T
Threats
Cisco ISE and Secure Firewall Critical Vulnerabilities
Overview
CVE: CVE-2026-20234, CVE-2026-20305, CVE-2026-20306, CVE-2026-20307, CVE-2026-20331, CVE-2026-76420
Severity: Critical
Date: 18 September 2026
Cisco has published fixes for six critical vulnerabilities across Cisco Identity Services Engine (ISE), Cisco ISE Passive Identity Connector (ISE-PIC), Secure Firewall ASA, Secure Firewall Threat Defense (FTD) and Secure Firewall Management Center (FMC).
The ISE issues require administrative access and can lead to command execution or root privilege escalation. CVE-2026-76420 affects Secure FMC and can allow an unauthenticated attacker to impersonate a peer device and execute commands as root, but only when the valid sftunnel connection between Secure FMC and Secure FTD is down.
Affected Versions
Cisco ISE and ISE-PIC - CVE-2026-20234
Affected: Cisco ISE and ISE-PIC, regardless of device configuration. Cisco lists 3.0.1 and earlier as requiring migration; 3.1.2, 3.2.2, 3.3, 3.4 and 3.5.3 have fixed patches available.
Fixed: 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4.
Not affected: Only products listed as vulnerable are known to be affected.
Source: Cisco Identity Services Engine Hardening Release: September 2026
Cisco ISE and ISE-PIC - CVE-2026-20305
Affected: Releases earlier than 3.1 require migration to a fixed release; ISE or ISE-PIC 3.1, 3.2, 3.3, 3.4 and 3.5.1 are affected.
Fixed: 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4.
Not affected: Cisco lists only ISE and ISE-PIC as vulnerable.
Source: Cisco Identity Services Engine Command Injection Vulnerabilities
Cisco ISE and ISE-PIC - CVE-2026-20306
Affected: ISE or ISE-PIC 3.4 Patch 4 and later, and 3.5.1 Patch 3.
Fixed: 3.4 Patch 7 and 3.5 Patch 4.
Not affected: 3.3 and earlier, 3.4 Patch 3 and earlier, and 3.5.1 Patch 2 and earlier.
Source: Cisco Identity Services Engine Command Injection Vulnerabilities
Cisco ISE - CVE-2026-20307
Affected: ISE releases earlier than 3.1, 3.1, 3.2, 3.3, 3.4 and 3.5.
Fixed: 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 3.
Not affected: Cisco ISE-PIC.
Source: Cisco Identity Services Engine Remote Code Execution Vulnerabilities
Cisco Secure Firewall ASA, FTD and FMC - CVE-2026-20331
Affected: ASA 9.16 and earlier, 9.18, 9.20, 9.22, 9.23 and 9.24; FTD and FMC 7.0 and earlier, 7.2, 7.4, 7.6, 7.7, 10.0 and 10.1.
Fixed: ASA 9.16.4.103, 9.18.4.94, 9.20.4.49, 9.22.3.26, 9.23.1.47 and 9.24.1.26; FTD and FMC 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 10.0.2 and 10.1.0.
Not affected: Only Secure Firewall ASA, FTD and FMC products listed by Cisco are known to be affected.
Source: Cisco Secure Firewall ASA, FTD and FMC Software Hardening Release: September 2026
Cisco Secure FMC - CVE-2026-76420
Affected: Cisco Secure FMC Software, regardless of device configuration. The vendor has not specified an exact affected-version range as of 16 September 2026.
Fixed: Cisco directs customers to use Cisco Software Checker to identify the first fixed release for their software release and platform.
Not affected: Cisco Secure Firewall ASA Software and Secure Firewall Threat Defense Software.
Source: Cisco Secure Firewall Management Center Software Vulnerabilities
Vulnerability Breakdown
CVE-2026-20234 - Insufficiently Protected Credentials
Severity: Critical
CVSS: 9.9
Description: Cisco groups this issue under CWE-522, insufficiently protected credentials, in its September ISE and ISE-PIC hardening release.
Impact: Cisco assigns a maximum potential severity of 9.9 for this vulnerability class.
Conditions: Cisco states that ISE and ISE-PIC are affected regardless of device configuration.
