Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2891+ Articles
167+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Cisco Patches 44 Vulnerabilities Across FMC, ISE, and Nexus Dashboard
Cisco Patches 44 Vulnerabilities Across FMC, ISE, and Nexus Dashboard
NEWS

Cisco Patches 44 Vulnerabilities Across FMC, ISE, and Nexus Dashboard

Cisco patches 44 flaws across FMC, ISE, and Nexus Dashboard, including root-access and RCE bugs; two FMC CVEs were already exploited since August.

Dylan H.

News Desk

September 17, 2026
3 min read

Cisco shipped a large batch of security fixes covering three widely deployed management and security products — Secure Firewall Management Center (FMC), Identity Services Engine (ISE), and Nexus Dashboard — totaling 44 CVEs across the three advisories, with root-access and remote-code-execution bugs among the most severe.

What's Being Patched

ProductTotal CVEsCriticalNotable Issues
Identity Services Engine (ISE)20123 publicly disclosed flaws (CVE-2026-20282, CVE-2026-20283, CVE-2026-20284) plus 6 additional critical RCE/command-injection bugs
Secure Firewall Management Center (FMC)1884 critical CVEs also affect Secure Firewall ASA and FTD; CVE-2026-20332 is linked to two already-exploited flaws
Nexus Dashboard6Critical/HighAuthentication bypass, injection, and SQL injection issues

Beyond the headline RCE and command-injection bugs, the batch also covers cross-site scripting, authentication and authorization bypasses, path traversal, and denial-of-service issues spread across the three products' web management interfaces and APIs.

Active Exploitation

Two of the FMC vulnerabilities, CVE-2026-20079 and CVE-2026-20316, have reportedly been exploited in the wild since August 2026 — meaning attackers had a working path into FMC deployments for roughly a month before today's fixes landed. CVE-2026-20332, part of this same patch batch, is directly related to those two already-exploited flaws.

Separately, this release also addresses an ISE authentication-bypass flaw that was exploited in the wild as a zero-day — the same CVSS 10.0 issue (CVE-2026-76460) covered in detail earlier today, for which CISA has given federal agencies until September 19 to patch. That flaw is one line item within this broader 44-CVE bundle, not a separate release.

Why It Matters

FMC, ISE, and Nexus Dashboard aren't edge appliances an organization can afford to leave unpatched for a normal maintenance cycle — they're the control planes that manage firewall policy, network access control, and data-center switching fabric, respectively. A root-access or RCE bug in any of the three gives an attacker leverage far beyond a single device: FMC compromise can mean rewriting firewall policy across an entire fleet, and ISE compromise can mean issuing an attacker their own valid network access credentials. The fact that two FMC flaws were already being exploited for weeks before a public fix existed is the clearest signal here — attackers found and weaponized these issues faster than the normal disclosure-to-patch timeline assumes.

Mitigation

  • Prioritize FMC first if CVE-2026-20079, CVE-2026-20316, or CVE-2026-20332 apply to your deployed version — these have confirmed in-the-wild exploitation.
  • Patch ISE for the three publicly disclosed CVEs (CVE-2026-20282/-20283/-20284) and the CVSS 10.0 auth-bypass zero-day (CVE-2026-76460) ahead of CISA's September 19 federal deadline, even if you're not a federal agency.
  • Review Nexus Dashboard exposure, particularly for the SQL injection and authentication-bypass CVEs, if the dashboard's API or web UI is reachable beyond a tightly restricted management network.
  • Check Cisco's advisories directly for exact affected version ranges — this batch spans 44 individual CVEs, and applicability varies by product train and release.

Sources

  • SecurityWeek — Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard
#Cisco#Security Updates#RCE#Identity Services Engine#Firewall Management Center

Related Articles

Interlock Ransomware Has Been Exploiting Cisco FMC Zero-Day

The Interlock ransomware gang has been actively exploiting a CVSS 10.0 insecure deserialization flaw in Cisco Secure Firewall Management Center since late...

7 min read

Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data

CISA has added a newly disclosed Cisco Secure Firewall Management Center zero-day to its Known Exploited Vulnerabilities catalog following confirmed in-the-wild exploitation. A separate static credentials issue further compounds the risk to enterprise firewall deployments.

4 min read

CVE-2026-20316: Cisco FMC Hardcoded Password Gives Unauthenticated Remote Access

A hardcoded static credential in Cisco Secure Firewall Management Center allows unauthenticated remote attackers to log in and access sensitive data. CISA added it to the KEV catalog on July 29, 2026, with a federal patch deadline of August 1.

5 min read
Back to all News