Cisco Fixes Critical ISE, FMC and Nexus Dashboard Flaws as Exploited Bugs Demand Immediate Action
Cisco patched critical ISE, FMC and Nexus Dashboard flaws, including exploited authentication bypass and root RCE bugs requiring urgent updates.
Text generated by artificial intelligence, published without human review. AI transparency
Illustrative image generated with AI
Cisco has released security updates for dozens of vulnerabilities across three major enterprise platforms: Identity Services Engine, Secure Firewall Management Center and Nexus Dashboard.
The broad patch release covers 20 CVEs in Cisco ISE, 18 in Secure Firewall Management Center (FMC), and six high- or critical-severity issues in Nexus Dashboard. Twelve ISE vulnerabilities and eight FMC vulnerabilities are rated critical.
The most urgent problems are not theoretical. Two FMC flaws are listed in the US Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog, while Cisco has separately warned about an actively exploited ISE authentication-bypass zero-day whose CVE identifier has not been disclosed.
ISE flaws reach operating systems, databases and security controls
Cisco’s ISE update addresses three remote-code-execution vulnerabilities and two command-injection bugs capable of executing commands with root privileges. It also fixes a REST API authentication bypass and critical issues involving injection, cross-site scripting, path traversal, information disclosure and security-control bypass.
Three vulnerabilities—CVE-2026-20282, CVE-2026-20283 and CVE-2026-20284—were publicly disclosed before the update. All require valid administrative credentials, limiting initial access but leaving compromised administrator accounts with powerful exploitation paths.
CVE-2026-20282 carries a CVSS score of 4.9 and is classified under CWE-641. An authenticated remote attacker can send a crafted HTTP request that provides write access to the underlying operating system. Although its score is moderate, the resulting access can support further compromise.
Its CVSS vector is:
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
CVE-2026-20283 is an OS command-injection vulnerability in the ISE IPsec Open API endpoint. Crafted input from an authenticated remote administrator can inject arbitrary commands into the operating system. The flaw is rated 6.5 and mapped to CWE-78.
Its vector is:
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
The most severe of the three is CVE-2026-20284, a SQL injection vulnerability in the SXP REST API. It has a CVSS score of 9.1 and is classified as CWE-943.
An authenticated attacker can manipulate REST API input to query the underlying database, potentially viewing or altering stored data. In a single-node deployment, successful exploitation can also make the ISE node unavailable.
Its vector reflects high impact across confidentiality, integrity and availability:
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Exact affected ISE versions for these three CVEs have not been disclosed in the available vulnerability records.
More concerning is the separate critical ISE authentication-bypass flaw that Cisco says is already being exploited as a zero-day. Its CVE number, affected versions, attack mechanics and observed indicators have not been made public in the available information.
Exploited FMC vulnerabilities enable root access and unauthorized logins
Cisco’s FMC release resolves 18 CVEs, including eight critical vulnerabilities. Reported consequences include authentication bypass, security-control bypass, arbitrary command execution as root and privilege escalation.
CVE-2026-20079 presents the clearest immediate risk. Rated CVSS 10.0, it affects Cisco Secure Firewall Management Center 7.0.0 and requires neither authentication nor user interaction.
The flaw exists in the FMC web interface and results from an improper system process created during startup. An attacker can send crafted HTTP requests, bypass authentication and execute script files, potentially obtaining root access to the operating system.
Its vector is:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA added CVE-2026-20079 to its KEV catalog on September 9, 2026. US federal agencies received a remediation deadline of September 12, 2026.
CVE-2026-20316 affects FMC versions up to and including 7.0.9. The web interface contains static credentials for a low-privileged account, allowing an unauthenticated remote attacker to log in and access sensitive information available to that account.
The vulnerability has a CVSS score of 5.3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Despite that lower score, exploitation evidence makes the flaw operationally urgent. CVE-2026-20316 has been used in ransomware campaigns and has appeared in CISA’s KEV catalog since July 29, 2026. Its federal remediation deadline was August 1, 2026.
Reporting indicates that CVE-2026-20079 and CVE-2026-20316 were disclosed in March and July, respectively, with exploitation beginning in August. The exact disclosure days are not known.
