Critical CVE-2026-20079, CVE-2026-76460, CVE-2026-76461, CVE-2026-76504, CVE-2026-20316, CVE-2026-20349, CVE-2026-20230, CVE-2026-20245, CVE-2026-20262 — Nine Cisco vulnerabilities were added to CISA's exploited list between June and September 2026, including CVSS 10 authentication bypasses in Firewall Management Center and ISE and a crafted-email root exploit in Secure Email Gateway. What's affected and how to check.
Published 2026-10-08 · Last updated 2026-10-08
TL;DR: Cisco's security and network-management products have been hit hard this summer: two CVSS 10 authentication bypasses (Firewall Management Center and Identity Services Engine), a Secure Email Gateway bug where one crafted email gives root, an ASA/FTD VPN crash bug, hard-coded credentials used by ransomware, and four SD-WAN/UCM flaws. Run Cisco's Software Checker against every device and upgrade to the first fixed release it lists.
| CVE-2026-20079 | FMC: auth bypass → scripts run as root. CVSS 10. KEV 2026-09-09 |
|---|---|
| CVE-2026-76460 | ISE / ISE-PIC: API auth bypass. CVSS 10. KEV 2026-09-16 |
| CVE-2026-76461 | Secure Email Gateway: crafted email → SQL injection → root commands. CVSS 9.8. KEV 2026-09-14 |
| CVE-2026-76504 | Catalyst SD-WAN Manager: URI-encoding auth bypass → admin. CVSS 9.8. KEV 2026-09-30 |
| CVE-2026-20316 | FMC: static low-privilege credentials. Known ransomware use. KEV 2026-07-29 |
| CVE-2026-20349 | ASA / FTD Remote Access SSL VPN: crafted HTTP → device reload. CVSS 8.6. KEV 2026-08-11 |
| Also | CVE-2026-20230 (Unified CM SSRF → file write), CVE-2026-20245 and CVE-2026-20262 (SD-WAN root/file write, authenticated) |
Cisco lists affected releases per train in each advisory, and the lists are long. The reliable way to check is the Cisco Software Checker: enter your product and version and it tells you which advisories apply and the first fixed release.
# ASA
show version | include Version
# FTD (from the FTD CLI)
show version
# FMC / ISE: version is on the web UI's About page; ISE CLI: show version
# Secure Email Gateway: version (CLI) or System Administration > System Upgrade
Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.