Release roundup
Cisco week 38 2026: two exploited flaws lead 85 CVEs across ISE, email and firewalls
Cisco's week 38 2026 release covers 85 CVEs: 29 critical, 26 high, 29 medium and 1 low. Two are actively exploited and in CISA KEV: CVE-2026-76461 in Secure Email Gateway and CVE-2026-76460 in Identity Services Engine. Patch these first, then other internet-facing ISE, firewall and email issues.
The release at a glance
Cisco's week 38 2026 release covers 85 CVEs in scope for our readers during 14–20 September 2026. Of these, 29 are rated critical, 26 high, 29 medium and 1 low. Two vulnerabilities are noted as actively exploited and appear in CISA's Known Exploited Vulnerabilities catalog: CVE-2026-76461, a SQL injection flaw in Cisco Secure Email Gateway, and CVE-2026-76460, an authentication bypass in Cisco Identity Services Engine (ISE). Both are rated critical.
The most serious remaining issues cluster around network-facing management and identity components: Cisco ISE and ISE-PIC, Cisco Secure Firewall ASA/FTD/FMC, Cisco Nexus Dashboard, and Cisco Secure Email.
What matters most
The two issues to review first are both actively exploited.
Cisco Secure Email — CVE-2026-76461 is a critical SQL injection in AsyncOS email parsing. An unauthenticated, remote attacker can send a crafted email containing malicious SQL statements and then execute commands with root privileges. Cisco PSIRT confirms active exploitation; CISA KEV lists a due date of 17 September 2026.
Cisco Identity Services Engine and ISE-PIC — CVE-2026-76460 is an actively exploited authentication bypass on an API endpoint. Cisco advises upgrading to a fixed release, and CISA KEV sets a due date of 19 September 2026. CVE-2026-76423 is a separate critical REST API authentication bypass that can give an unauthenticated remote attacker administrative access. The ISE hardening release also includes access-control issues with a CVSS base score of 10, represented by CVE-2026-20192, and CVE-2026-20307 is remote code execution through insecure deserialisation in the ISE web interface, requiring low-privileged administrative credentials.
Cisco Secure Firewall ASA/FTD/FMC — CVE-2026-20324 in FMC's sftunnel protocol allows an authenticated remote attacker to write a file that is then executed with root privileges. The related hardening release, represented by CVE-2026-20329, covers exceptional-condition issues across ASA, FTD and FMC, with other CVEs covering neutralisation and access control.
Cisco Nexus Dashboard — CVE-2026-20322 is a representative hardening-release issue for improper access control, with related command-injection issues in the same release.
Patch in this order
- Patch Cisco Secure Email (AsyncOS) for CVE-2026-76461 first. Fixed versions are AsyncOS 15.5.5-014, 16.0.4-302 and 16.5.0-780. CISA KEV lists a due date of 17 September 2026; exploitation is active.
- Patch Cisco Identity Services Engine for CVE-2026-76460. Cisco advises upgrading to a fixed software release. CISA KEV lists a due date of 19 September 2026; exploitation is active.
- Patch internet-facing Cisco ISE and ISE-PIC for CVE-2026-76423 and the hardening-release access-control issues represented by CVE-2026-20192. These are unauthenticated remote issues rated critical.
- Patch the ISE web management interface for CVE-2026-20307, but after unauthenticated API issues because exploitation requires low-privileged administrative credentials.
- Patch Cisco Secure Firewall FMC, ASA and FTD for the hardening-release issues represented by CVE-2026-20329 and for CVE-2026-20324. Prioritise FMC deployments with registered sftunnel peers.
- Patch Cisco Nexus Dashboard for CVE-2026-20322 and related command-injection issues.
- Then work through the remaining release: 29 critical, 26 high, 29 medium and 1 low, applying vendor updates based on exposure. Pay particular attention to internet-facing Secure Email, FMC, ASA, FTD, Nexus Dashboard, ISE and ThousandEyes assets.
Beyond the patch
Next month, the difference between a manageable Cisco week and a scramble is knowing which network-facing devices are exposed and having detection already running for exploited flaws. Managed Detection & Response (MDR) provides the detection and response layer for actively exploited CVEs, Virtual CISO Services (vCISO) helps map and reduce exposure on internet-facing ISE, Secure Email and firewall management interfaces, and Implementation & Assessment Services gives the penetration testing and hardening work that finds injection, deserialisation and authentication flaws before they show up in a patch cycle.
