Critical Vulnerabilities Patched in Cisco FMC, ISE, and Nexus Dashboard
Cisco has released emergency patches for dozens of critical vulnerabilities across Identity Services Engine (ISE), Secure Firewall Management Center (FMC), and Nexus Dashboard, including several flaws currently exploited in the wild.
CVE search metadata
CVE search record: CVE-2026-20079. Severity: critical. CVSS: 10.0. EPSS: 75.75%. KEV: no. Product: Secure Firewall Management Center, Identity Services Engine, Nexus Dashboard, Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense. Brief: Critical Vulnerabilities Patched in Cisco FMC, ISE, and Nexus Dashboard. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cisco-vulnerability-update/
CVE search record: CVE-2026-20316. Severity: medium. CVSS: 5.3. EPSS: 11.15%. KEV: no. Product: Secure Firewall Management Center, Identity Services Engine, Nexus Dashboard, Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense. Brief: Critical Vulnerabilities Patched in Cisco FMC, ISE, and Nexus Dashboard. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cisco-vulnerability-update/
CVE search record: CVE-2026-20284. Severity: critical. CVSS: 9.1. KEV: no. Product: Secure Firewall Management Center, Identity Services Engine, Nexus Dashboard, Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense. Brief: Critical Vulnerabilities Patched in Cisco FMC, ISE, and Nexus Dashboard. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cisco-vulnerability-update/
Cisco has released security updates addressing dozens of critical-severity vulnerabilities affecting Secure Firewall Management Center (FMC), Identity Services Engine (ISE), and Nexus Dashboard. The patches resolve a wide array of high-impact vulnerability classes, including remote code execution (RCE), command injection, authentication bypass, path traversal, and SQL injection. Notably, Cisco confirmed active exploitation in the wild for several vulnerabilities within the FMC, Secure Firewall Adaptive Security Appliance (ASA), and Secure Firewall Threat Defense (FTD) product lines, specifically related to CVE-2026-20332 and previously disclosed flaws CVE-2026-20079 and CVE-2026-20316. Additionally, a zero-day authentication bypass in ISE is currently under active exploitation. These vulnerabilities provide remote attackers with multiple pathways to obtain root access, tamper with data, and execute arbitrary commands on critical network management infrastructure.
Impact
Successful exploitation of these vulnerabilities can lead to full system compromise, including root-level remote code execution and unauthorized data access across enterprise network perimeters. The active exploitation of vulnerabilities in FMC and ISE poses a significant risk to organizations relying on these platforms for centralized firewall management, identity verification, and access control. Failure to patch these systems immediately may allow unauthorized actors to gain persistent access, bypass existing security controls, or execute denial-of-service attacks, potentially disrupting large-scale enterprise network operations.
Recommendation
Prioritize the immediate application of Cisco security patches for all instances of FMC, ISE, and Nexus Dashboard.
- Review the Cisco Security Advisories page to verify specific affected version ranges for CVE-2026-20282, CVE-2026-20283, CVE-2026-20284, CVE-2026-20332, CVE-2026-20079, and CVE-2026-20316.
- Audit network management logs for unauthorized access or anomalous command execution, particularly targeting the REST APIs of affected ISE and FMC appliances.
- Restrict management interface access to trusted administrative networks only to mitigate the risk of remote unauthenticated exploitation while patching is in progress.
- Enable extended logging for authentication and API access on all Cisco infrastructure to detect indicators of the ongoing exploitation campaigns.
Immediate actions
Patch all instances of FMC, ISE, and Nexus Dashboard following Cisco vendor guidance.
Mitigations
Restrict access to management interfaces for Cisco FMC and ISE appliances.
All identified CVEs