Skip to content

Release roundup

Cisco week 38 2026: two exploited flaws lead 85 CVEs across ISE, email and firewalls

Critical 10.0 KEV Vendor: Cisco 85 CVEs in scope Published

Cisco's week 38 2026 release covers 85 CVEs: 29 critical, 26 high, 29 medium and 1 low. Two are actively exploited and in CISA KEV: CVE-2026-76461 in Secure Email Gateway and CVE-2026-76460 in Identity Services Engine. Patch these first, then other internet-facing ISE, firewall and email issues.

The release at a glance

Cisco's week 38 2026 release covers 85 CVEs in scope for our readers during 14–20 September 2026. Of these, 29 are rated critical, 26 high, 29 medium and 1 low. Two vulnerabilities are noted as actively exploited and appear in CISA's Known Exploited Vulnerabilities catalog: CVE-2026-76461, a SQL injection flaw in Cisco Secure Email Gateway, and CVE-2026-76460, an authentication bypass in Cisco Identity Services Engine (ISE). Both are rated critical.

The most serious remaining issues cluster around network-facing management and identity components: Cisco ISE and ISE-PIC, Cisco Secure Firewall ASA/FTD/FMC, Cisco Nexus Dashboard, and Cisco Secure Email.

What matters most

The two issues to review first are both actively exploited.

Cisco Secure Email — CVE-2026-76461 is a critical SQL injection in AsyncOS email parsing. An unauthenticated, remote attacker can send a crafted email containing malicious SQL statements and then execute commands with root privileges. Cisco PSIRT confirms active exploitation; CISA KEV lists a due date of 17 September 2026.

Cisco Identity Services Engine and ISE-PIC — CVE-2026-76460 is an actively exploited authentication bypass on an API endpoint. Cisco advises upgrading to a fixed release, and CISA KEV sets a due date of 19 September 2026. CVE-2026-76423 is a separate critical REST API authentication bypass that can give an unauthenticated remote attacker administrative access. The ISE hardening release also includes access-control issues with a CVSS base score of 10, represented by CVE-2026-20192, and CVE-2026-20307 is remote code execution through insecure deserialisation in the ISE web interface, requiring low-privileged administrative credentials.

Cisco Secure Firewall ASA/FTD/FMC — CVE-2026-20324 in FMC's sftunnel protocol allows an authenticated remote attacker to write a file that is then executed with root privileges. The related hardening release, represented by CVE-2026-20329, covers exceptional-condition issues across ASA, FTD and FMC, with other CVEs covering neutralisation and access control.

Cisco Nexus Dashboard — CVE-2026-20322 is a representative hardening-release issue for improper access control, with related command-injection issues in the same release.

Patch in this order

  1. Patch Cisco Secure Email (AsyncOS) for CVE-2026-76461 first. Fixed versions are AsyncOS 15.5.5-014, 16.0.4-302 and 16.5.0-780. CISA KEV lists a due date of 17 September 2026; exploitation is active.
  2. Patch Cisco Identity Services Engine for CVE-2026-76460. Cisco advises upgrading to a fixed software release. CISA KEV lists a due date of 19 September 2026; exploitation is active.
  3. Patch internet-facing Cisco ISE and ISE-PIC for CVE-2026-76423 and the hardening-release access-control issues represented by CVE-2026-20192. These are unauthenticated remote issues rated critical.
  4. Patch the ISE web management interface for CVE-2026-20307, but after unauthenticated API issues because exploitation requires low-privileged administrative credentials.
  5. Patch Cisco Secure Firewall FMC, ASA and FTD for the hardening-release issues represented by CVE-2026-20329 and for CVE-2026-20324. Prioritise FMC deployments with registered sftunnel peers.
  6. Patch Cisco Nexus Dashboard for CVE-2026-20322 and related command-injection issues.
  7. Then work through the remaining release: 29 critical, 26 high, 29 medium and 1 low, applying vendor updates based on exposure. Pay particular attention to internet-facing Secure Email, FMC, ASA, FTD, Nexus Dashboard, ISE and ThousandEyes assets.

