# Cisco patches dozens of ASA, FTD, FMC, ISE flaws

Published: 2026-09-17 · Severity: severe · Sectors: technology, infrastructure
Canonical: https://vorant.io/reports/1430dafe-e061-51b2-929a-2d350875e3d2/cisco-patches-dozens-of-asa-ftd-fmc-ise-flaws

> Cisco released a large batch of security advisories for ASA, FTD, FMC and ISE covering RCE, privilege escalation, DoS and SQLi flaws; one (CVE-2026-76460) is actively exploited.

CERT-FR relayed a bundle of Cisco security advisories (published 16 September 2026) covering multiple vulnerabilities across Adaptive Security Appliance (ASA), Firewall Threat Defense (FTD), Firewall Management Center (FMC) and Identity Services Engine (ISE)/ISE-PIC. The flaws span a wide range of impact categories including remote code execution, privilege escalation, remote denial of service, SQL injection, data integrity/confidentiality loss and security-policy bypass. Cisco has confirmed that CVE-2026-76460 is being actively exploited in the wild, making prompt patching a priority for any organisation running affected ASA/FTD/FMC/ISE deployments.

Several ISE branches are affected by unpatched vulnerabilities because their support lifecycle has ended or is ending: ISE 3.1 and 3.2 will lose support on 30 November 2027 and will not receive fixes for CVE-2026-20247, CVE-2026-20282, CVE-2026-20300, CVE-2026-76424, CVE-2026-76425, CVE-2026-76426, CVE-2026-76427 and CVE-2026-76428; ISE 3.0 has been unsupported since 13 July 2025. ISE-PIC has been discontinued, with 3.4 being the last maintained release. Defenders on these unsupported branches should plan migration to a patched, supported release (ISE 3.4 Patch 7, 3.5 Patch 4, 3.3 Patch 12, or later) since no further fixes will be issued.

Because the advisory consolidates numerous separate Cisco security bulletins (ASA/FTD logging DoS, DTLS DoS, EIGRP DoS, IKEv2 certificate DoS, FMC Java RCE, FMC multi-vulnerabilities, ISE command injection, ISE SQL injection, ISE RCE, RADIUS DoS, TLS 1.3 DoS, and general hardening guidance), defenders should consult the individual Cisco bulletins referenced by CERT-FR to determine exact affected versions and apply vendor-supplied patches. Given the presence of at least one actively exploited CVE affecting widely deployed perimeter security and identity/network-access-control products, this warrants urgent patch prioritization.

## Mentioned in this report

- Vulnerabilities: CVE-2026-20130, CVE-2026-20135, CVE-2026-20154, CVE-2026-20176, CVE-2026-20192, CVE-2026-20194, CVE-2026-20211, CVE-2026-20222, CVE-2026-20234, CVE-2026-20237, CVE-2026-20242, CVE-2026-20247, CVE-2026-20249, CVE-2026-20250, CVE-2026-20282, CVE-2026-20283, CVE-2026-20284, CVE-2026-20287, CVE-2026-20295, CVE-2026-20300, CVE-2026-20305, CVE-2026-20306, CVE-2026-20307, CVE-2026-20322, CVE-2026-20323, CVE-2026-20324, CVE-2026-20325, CVE-2026-20326, CVE-2026-20329, CVE-2026-20330, CVE-2026-20331, CVE-2026-20332, CVE-2026-20333, CVE-2026-20334, CVE-2026-20335, CVE-2026-20336, CVE-2026-20340, CVE-2026-20341, CVE-2026-76424, CVE-2026-76460 (KEV)

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1197

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/1430dafe-e061-51b2-929a-2d350875e3d2/cisco-patches-dozens-of-asa-ftd-fmc-ise-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
