Vulnerabilities

Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard

The vulnerabilities may lead to root access, command execution, bypasses, SQL injection, and remote code execution.  

Cisco vulnerabilities

Cisco on Wednesday announced patches for dozens of critical-severity CVEs in Secure Firewall Management Center (FMC), Identity Services Engine (ISE), and Nexus Dashboard.

The ISE security updates stand out with patches for 20 CVEs, including 12 critical-severity flaws. Three of the issues have already been publicly disclosed, Cisco warned.

Tracked as CVE-2026-20282, CVE-2026-20283, and CVE-2026-20284, they can be exploited by remote attackers for SQL injection, data tampering, and arbitrary command execution. Administrative access is required for all three.

CVE-2026-20282 and CVE-2026-20283 are medium-severity bugs, but Cisco considers them high risk, as they provide attackers with a level of privileges that could easily lead to root access.

CVE-2026-20284 is a critical-severity insufficient validation of user-supplied input that can allow attackers to view or modify data and cause a denial-of-service (DoS) condition.

“The Cisco PSIRT is aware that a public announcement is available for the vulnerabilities that are described in this advisory,” the company notes.

Advertisement. Scroll to continue reading.

Cisco’s advisories detail six other critical-severity ISE vulnerabilities: three remote code execution (RCE) issues, two command injection flaws leading to command execution with root privileges, and an authentication bypass in the REST API.

Multiple other critical-severity flaws related to injection, XSS, bypass, information disclosure, path traversal, and related attacks that are collectively tracked under five CVEs were also patched in ISE.

Cisco’s FMC updates resolve 18 CVEs, including eight critical-severity bugs that could allow remote attackers to execute arbitrary commands as root, obtain root privileges, bypass protections and authentication, and perform other types of attacks.

Four of the critical-severity CVEs address multiple vulnerabilities grouped based on their underlying class, and also affect Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD).

Of these, CVE-2026-20332 stands out, as two vulnerabilities in the same class have been exploited in the wild: CVE-2026-20079 and CVE-2026-20316, disclosed in March and July, respectively, and exploited since August.

Cisco also rolled out patches for six critical- and high-severity CVEs covering multiple authentication, code/command injection, cleartext storage, SQL injection, and path traversal vulnerabilities in Nexus Dashboard.

On Wednesday, Cisco also warned of a critical-severity authentication bypass in ISE that has been exploited in the wild as a zero-day.

Additional information is available on the company’s security advisories page and in the September 16 notification.

Related: Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation

Related: Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities

Related: Cisco Patches Critical Crosswork, Secure Workload Vulnerabilities

Related: Cisco Patches Firewall Zero-Day Exploited for DoS Attacks

Related Content

Artificial Intelligence

Hacktron researchers earned a bug bounty after demonstrating access to OpenAI employee accounts. 

Artificial Intelligence

Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority.

Vulnerabilities

CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions.

Endpoint Security

Check Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges.

Government

The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk.

Vulnerabilities

Attackers could exploit the flaws to increase resource usage, trigger an unexpected program exit, or terminate the named process.

Vulnerabilities

Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests.

Vulnerabilities

Vulnerabilities in The Events Calendar can provide attackers with remote code execution capabilities.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version