Beyond the patch

Next month, the difference between a manageable Cisco week and a scramble is knowing which network-facing devices are exposed and having detection already running for exploited flaws. Managed Detection & Response (MDR) provides the detection and response layer for actively exploited CVEs, Virtual CISO Services (vCISO) helps map and reduce exposure on internet-facing ISE, Secure Email and firewall management interfaces, and Implementation & Assessment Services gives the penetration testing and hardening work that finds injection, deserialisation and authentication flaws before they show up in a patch cycle.

Every CVE in this release

CVEProductSeverity
CVE-2026-76461Cisco Secure EmailCritical 9.8 KEVAdvisory →
CVE-2026-76460Cisco Identity Services Engine SoftwareCritical 10.0 KEVAdvisory →
CVE-2026-76423Cisco Identity Services Engine SoftwareCritical 10.0Advisory →
CVE-2026-20192Cisco Identity Services Engine SoftwareCritical 10.0Advisory →
CVE-2026-20130Cisco Identity Services Engine SoftwareCritical 10.0Advisory →
CVE-2026-20307Cisco Identity Services Engine SoftwareCritical 9.9Advisory →
CVE-2026-20329Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareCritical 9.9Advisory →
CVE-2026-20322Cisco Nexus DashboardCritical 9.9Advisory →
CVE-2026-20330Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareCritical 9.9Advisory →
CVE-2026-20325Cisco Nexus DashboardCritical 9.9Advisory →
CVE-2026-20324Cisco Secure Firewall Management Center (FMC)Critical 9.9Advisory →
CVE-2026-20332Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareCritical 9.9Advisory →
CVE-2026-20234Cisco Identity Services Engine SoftwareCritical 9.9Advisory →
CVE-2026-20242Cisco Secure Firewall Management Center (FMC)Critical 9.8Advisory →
CVE-2026-20326Cisco Nexus DashboardCritical 9.8Advisory →
CVE-2026-76441Cisco Secure Email and Web ManagerCritical 9.8Advisory →
CVE-2026-76440Cisco Secure EmailCritical 9.8Advisory →
CVE-2026-76443Cisco Secure EmailCritical 9.8Advisory →
CVE-2026-20353Cisco Secure EmailCritical 9.8Advisory →
CVE-2026-20331Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareCritical 9.6Advisory →
CVE-2026-20306Cisco Identity Services Engine SoftwareCritical 9.1Advisory →
CVE-2026-20305Cisco Identity Services Engine SoftwareCritical 9.1Advisory →
CVE-2026-20211Cisco Identity Services Engine SoftwareCritical 9.1Advisory →
CVE-2026-20176Cisco Identity Services Engine SoftwareCritical 9.1Advisory →
CVE-2026-20194Cisco Identity Services Engine SoftwareCritical 9.1Advisory →
CVE-2026-20237Cisco Identity Services Engine SoftwareCritical 9.1Advisory →
CVE-2026-20341Cisco Secure Firewall Management Center (FMC)Critical 9.1Advisory →
CVE-2026-20284Cisco Identity Services Engine SoftwareCritical 9.1
CVE-2026-76420Cisco Secure Firewall Management Center (FMC)Critical 9.0Advisory →
CVE-2026-76409Cisco Nexus DashboardHigh 8.8Advisory →
CVE-2026-20340Cisco Secure Firewall Management Center (FMC)High 8.8Advisory →
CVE-2026-20361Cisco Nexus DashboardHigh 8.8Advisory →
CVE-2026-20336Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareHigh 8.8Advisory →
CVE-2026-20360Cisco Nexus DashboardHigh 8.8Advisory →
CVE-2026-20344Cisco Secure Firewall Management Center (FMC)High 8.8Advisory →
CVE-2026-20333Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareHigh 8.8Advisory →
CVE-2026-20250Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareHigh 8.6Advisory →
