VYPR
patchPublished Sep 17, 2026· 1 source

Cisco Patches Dozens of Critical Flaws Across FMC, ISE, and Nexus Dashboard

Cisco has released urgent patches for numerous critical vulnerabilities affecting its Secure Firewall Management Center (FMC), Identity Services Engine (ISE), and Nexus Dashboard products, some of which are already publicly disclosed or exploited.

Cisco has issued a significant wave of security updates, addressing dozens of critical vulnerabilities across its Secure Firewall Management Center (FMC), Identity Services Engine (ISE), and Nexus Dashboard product lines. The company urged customers to apply these patches promptly to mitigate risks ranging from unauthorized access to full system compromise.

The Identity Services Engine (ISE) is particularly affected, receiving patches for 20 distinct vulnerabilities, including 12 rated as critical severity. Cisco highlighted that three of these critical flaws (CVE-2026-20282, CVE-2026-20283, and CVE-2026-20284) have already seen public disclosure. These vulnerabilities, requiring administrative access for exploitation, can enable attackers to perform SQL injection, tamper with data, and execute arbitrary commands. While two are classified as medium severity, Cisco considers them high risk due to their potential to escalate privileges to root access.

Another critical ISE vulnerability, CVE-2026-20284, stems from insufficient validation of user-supplied input, potentially leading to data viewing or modification and denial-of-service conditions. Beyond these, Cisco's advisories detail six other critical ISE vulnerabilities, including three that permit remote code execution (RCE), two enabling command injection with root privileges, and an authentication bypass flaw within the REST API. Several other critical vulnerabilities related to injection, cross-site scripting (XSS), bypasses, information disclosure, and path traversal were also addressed in ISE.

The Secure Firewall Management Center (FMC) also sees substantial updates, with patches released for 18 CVEs, eight of which are critical. These flaws could allow remote attackers to execute arbitrary commands as root, gain root privileges, bypass security controls and authentication mechanisms, and conduct other malicious activities. Notably, four of these critical FMC vulnerabilities also impact Cisco's Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) products.

Among the critical FMC-related vulnerabilities, CVE-2026-20332 is particularly concerning as it is part of a class of vulnerabilities that have already been exploited in the wild. Cisco previously disclosed CVE-2026-20079 and CVE-2026-20316 in March and July respectively, and these have been actively exploited since August, underscoring the immediate threat posed by related flaws.

Cisco's Nexus Dashboard product line is not exempt, with patches addressing six critical and high-severity CVEs. These vulnerabilities encompass issues related to authentication, code and command injection, cleartext storage of sensitive information, SQL injection, and path traversal attacks.

Adding to the urgency, Cisco also disclosed on Wednesday that a critical-severity authentication bypass vulnerability in ISE has been exploited in the wild as a zero-day. This revelation underscores the active threat landscape and the importance of immediate patching for affected systems. Customers are strongly advised to consult Cisco's security advisories for detailed information and to apply the necessary updates as soon as possible to protect their networks.

These extensive patches highlight Cisco's ongoing efforts to address a wide array of security weaknesses across its enterprise networking and security portfolio. The company's proactive disclosure of publicly known and exploited vulnerabilities emphasizes the critical need for organizations to maintain vigilant patch management practices and stay informed about emerging threats.

Synthesized by Vypr AI