Cisco Fixes Critical ISE, FMC and Nexus Dashboard Flaws as Exploited Bugs Demand Immediate Action

Cisco patched critical ISE, FMC and Nexus Dashboard flaws, including exploited authentication bypass and root RCE bugs requiring urgent updates.

Text generated by artificial intelligence, published without human review. AI transparency

Cisco Fixes Critical ISE, FMC and Nexus Dashboard Flaws as Exploited Bugs Demand Immediate Action
Vulnerabilities

Illustrative image generated with AI

Listen to this articleAudio edition · 11 min

Cisco has released security updates for dozens of vulnerabilities across three major enterprise platforms: Identity Services Engine, Secure Firewall Management Center and Nexus Dashboard.

The broad patch release covers 20 CVEs in Cisco ISE, 18 in Secure Firewall Management Center (FMC), and six high- or critical-severity issues in Nexus Dashboard. Twelve ISE vulnerabilities and eight FMC vulnerabilities are rated critical.

The most urgent problems are not theoretical. Two FMC flaws are listed in the US Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog, while Cisco has separately warned about an actively exploited ISE authentication-bypass zero-day whose CVE identifier has not been disclosed.

ISE flaws reach operating systems, databases and security controls

Cisco’s ISE update addresses three remote-code-execution vulnerabilities and two command-injection bugs capable of executing commands with root privileges. It also fixes a REST API authentication bypass and critical issues involving injection, cross-site scripting, path traversal, information disclosure and security-control bypass.

Three vulnerabilities—CVE-2026-20282, CVE-2026-20283 and CVE-2026-20284—were publicly disclosed before the update. All require valid administrative credentials, limiting initial access but leaving compromised administrator accounts with powerful exploitation paths.

CVE-2026-20282 carries a CVSS score of 4.9 and is classified under CWE-641. An authenticated remote attacker can send a crafted HTTP request that provides write access to the underlying operating system. Although its score is moderate, the resulting access can support further compromise.

Its CVSS vector is:

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

CVE-2026-20283 is an OS command-injection vulnerability in the ISE IPsec Open API endpoint. Crafted input from an authenticated remote administrator can inject arbitrary commands into the operating system. The flaw is rated 6.5 and mapped to CWE-78.

Its vector is:

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

The most severe of the three is CVE-2026-20284, a SQL injection vulnerability in the SXP REST API. It has a CVSS score of 9.1 and is classified as CWE-943.

An authenticated attacker can manipulate REST API input to query the underlying database, potentially viewing or altering stored data. In a single-node deployment, successful exploitation can also make the ISE node unavailable.

Its vector reflects high impact across confidentiality, integrity and availability:

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Exact affected ISE versions for these three CVEs have not been disclosed in the available vulnerability records.

More concerning is the separate critical ISE authentication-bypass flaw that Cisco says is already being exploited as a zero-day. Its CVE number, affected versions, attack mechanics and observed indicators have not been made public in the available information.

Exploited FMC vulnerabilities enable root access and unauthorized logins

Cisco’s FMC release resolves 18 CVEs, including eight critical vulnerabilities. Reported consequences include authentication bypass, security-control bypass, arbitrary command execution as root and privilege escalation.

CVE-2026-20079 presents the clearest immediate risk. Rated CVSS 10.0, it affects Cisco Secure Firewall Management Center 7.0.0 and requires neither authentication nor user interaction.

The flaw exists in the FMC web interface and results from an improper system process created during startup. An attacker can send crafted HTTP requests, bypass authentication and execute script files, potentially obtaining root access to the operating system.

Its vector is:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA added CVE-2026-20079 to its KEV catalog on September 9, 2026. US federal agencies received a remediation deadline of September 12, 2026.

CVE-2026-20316 affects FMC versions up to and including 7.0.9. The web interface contains static credentials for a low-privileged account, allowing an unauthenticated remote attacker to log in and access sensitive information available to that account.

The vulnerability has a CVSS score of 5.3:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Despite that lower score, exploitation evidence makes the flaw operationally urgent. CVE-2026-20316 has been used in ransomware campaigns and has appeared in CISA’s KEV catalog since July 29, 2026. Its federal remediation deadline was August 1, 2026.

Reporting indicates that CVE-2026-20079 and CVE-2026-20316 were disclosed in March and July, respectively, with exploitation beginning in August. The exact disclosure days are not known.

CVE-2026-20332 extends the firewall update across ASA and FTD

CVE-2026-20332 groups multiple improper-access-control issues found during an internal Cisco engineering review. It is rated 9.9 and assigned CWE-284.

The CVSS vector is:

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

The grouped security problems affect Secure Firewall Management Center, Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense software. However, exact affected versions and complete exploitation conditions for CVE-2026-20332 have not been disclosed.

Published reporting associates this vulnerability class with the separately tracked CVE-2026-20079 and CVE-2026-20316. Those two CVEs have their own exploitation characteristics, affected FMC releases and KEV records. The available information does not establish that CVE-2026-20332 itself has a separate KEV entry.

Four of the critical FMC CVEs group multiple vulnerabilities according to their underlying weakness class. Administrators should therefore assess ASA and FTD deployments alongside FMC rather than treating the update as a management-console-only problem.

Nexus Dashboard patches cover six attack classes

Cisco also fixed six high- and critical-severity vulnerabilities in Nexus Dashboard. The affected categories are authentication bypass, code injection, command injection, SQL injection, path traversal and cleartext storage of sensitive information.

Individual CVE identifiers, CVSS vectors, CWE classifications and exact affected Nexus Dashboard versions have not been disclosed in the available reporting.

That lack of detail makes vendor release information essential for asset matching. Organizations running Nexus Dashboard should compare their installed releases directly against Cisco’s advisories and apply the corresponding updates.

Remediation should prioritize KEV-listed and exposed management systems

Cisco has issued fixes for the affected ISE, FMC and Nexus Dashboard products, with the relevant vendor notification referenced as September 16. Administrators should identify installed versions and apply the applicable updates rather than relying only on headline severity ratings.

CVE-2026-20079 and CVE-2026-20316 warrant first priority because exploitation is confirmed. CISA requires mitigations in accordance with Cisco’s instructions, compliance with BOD 26-04 and completion of the agency’s forensic triage requirements. Where mitigations are unavailable, its direction includes following applicable cloud-service guidance or discontinuing use of the product.

FMC investigations should look for:

  • Unauthorized or unexplained logins, including activity involving low-privileged accounts.
  • Crafted HTTP requests directed at the management interface.
  • Unexpected scripts, command execution or operating-system changes.
  • Unexplained access to configurations or sensitive data.
  • Indicators connected with ransomware activity.

ISE operators should review administrator-account activity, REST and IPsec Open API requests, database integrity, operating-system modifications and unexplained service disruption. Any evidence of authentication bypass deserves particular scrutiny because the actively exploited ISE zero-day remains technically unidentified.

Cisco has also had five other vulnerabilities enter the KEV catalog within the last 90 days: CVE-2026-76460 on September 16, 2026; CVE-2026-76461 on September 14, 2026; CVE-2026-20349 on August 11, 2026; CVE-2008-4128 on July 13, 2026; and CVE-2026-20230 on June 25, 2026.

For defenders, the immediate task is clear: patch exposed management infrastructure, validate that updates succeeded, and investigate affected systems rather than assuming remediation alone removes evidence of earlier compromise.

Read next

Sources

This article is an original reworking based on the sources below.

CVEs covered in this article

Related topicsCisco ISECisco FMCNexus DashboardCVE-2026-20079authentication bypassnetwork security
Back to home