Source: Cisco Identity Services Engine Hardening Release: September 2026
CVE-2026-20305 - Command Injection in Diagnostic Tools
Severity: Critical
CVSS: 9.1
Description: Improper validation of user-supplied input in ISE and ISE-PIC diagnostic tools can allow command injection through the web-based management interface.
Impact: An attacker can execute arbitrary commands on the underlying operating system and elevate privileges to root. A successful attack against a single-node deployment can make the ISE node unavailable and prevent unauthenticated endpoints from accessing the network until recovery.
Conditions: Authenticated remote access with valid administrative credentials is required.
Source: Cisco Identity Services Engine Command Injection Vulnerabilities
CVE-2026-20306 - Command Injection in the REST API
Severity: Critical
CVSS: 9.1
Description: Improper validation of user-supplied input in the ISE and ISE-PIC REST API can allow command injection through the web-based management interface.
Impact: An attacker can execute arbitrary commands and elevate privileges to root. In a single-node deployment, exploitation can cause an ISE node outage and disrupt new endpoint access.
Conditions: Authenticated remote access with valid administrative credentials is required.
Source: Cisco Identity Services Engine Command Injection Vulnerabilities
CVE-2026-20307 - Remote Code Execution Through Insecure Deserialisation
Severity: Critical
CVSS: 9.9
Description: Insecure deserialisation of a user-supplied Java byte stream in the ISE web-based management interface can enable arbitrary command execution.
Impact: An attacker can execute arbitrary code and elevate privileges to root. A successful attack can also make a single-node ISE deployment unavailable.
Conditions: Authenticated remote access with at least low-privileged administrative credentials is required.
Source: Cisco Identity Services Engine Remote Code Execution Vulnerabilities
CVE-2026-20331 - Failure of Protection Mechanisms
Severity: Critical
CVSS: 9.6
Description: Cisco groups this issue under CWE-693, a failure to use a protection mechanism that provides sufficient defence against directed attacks.
Impact: Cisco assigns a maximum potential severity of 9.6 for this vulnerability class.
Conditions: Cisco states that affected Secure Firewall ASA, FTD and FMC products are vulnerable regardless of device configuration.
Source: Cisco Secure Firewall ASA, FTD and FMC Software Hardening Release: September 2026
CVE-2026-76420 - Secure FMC Peer Impersonation
Severity: Critical
CVSS: 9.0
Description: Incorrect initialisation of AJP connector encryption parameters at boot can allow an unauthenticated remote attacker to impersonate a peer device.
Impact: An attacker can execute commands as root and gain full control of FMC REST APIs.
Conditions: Exploitation is possible only when the valid sftunnel connection between Secure FMC and Secure FTD is down.
Source: Cisco Secure Firewall Management Center Software Vulnerabilities
Mitigation
Identify all Cisco ISE, ISE-PIC, Secure Firewall ASA, FTD and FMC deployments.
Upgrade ISE and ISE-PIC to the first fixed release listed for each applicable CVE.
Upgrade Secure Firewall ASA, FTD and FMC to Cisco's first fixed release for the relevant branch. For CVE-2026-76420, use Cisco Software Checker to validate the exact fixed release for the deployed platform.
Review and restrict administrative access to ISE management interfaces and APIs. Use strong access controls and MFA for administrative accounts.
Monitor ISE, FMC and firewall management logs for unexpected administrative activity, command execution attempts and authentication anomalies.
There are no workarounds for these vulnerabilities. Apply Cisco software updates as the remediation path.
Summary for IT Teams
Products: Cisco ISE, ISE-PIC, Secure Firewall ASA, Secure Firewall FTD and Secure FMC
Threat Level: Critical, CVSS 9.0 to 9.9
Action Required: Prioritise deployment of Cisco's fixed releases. Restrict and review administrative access while patching, and verify the health of FMC-to-FTD sftunnel connections.
References
Cisco Identity Services Engine Hardening Release: September 2026
Cisco Identity Services Engine Command Injection Vulnerabilities
Cisco Identity Services Engine Remote Code Execution Vulnerabilities
Cisco Secure Firewall ASA, FTD and FMC Software Hardening Release: September 2026
Cisco Secure Firewall Management Center Software Vulnerabilities
Need Help?
Secure ISS can help assess exposure, plan upgrades and strengthen administrative access controls. Contact us on 1300 769 460 or email the Secure ISS team.

