Cisco shipped a large batch of security fixes covering three widely deployed management and security products — Secure Firewall Management Center (FMC), Identity Services Engine (ISE), and Nexus Dashboard — totaling 44 CVEs across the three advisories, with root-access and remote-code-execution bugs among the most severe.
What's Being Patched
| Product | Total CVEs | Critical | Notable Issues |
|---|---|---|---|
| Identity Services Engine (ISE) | 20 | 12 | 3 publicly disclosed flaws (CVE-2026-20282, CVE-2026-20283, CVE-2026-20284) plus 6 additional critical RCE/command-injection bugs |
| Secure Firewall Management Center (FMC) | 18 | 8 | 4 critical CVEs also affect Secure Firewall ASA and FTD; CVE-2026-20332 is linked to two already-exploited flaws |
| Nexus Dashboard | 6 | Critical/High | Authentication bypass, injection, and SQL injection issues |
Beyond the headline RCE and command-injection bugs, the batch also covers cross-site scripting, authentication and authorization bypasses, path traversal, and denial-of-service issues spread across the three products' web management interfaces and APIs.
Active Exploitation
Two of the FMC vulnerabilities, CVE-2026-20079 and CVE-2026-20316, have reportedly been exploited in the wild since August 2026 — meaning attackers had a working path into FMC deployments for roughly a month before today's fixes landed. CVE-2026-20332, part of this same patch batch, is directly related to those two already-exploited flaws.
Separately, this release also addresses an ISE authentication-bypass flaw that was exploited in the wild as a zero-day — the same CVSS 10.0 issue (CVE-2026-76460) covered in detail earlier today, for which CISA has given federal agencies until September 19 to patch. That flaw is one line item within this broader 44-CVE bundle, not a separate release.
Why It Matters
FMC, ISE, and Nexus Dashboard aren't edge appliances an organization can afford to leave unpatched for a normal maintenance cycle — they're the control planes that manage firewall policy, network access control, and data-center switching fabric, respectively. A root-access or RCE bug in any of the three gives an attacker leverage far beyond a single device: FMC compromise can mean rewriting firewall policy across an entire fleet, and ISE compromise can mean issuing an attacker their own valid network access credentials. The fact that two FMC flaws were already being exploited for weeks before a public fix existed is the clearest signal here — attackers found and weaponized these issues faster than the normal disclosure-to-patch timeline assumes.
Mitigation
- Prioritize FMC first if CVE-2026-20079, CVE-2026-20316, or CVE-2026-20332 apply to your deployed version — these have confirmed in-the-wild exploitation.
- Patch ISE for the three publicly disclosed CVEs (CVE-2026-20282/-20283/-20284) and the CVSS 10.0 auth-bypass zero-day (CVE-2026-76460) ahead of CISA's September 19 federal deadline, even if you're not a federal agency.
- Review Nexus Dashboard exposure, particularly for the SQL injection and authentication-bypass CVEs, if the dashboard's API or web UI is reachable beyond a tightly restricted management network.
- Check Cisco's advisories directly for exact affected version ranges — this batch spans 44 individual CVEs, and applicability varies by product train and release.