Security1 publisher2 min readPublished
Cisco Patches 44 CVEs Across ISE, FMC, Nexus Dashboard; Separately Warns of Exploited ISE Authentication Bypass Zero-Day
Twelve of the 20 Identity Services Engine CVEs Cisco fixed on September 16 are critical and three were public before the patch, but all three need an administrator account, so the queue starts elsewhere.
The Watch · Security desk

What happened
- Cisco published fixes on September 16 covering 44 CVEs across Identity Services Engine, Secure Firewall Management Center and Nexus Dashboard.
- Identity Services Engine took 20 of those CVEs, 12 of them rated critical severity.
- In Secure Firewall Management Center, CVE-2026-20332 covers the same bug class as CVE-2026-20079 and CVE-2026-20316, disclosed in March and July and exploited since August.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Teams with one change window have to sequence: the zero-day bypass and the firewall class bug run without credentials, so the pre-disclosed ISE trio can queue behind them.
- exposure Four of FMC's critical fixes also apply to ASA and FTD, so the remediation leaves the management console and lands on the appliances carrying production traffic.
- capability If the exploited bypass yields an administrative session, the admin precondition on the three published ISE bugs stops protecting anything and Cisco's own assessment puts root one step later.
- precedent Two members of the CVE-2026-20332 class were attacked months after their advisories went out.
All three of the ISE flaws that went public before the fix require administrative access to reach [3][4]. That gates them. Cisco rates CVE-2026-20282 and CVE-2026-20283 as medium severity while treating them as high risk, because the privileges they hand an attacker lead easily to root [5]. CVE-2026-20284 is the critical one in the set, an insufficient validation of user-supplied input that lets an attacker view or modify data and cause a denial of service [6]. "The Cisco PSIRT is aware that a public announcement is available for the vulnerabilities that are described in this advisory," the company wrote [7].
The item with no precondition is the ISE authentication bypass Cisco flagged the same day as exploited in the wild as a zero-day [14]. Cisco's ISE advisories separately list an authentication bypass in the REST API among six further critical bugs, alongside three remote code execution issues and two command injection flaws that execute with root privileges [8]. SecurityWeek describes the exploited bypass as critical-severity but does not name the CVE or say whether it is the REST API bypass [16].
On the firewall side, CVE-2026-20332 is the one to schedule first. Two vulnerabilities of the same class have already been exploited: CVE-2026-20079, disclosed in March, and CVE-2026-20316, disclosed in July, both in use since August [12]. That is roughly five months from disclosure to exploitation for the March bug and about one month for the July bug [3]. Four of the eight critical FMC CVEs are class groupings of this kind [11]. The other critical FMC bugs allow remote attackers to run arbitrary commands as root, obtain root privileges, and bypass protections and authentication [10].
The three product families come to 44 CVEs in one notification: 20 in ISE, 18 in FMC and six in Nexus Dashboard, the last covering authentication, code and command injection, cleartext storage, SQL injection and path traversal [1][13]. Twenty of the 44 are rated critical in ISE and FMC alone [2].
For an identity team the preconditions set the sequence. The exploited bypass and the FMC class need no credentials [14][12]. The three announced ISE bugs come next, because an attacker holding an administrative session on ISE would find published methods for SQL injection, data tampering and arbitrary command execution on the same appliance [3]. Five more ISE CVEs, each grouping multiple bugs, cover injection, cross-site scripting, bypass, information disclosure and path traversal [9].
What to watch
- Whether Cisco publishes a CVE and affected version list for the ISE authentication bypass already under exploitation.
- Whether a third member of the CVE-2026-20332 class turns up in attacks after CVE-2026-20079 and CVE-2026-20316.
- Whether attackers chain the exploited bypass with the three announced ISE bugs to drop the administrative access requirement.