CVE-2026-20332 extends the firewall update across ASA and FTD
CVE-2026-20332 groups multiple improper-access-control issues found during an internal Cisco engineering review. It is rated 9.9 and assigned CWE-284.
The CVSS vector is:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The grouped security problems affect Secure Firewall Management Center, Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense software. However, exact affected versions and complete exploitation conditions for CVE-2026-20332 have not been disclosed.
Published reporting associates this vulnerability class with the separately tracked CVE-2026-20079 and CVE-2026-20316. Those two CVEs have their own exploitation characteristics, affected FMC releases and KEV records. The available information does not establish that CVE-2026-20332 itself has a separate KEV entry.
Four of the critical FMC CVEs group multiple vulnerabilities according to their underlying weakness class. Administrators should therefore assess ASA and FTD deployments alongside FMC rather than treating the update as a management-console-only problem.
Nexus Dashboard patches cover six attack classes
Cisco also fixed six high- and critical-severity vulnerabilities in Nexus Dashboard. The affected categories are authentication bypass, code injection, command injection, SQL injection, path traversal and cleartext storage of sensitive information.
Individual CVE identifiers, CVSS vectors, CWE classifications and exact affected Nexus Dashboard versions have not been disclosed in the available reporting.
That lack of detail makes vendor release information essential for asset matching. Organizations running Nexus Dashboard should compare their installed releases directly against Cisco’s advisories and apply the corresponding updates.
Remediation should prioritize KEV-listed and exposed management systems
Cisco has issued fixes for the affected ISE, FMC and Nexus Dashboard products, with the relevant vendor notification referenced as September 16. Administrators should identify installed versions and apply the applicable updates rather than relying only on headline severity ratings.
CVE-2026-20079 and CVE-2026-20316 warrant first priority because exploitation is confirmed. CISA requires mitigations in accordance with Cisco’s instructions, compliance with BOD 26-04 and completion of the agency’s forensic triage requirements. Where mitigations are unavailable, its direction includes following applicable cloud-service guidance or discontinuing use of the product.
FMC investigations should look for:
- Unauthorized or unexplained logins, including activity involving low-privileged accounts.
- Crafted HTTP requests directed at the management interface.
- Unexpected scripts, command execution or operating-system changes.
- Unexplained access to configurations or sensitive data.
- Indicators connected with ransomware activity.
ISE operators should review administrator-account activity, REST and IPsec Open API requests, database integrity, operating-system modifications and unexplained service disruption. Any evidence of authentication bypass deserves particular scrutiny because the actively exploited ISE zero-day remains technically unidentified.
Cisco has also had five other vulnerabilities enter the KEV catalog within the last 90 days: CVE-2026-76460 on September 16, 2026; CVE-2026-76461 on September 14, 2026; CVE-2026-20349 on August 11, 2026; CVE-2008-4128 on July 13, 2026; and CVE-2026-20230 on June 25, 2026.
For defenders, the immediate task is clear: patch exposed management infrastructure, validate that updates succeeded, and investigate affected systems rather than assuming remediation alone removes evidence of earlier compromise.
Sources
This article is an original reworking based on the sources below.
CVEs covered in this article
- CVE-2026-20079Critical10.0A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability
- CVE-2026-76460Critical10.0A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication. This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a crafted reques
- CVE-2026-20332Critical9.9As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engineering team has conducted a comprehensive internal security
- CVE-2026-76461Critical9.8A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email pa
- CVE-2026-20284Critical9.1A vulnerability in the SXP REST API of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks. This vulnerability is due to insufficient validation of user-supplied input in REST API calls. An attacker could exploit this vulnerability by sending crafted input to
- CVE-2026-20230High8.6A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. This vulnerab
- CVE-2026-20349High8.6A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of servi
- CVE-2026-20283Medium6.5A vulnerability in the IPsec Open API endpoint of Cisco ISE could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system. This vulnerability is due to insufficient validation of user-supplied input in IPsec Open API calls. An attacker could e
- CVE-2026-20316Medium5.3A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the pres
- CVE-2026-20282Medium4.9A vulnerability in Cisco ISE could allow an authenticated, remote attacker to obtain write access on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by sending a crafte
- CVE-2008-4128Medium4.3Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router allow remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alia
