Back to Feed
VulnerabilitiesSep 17, 2026

Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard

Cisco patches dozens of critical vulnerabilities in FMC, ISE, and Nexus Dashboard.

Summary

Cisco has released patches for numerous critical vulnerabilities affecting its Secure Firewall Management Center (FMC), Identity Services Engine (ISE), and Nexus Dashboard. The updates address issues including SQL injection, command execution, authentication bypass, and remote code execution, with some flaws already publicly disclosed or exploited in the wild as zero-days.

Full text

Cisco on Wednesday announced patches for dozens of critical-severity CVEs in Secure Firewall Management Center (FMC), Identity Services Engine (ISE), and Nexus Dashboard. The ISE security updates stand out with patches for 20 CVEs, including 12 critical-severity flaws. Three of the issues have already been publicly disclosed, Cisco warned. Tracked as CVE-2026-20282, CVE-2026-20283, and CVE-2026-20284, they can be exploited by remote attackers for SQL injection, data tampering, and arbitrary command execution. Administrative access is required for all three. CVE-2026-20282 and CVE-2026-20283 are medium-severity bugs, but Cisco considers them high risk, as they provide attackers with a level of privileges that could easily lead to root access. CVE-2026-20284 is a critical-severity insufficient validation of user-supplied input that can allow attackers to view or modify data and cause a denial-of-service (DoS) condition. “The Cisco PSIRT is aware that a public announcement is available for the vulnerabilities that are described in this advisory,” the company notes.Advertisement. Scroll to continue reading. Cisco’s advisories detail six other critical-severity ISE vulnerabilities: three remote code execution (RCE) issues, two command injection flaws leading to command execution with root privileges, and an authentication bypass in the REST API. Multiple other critical-severity flaws related to injection, XSS, bypass, information disclosure, path traversal, and related attacks that are collectively tracked under five CVEs were also patched in ISE. Cisco’s FMC updates resolve 18 CVEs, including eight critical-severity bugs that could allow remote attackers to execute arbitrary commands as root, obtain root privileges, bypass protections and authentication, and perform other types of attacks. Four of the critical-severity CVEs address multiple vulnerabilities grouped based on their underlying class, and also affect Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD). Of these, CVE-2026-20332 stands out, as two vulnerabilities in the same class have been exploited in the wild: CVE-2026-20079 and CVE-2026-20316, disclosed in March and July, respectively, and exploited since August. Cisco also rolled out patches for six critical- and high-severity CVEs covering multiple authentication, code/command injection, cleartext storage, SQL injection, and path traversal vulnerabilities in Nexus Dashboard. On Wednesday, Cisco also warned of a critical-severity authentication bypass in ISE that has been exploited in the wild as a zero-day. Additional information is available on the company’s security advisories page and in the September 16 notification. Related: Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation Related: Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities Related: Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities Related: Cisco Patches Firewall Zero-Day Exploited for DoS Attacks Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire AIUC Raises $40 Million to Certify Enterprise AI AgentsUnauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover280,000 Impacted by Premier Medical Group Data BreachChrome, Firefox Updates Patch 115 VulnerabilitiesAcronis Patches Exploited Vulnerability in cPanel Backup PluginOracle Patches 800+ Vulnerabilities in September 2026 Security UpdateExein Secures $270M at $1.7B Valuation for Physical AI SecurityThai Broadband Provider Hacked via Fortinet Vulnerability Latest News Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M RansomComp AI Raises $34 Million for AI-Native Compliance and SecurityISC Patches 14 Vulnerabilities in BIND 9 Security UpdateRansomware Attacks on Manufacturers Surge as Supply Chain Risk GrowsCISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure DefensesAI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing RefusalsActive Exploitation Triggers Emergency Patch for Cisco ISE Zero-DayFirst Agentic AI Data Breach Reported to Spanish Regulator Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the Moveincident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.Ruben D. Chacon has joined ADM as Vice President and Global CISO.GDIT has appointed retired Maj. Gen. Ryan Heritage as Vice President, Full-Spectrum Cyber.More People On The MoveExpert Insights “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • cve — CVE-2026-20282
  • cve — CVE-2026-20283
  • cve — CVE-2026-20284
  • cve — CVE-2026-20332
  • cve — CVE-2026-20079
  • cve — CVE-2026-20316

Entities

Secure Firewall Management Center (product)Identity Services Engine (product)Nexus Dashboard (product)Secure Firewall Adaptive Security Appliance (product)Secure Firewall Threat Defense (product)Cisco (vendor)