Every CVE in this release
| CVE | Product | Severity | |
|---|---|---|---|
| CVE-2026-76461 | Cisco Secure Email | Critical 9.8 KEV | Advisory → |
| CVE-2026-76460 | Cisco Identity Services Engine Software | Critical 10.0 KEV | Advisory → |
| CVE-2026-76423 | Cisco Identity Services Engine Software | Critical 10.0 | Advisory → |
| CVE-2026-20192 | Cisco Identity Services Engine Software | Critical 10.0 | Advisory → |
| CVE-2026-20130 | Cisco Identity Services Engine Software | Critical 10.0 | Advisory → |
| CVE-2026-20307 | Cisco Identity Services Engine Software | Critical 9.9 | Advisory → |
| CVE-2026-20329 | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | Critical 9.9 | Advisory → |
| CVE-2026-20322 | Cisco Nexus Dashboard | Critical 9.9 | Advisory → |
| CVE-2026-20330 | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | Critical 9.9 | Advisory → |
| CVE-2026-20325 | Cisco Nexus Dashboard | Critical 9.9 | Advisory → |
| CVE-2026-20324 | Cisco Secure Firewall Management Center (FMC) | Critical 9.9 | Advisory → |
| CVE-2026-20332 | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | Critical 9.9 | Advisory → |
| CVE-2026-20234 | Cisco Identity Services Engine Software | Critical 9.9 | Advisory → |
| CVE-2026-20242 | Cisco Secure Firewall Management Center (FMC) | Critical 9.8 | Advisory → |
| CVE-2026-20326 | Cisco Nexus Dashboard | Critical 9.8 | Advisory → |
| CVE-2026-76441 | Cisco Secure Email and Web Manager | Critical 9.8 | Advisory → |
| CVE-2026-76440 | Cisco Secure Email | Critical 9.8 | Advisory → |
| CVE-2026-76443 | Cisco Secure Email | Critical 9.8 | Advisory → |
| CVE-2026-20353 | Cisco Secure Email | Critical 9.8 | Advisory → |
| CVE-2026-20331 | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | Critical 9.6 | Advisory → |
| CVE-2026-20306 | Cisco Identity Services Engine Software | Critical 9.1 | Advisory → |
| CVE-2026-20305 | Cisco Identity Services Engine Software | Critical 9.1 | Advisory → |
| CVE-2026-20211 | Cisco Identity Services Engine Software | Critical 9.1 | Advisory → |
| CVE-2026-20176 | Cisco Identity Services Engine Software | Critical 9.1 | Advisory → |
| CVE-2026-20194 | Cisco Identity Services Engine Software | Critical 9.1 | Advisory → |
| CVE-2026-20237 | Cisco Identity Services Engine Software | Critical 9.1 | Advisory → |
| CVE-2026-20341 | Cisco Secure Firewall Management Center (FMC) | Critical 9.1 | Advisory → |
| CVE-2026-20284 | Cisco Identity Services Engine Software | Critical 9.1 | |
| CVE-2026-76420 | Cisco Secure Firewall Management Center (FMC) | Critical 9.0 | Advisory → |
| CVE-2026-76409 | Cisco Nexus Dashboard | High 8.8 | Advisory → |
| CVE-2026-20340 | Cisco Secure Firewall Management Center (FMC) | High 8.8 | Advisory → |
| CVE-2026-20361 | Cisco Nexus Dashboard | High 8.8 | Advisory → |
| CVE-2026-20336 | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | High 8.8 | Advisory → |
| CVE-2026-20360 | Cisco Nexus Dashboard | High 8.8 | Advisory → |
| CVE-2026-20344 | Cisco Secure Firewall Management Center (FMC) | High 8.8 | Advisory → |
| CVE-2026-20333 | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | High 8.8 | Advisory → |
| CVE-2026-20250 | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | High 8.6 | Advisory → |
| CVE-2026-20295 | Cisco Secure Firewall Management Center (FMC) | High 8.6 | Advisory → |
| CVE-2026-20249 | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | High 8.6 | Advisory → |
| CVE-2026-20352 | Cisco Identity Services Engine Software | High 8.6 |
Show all 85
| CVE | Product | Severity | |
|---|---|---|---|
| CVE-2026-20135 | Cisco Secure Firewall Threat Defense (FTD) Software | High 8.6 | Advisory → |
| CVE-2026-20154 | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | High 8.6 | Advisory → |
| CVE-2026-76412 | Cisco Secure Firewall Management Center (FMC) | High 8.5 | Advisory → |
| CVE-2026-20334 | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | High 8.4 | Advisory → |
