organizations to upgrade to fixed patch levels, limit access to trusted sources, and review logs for suspicious activity.
Cisco reported active exploitation in the wild of CVE-2026-20329 and CVE-2026-20330, two CVSS 9.9 vulnerabilities affecting Cisco ASA and FTD software.
Cisco recommended reviewing Kong API Gateway logs on all ISE nodes for suspicious usernames such as "dummyuser" and correlating findings with perimeter logs. For suspected exploitation of CVE-2026-76460, Cisco advised isolating and re-imaging affected nodes and restoring known-good configurations rather than merely applying the patch.
Cisco reported that attackers were exploiting vulnerabilities in Secure Firewall Management Center and Identity Services Engine, including critical issues that can permit root or administrative access, authentication bypass, or code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
49 references tracked. Mallory keeps watching after this page renders.
triskelelabs.com
Open sourcecsirt.bj
Open sourcecsirt.sk
Open sourcethecyberexpress.com
Open sourcecwe.mitre.org
Open sourcebst.cloudapps.cisco.com
Open sourcebst.cloudapps.cisco.com
Open sourcebst.cloudapps.cisco.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.