news.mlab.sh
Back to the feed
vulnerability

Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard

CriticalCVSS 10.0
Summary

Cisco has released patches to address dozens of critical and high-severity vulnerabilities across its Secure Firewall Management Center (FMC), Identity Services Engine (ISE), and Nexus Dashboard products. Several of these vulnerabilities have been actively exploited in the wild, including a zero-day authentication bypass in ISE. The updates aim to mitigate risks associated with remote code execution, command injection, and data tampering.

Cisco announced on Wednesday that it is releasing patches to address a significant number of vulnerabilities affecting its Secure Firewall Management Center (FMC), Identity Services Engine (ISE), and Nexus Dashboard products. The company’s Product Security Incident Response Team (PSIRT) is aware of a public announcement detailing these vulnerabilities.

Specifically, ISE security updates include patches for 20 CVEs, with 12 of these classified as critical-severity. These vulnerabilities include remote code execution (RCE) issues, command injection flaws leading to command execution with root privileges, and an authentication bypass in the REST API.

Several of these vulnerabilities have been exploited in the wild, including a zero-day authentication bypass in ISE. CVE-2026-20282, CVE-2026-20283, and CVE-2026-20284 are critical-severity flaws that can be exploited by remote attackers for SQL injection, data tampering, and arbitrary command execution, requiring administrative access. CVE-2026-20282 and CVE-2026-20316 are medium-severity bugs, but Cisco considers them high risk due to the potential for attackers to gain root access.

FMC updates address 18 CVEs, including eight critical-severity bugs that could allow remote attackers to execute arbitrary commands as root, obtain root privileges, bypass protections and authentication, and perform other types of attacks. CVE-2026-20332 stands out, as two vulnerabilities in the same class have been exploited in the wild since August.

Six critical- and high-severity CVEs have been patched in Nexus Dashboard, covering multiple authentication, code/command injection, cleartext storage, SQL injection, and path traversal vulnerabilities. The patches are intended to mitigate risks associated with unauthorized access and data compromise.

Read the full article at SecurityWeek