| CVE-2026-20323 | Cisco Secure Firewall Management Center (FMC) | High 8.3 | Advisory → |
| CVE-2026-76413 | Cisco Secure Firewall Management Center (FMC) | High 8.2 | Advisory → |
| CVE-2026-20335 | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | High 8.1 | Advisory → |
| CVE-2026-20342 | Cisco Secure Firewall Management Center (FMC) | High 7.7 | Advisory → |
| CVE-2026-76425 | Cisco Identity Services Engine Software | High 7.6 | Advisory → |
| CVE-2026-20247 | Cisco Identity Services Engine Software | High 7.5 | |
| CVE-2026-20343 | Cisco Secure Firewall Management Center (FMC) | High 7.5 | Advisory → |
| CVE-2026-20222 | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | High 7.4 | Advisory → |
| CVE-2026-76442 | Cisco Secure Email | High 7.5 | Advisory → |
| CVE-2026-76424 | Cisco Identity Services Engine Software | High 7.2 | Advisory → |
| CVE-2026-20300 | Cisco Identity Services Engine Software | High 7.1 | |
| CVE-2026-20248 | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | Medium 6.8 | |
| CVE-2026-76438 | Cisco BroadWorks | Medium 6.5 | |
| CVE-2026-20283 | Cisco Identity Services Engine Software | Medium 6.5 | |
| CVE-2026-20287 | Cisco Identity Services Engine Software | Medium 6.5 | Advisory → |
| CVE-2026-20309 | Cisco Identity Services Engine Software | Medium 6.1 | |
| CVE-2026-20290 | Cisco Secure Firewall Threat Defense (FTD) Software | Medium 5.8 | |
| CVE-2026-20120 | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | Medium 5.8 | |
| CVE-2026-76433 | Cisco Identity Services Engine Software | Medium 5.3 | |
| CVE-2026-20121 | Cisco Secure Firewall Adaptive Security Appliance (ASA) Software | Medium 5.3 | |
| CVE-2026-76439 | Cisco Identity Services Engine Software | Medium 5.3 | |
| CVE-2026-76444 | Cisco Identity Services Engine Software | Medium 5.3 | |
| CVE-2026-76447 | Cisco Identity Services Engine Software | Medium 5.3 | |
| CVE-2026-76432 | Cisco Identity Services Engine Software | Medium 4.9 | |
| CVE-2026-76431 | Cisco Identity Services Engine Software | Medium 4.9 | |
| CVE-2026-20282 | Cisco Identity Services Engine Software | Medium 4.9 | |
| CVE-2026-76446 | Cisco Identity Services Engine Software | Medium 4.9 | |
| CVE-2026-76428 | Cisco Identity Services Engine Software | Medium 4.9 | Advisory → |
| CVE-2026-76450 | Cisco Identity Services Engine Software | Medium 4.9 | |
| CVE-2026-76449 | Cisco Identity Services Engine Software | Medium 4.9 | |
| CVE-2026-20235 | Cisco Identity Services Engine Software | Medium 4.9 | |
| CVE-2026-76451 | Cisco Identity Services Engine Software | Medium 4.9 | |
| CVE-2026-76434 | Cisco Identity Services Engine Software | Medium 4.9 | |
| CVE-2026-76448 | Cisco Identity Services Engine Software | Medium 4.9 | |
| CVE-2026-20072 | Cisco Identity Services Engine Software | Medium 4.9 | |
| CVE-2026-76427 | Cisco Identity Services Engine Software | Medium 4.9 | Advisory → |
| CVE-2026-76426 | Cisco Identity Services Engine Software | Medium 4.9 | Advisory → |
| CVE-2026-20350 | Cisco ThousandEyes Enterprise Agent | Medium 4.7 | |
| CVE-2026-20286 | Cisco Identity Services Engine Software | Medium 4.3 | |
| CVE-2026-20285 | Cisco Identity Services Engine Software | Medium 4.3 | |
| CVE-2026-20071 | Cisco Identity Services Engine Software | Low 3.8 |
References
Vendor advisory
Other
CVE
- CVE-2026-76461 — cve.org
- CVE-2026-76461 — NVD
- CVE-2026-76460 — cve.org
- CVE-2026-76460 — NVD
- CVE-2026-76423 — cve.org
- CVE-2026-76423 — NVD
- CVE-2026-20192 — cve.org
- CVE-2026-20192 — NVD
- CVE-2026-20130 — cve.org
- CVE-2026-20130 — NVD
- CVE-2026-20307 — cve.org
- CVE-2026-20307 — NVD
- CVE-2026-20329 — cve.org
- CVE-2026-20329 — NVD
- CVE-2026-20322 — cve.org
- CVE-2026-20322 — NVD
- CVE-2026-20330 — cve.org
- CVE-2026-20330 — NVD
- CVE-2026-20325 — cve.org
- CVE-2026-20325 — NVD
- CVE-2026-20324 — cve.org
- CVE-2026-20324 — NVD
- CVE-2026-20332 — cve.org
- CVE-2026-20332 — NVD