Cisco released emergency fixes for more than 20 vulnerabilities across Identity Services Engine (ISE/ISE-PIC), Secure Firewall Management Center (FMC), Nexus Dashboard, and Secure Firewall ASA/FTD. Five flaws carry a maximum CVSS 10.0 rating: FMC vulnerability CVE-2026-20079 allows unauthenticated remote attackers to send crafted HTTP requests and gain root privileges, while CVE-2026-20130, CVE-2026-20192, CVE-2026-76423, and CVE-2026-76460 in ISE can permit authentication bypass, privileged administrative or system access, and in some cases code execution. A successful FMC compromise could allow attackers to modify firewall policies or disable security controls.
Cisco reports active exploitation of flaws in FMC and ISE, and CISA added the ISE privileged-API vulnerability CVE-2026-76460 to its Known Exploited Vulnerabilities catalog. Active exploitation has also been reported for ASA/FTD vulnerabilities CVE-2026-20329 and CVE-2026-20330. No workarounds are available; organizations should urgently upgrade to Cisco's fixed releases and restrict management interfaces to trusted networks while patching. ISE 3.0 and earlier are unsupported and must first be upgraded to a supported version before fixes can be applied.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
CISA added CVE-2026-76460, a CVSS 10.0 Cisco ISE privileged-API vulnerability that can provide unauthenticated full system access, to its Known Exploited Vulnerabilities catalog, indicating active exploitation.
Cisco released coordinated September 2026 updates addressing more than 20 vulnerabilities in ISE/ISE-PIC, FMC, Nexus Dashboard, and ASA/FTD software. The release included four CVSS 10.0 ISE flaws and fixed FMC and Nexus Dashboard issues; Cisco said no workarounds were available.
The critical unauthenticated remote vulnerability CVE-2026-20079 affecting Cisco Secure Firewall Management Center was known by March 2026. Crafted HTTP requests can yield root privileges on vulnerable FMC systems.
Cisco reported active exploitation in the wild of CVE-2026-20329 and CVE-2026-20330, two CVSS 9.9 vulnerabilities affecting Cisco ASA and FTD software.
Cisco reported that attackers were exploiting vulnerabilities in Secure Firewall Management Center and Identity Services Engine, including critical issues that can permit root or administrative access, authentication bypass, or code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.