CVE-2026-20295Cisco Secure Firewall Management Center (FMC)High 8.6Advisory →
CVE-2026-20249Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareHigh 8.6Advisory →
CVE-2026-20352Cisco Identity Services Engine SoftwareHigh 8.6
Show all 85
CVEProductSeverity
CVE-2026-20135Cisco Secure Firewall Threat Defense (FTD) SoftwareHigh 8.6Advisory →
CVE-2026-20154Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareHigh 8.6Advisory →
CVE-2026-76412Cisco Secure Firewall Management Center (FMC)High 8.5Advisory →
CVE-2026-20334Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareHigh 8.4Advisory →
CVE-2026-20323Cisco Secure Firewall Management Center (FMC)High 8.3Advisory →
CVE-2026-76413Cisco Secure Firewall Management Center (FMC)High 8.2Advisory →
CVE-2026-20335Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareHigh 8.1Advisory →
CVE-2026-20342Cisco Secure Firewall Management Center (FMC)High 7.7Advisory →
CVE-2026-76425Cisco Identity Services Engine SoftwareHigh 7.6Advisory →
CVE-2026-20247Cisco Identity Services Engine SoftwareHigh 7.5
CVE-2026-20343Cisco Secure Firewall Management Center (FMC)High 7.5Advisory →
CVE-2026-20222Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareHigh 7.4Advisory →
CVE-2026-76442Cisco Secure EmailHigh 7.5Advisory →
CVE-2026-76424Cisco Identity Services Engine SoftwareHigh 7.2Advisory →
CVE-2026-20300Cisco Identity Services Engine SoftwareHigh 7.1
CVE-2026-20248Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareMedium 6.8
CVE-2026-76438Cisco BroadWorksMedium 6.5
CVE-2026-20283Cisco Identity Services Engine SoftwareMedium 6.5
CVE-2026-20287Cisco Identity Services Engine SoftwareMedium 6.5Advisory →
CVE-2026-20309Cisco Identity Services Engine SoftwareMedium 6.1
CVE-2026-20290Cisco Secure Firewall Threat Defense (FTD) SoftwareMedium 5.8
CVE-2026-20120Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareMedium 5.8
CVE-2026-76433Cisco Identity Services Engine SoftwareMedium 5.3
CVE-2026-20121Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareMedium 5.3
CVE-2026-76439Cisco Identity Services Engine SoftwareMedium 5.3
CVE-2026-76444Cisco Identity Services Engine SoftwareMedium 5.3
CVE-2026-76447Cisco Identity Services Engine SoftwareMedium 5.3
CVE-2026-76432Cisco Identity Services Engine SoftwareMedium 4.9
CVE-2026-76431Cisco Identity Services Engine SoftwareMedium 4.9
CVE-2026-20282Cisco Identity Services Engine SoftwareMedium 4.9
CVE-2026-76446Cisco Identity Services Engine SoftwareMedium 4.9
CVE-2026-76428Cisco Identity Services Engine SoftwareMedium 4.9Advisory →
CVE-2026-76450Cisco Identity Services Engine SoftwareMedium 4.9
CVE-2026-76449Cisco Identity Services Engine SoftwareMedium 4.9
CVE-2026-20235Cisco Identity Services Engine SoftwareMedium 4.9
CVE-2026-76451Cisco Identity Services Engine SoftwareMedium 4.9
CVE-2026-76434Cisco Identity Services Engine SoftwareMedium 4.9
CVE-2026-76448Cisco Identity Services Engine SoftwareMedium 4.9
CVE-2026-20072Cisco Identity Services Engine SoftwareMedium 4.9
CVE-2026-76427Cisco Identity Services Engine SoftwareMedium 4.9Advisory →
CVE-2026-76426Cisco Identity Services Engine SoftwareMedium 4.9Advisory →
CVE-2026-20350Cisco ThousandEyes Enterprise AgentMedium 4.7
CVE-2026-20286Cisco Identity Services Engine SoftwareMedium 4.3
CVE-2026-20285Cisco Identity Services Engine SoftwareMedium 4.3
CVE-2026-20071Cisco Identity Services Engine SoftwareLow 3.8

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.