Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

Cisco Exploited CVEs 2026: FMC CVSS 10 Auth Bypass, ISE, Secure Email, ASA/FTD VPN, SD-WAN

Critical CVE-2026-20079, CVE-2026-76460, CVE-2026-76461, CVE-2026-76504, CVE-2026-20316, CVE-2026-20349, CVE-2026-20230, CVE-2026-20245, CVE-2026-20262 — Nine Cisco vulnerabilities were added to CISA's exploited list between June and September 2026, including CVSS 10 authentication bypasses in Firewall Management Center and ISE and a crafted-email root exploit in Secure Email Gateway. What's affected and how to check.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: Cisco's security and network-management products have been hit hard this summer: two CVSS 10 authentication bypasses (Firewall Management Center and Identity Services Engine), a Secure Email Gateway bug where one crafted email gives root, an ASA/FTD VPN crash bug, hard-coded credentials used by ransomware, and four SD-WAN/UCM flaws. Run Cisco's Software Checker against every device and upgrade to the first fixed release it lists.

CVE-2026-20079FMC: auth bypass → scripts run as root. CVSS 10. KEV 2026-09-09
CVE-2026-76460ISE / ISE-PIC: API auth bypass. CVSS 10. KEV 2026-09-16
CVE-2026-76461Secure Email Gateway: crafted email → SQL injection → root commands. CVSS 9.8. KEV 2026-09-14
CVE-2026-76504Catalyst SD-WAN Manager: URI-encoding auth bypass → admin. CVSS 9.8. KEV 2026-09-30
CVE-2026-20316FMC: static low-privilege credentials. Known ransomware use. KEV 2026-07-29
CVE-2026-20349ASA / FTD Remote Access SSL VPN: crafted HTTP → device reload. CVSS 8.6. KEV 2026-08-11
AlsoCVE-2026-20230 (Unified CM SSRF → file write), CVE-2026-20245 and CVE-2026-20262 (SD-WAN root/file write, authenticated)

What’s been exploited

Firewalls: FMC, ASA, FTD

  • CVE-2026-20079 (CVSS 10): a system process created at boot in Secure Firewall Management Center lets an unauthenticated attacker send crafted HTTP requests, run scripts, and get root on the FMC, the box that pushes policy to every firewall you own.
  • CVE-2026-20316: FMC shipped with static credentials for a low-privileged account. An unauthenticated attacker can log in with it and read sensitive data. CISA marks this one as used by ransomware groups.
  • CVE-2026-20349 (8.6): a crafted HTTP request to the Remote Access SSL VPN service on ASA or FTD reloads the device: your firewall and VPN go down on demand.

Identity and email

  • CVE-2026-76460 (CVSS 10): an API endpoint in Identity Services Engine (and ISE Passive Identity Connector) doesn’t enforce authentication, giving unauthenticated access around the management UI. ISE controls who gets on your network.
  • CVE-2026-76461 (9.8): the email parser in AsyncOS for Secure Email Gateway can be fed SQL inside a crafted message, leading to arbitrary commands as root. The attacker only has to send an email to your domain.

SD-WAN and voice

  • CVE-2026-76504 (9.8): URI-encoding trick bypasses an authentication rule in the Catalyst SD-WAN Manager (vManage) API, giving admin privileges without logging in.
  • CVE-2026-20245 / CVE-2026-20262: authenticated SD-WAN bugs (root via crafted file, arbitrary file write), typically chained after the bypass.
  • CVE-2026-20230: SSRF in Unified Communications Manager 14 and 15 lets an unauthenticated attacker write files on the server.

Am I affected?

Cisco lists affected releases per train in each advisory, and the lists are long. The reliable way to check is the Cisco Software Checker: enter your product and version and it tells you which advisories apply and the first fixed release.

# ASA
show version | include Version
# FTD (from the FTD CLI)
show version
# FMC / ISE: version is on the web UI's About page; ISE CLI: show version
# Secure Email Gateway: version (CLI) or System Administration > System Upgrade

How to patch

  1. Upgrade each product to the first fixed release from the Software Checker (or the advisory’s “Fixed Software” table). Most of these have no workaround per Cisco.
  2. Prioritise anything reachable from the internet: Secure Email Gateways (they receive internet mail by design), ASA/FTD with AnyConnect/Secure Client VPN, and any FMC, ISE or SD-WAN Manager UI not restricted to a management network.
  3. For CVE-2026-20316, after upgrading, confirm no unexpected accounts can log in to FMC.

Hardening

  • Management interfaces (FMC, ISE, SD-WAN Manager, UCM admin) belong on an isolated management network or behind a VPN, never on the internet.
  • On ASA/FTD, restrict which sources can reach the VPN portal if your users come from known regions, and keep threat-detection for VPN services enabled.
  • Forward device logs to a SIEM or syslog server off the box. On compromised appliances, local logs are the first thing attackers clean.

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories