T

Threats

Cisco ISE and Secure Firewall Critical Vulnerabilities

Overview

  • CVE: CVE-2026-20234, CVE-2026-20305, CVE-2026-20306, CVE-2026-20307, CVE-2026-20331, CVE-2026-76420

  • Severity: Critical

  • Date: 18 September 2026

Cisco has published fixes for six critical vulnerabilities across Cisco Identity Services Engine (ISE), Cisco ISE Passive Identity Connector (ISE-PIC), Secure Firewall ASA, Secure Firewall Threat Defense (FTD) and Secure Firewall Management Center (FMC).

The ISE issues require administrative access and can lead to command execution or root privilege escalation. CVE-2026-76420 affects Secure FMC and can allow an unauthenticated attacker to impersonate a peer device and execute commands as root, but only when the valid sftunnel connection between Secure FMC and Secure FTD is down.

Affected Versions

Cisco ISE and ISE-PIC - CVE-2026-20234

  • Affected: Cisco ISE and ISE-PIC, regardless of device configuration. Cisco lists 3.0.1 and earlier as requiring migration; 3.1.2, 3.2.2, 3.3, 3.4 and 3.5.3 have fixed patches available.

  • Fixed: 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4.

  • Not affected: Only products listed as vulnerable are known to be affected.

  • Source: Cisco Identity Services Engine Hardening Release: September 2026

Cisco ISE and ISE-PIC - CVE-2026-20305

  • Affected: Releases earlier than 3.1 require migration to a fixed release; ISE or ISE-PIC 3.1, 3.2, 3.3, 3.4 and 3.5.1 are affected.

  • Fixed: 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4.

  • Not affected: Cisco lists only ISE and ISE-PIC as vulnerable.

  • Source: Cisco Identity Services Engine Command Injection Vulnerabilities

Cisco ISE and ISE-PIC - CVE-2026-20306

Cisco ISE - CVE-2026-20307

Cisco Secure Firewall ASA, FTD and FMC - CVE-2026-20331

  • Affected: ASA 9.16 and earlier, 9.18, 9.20, 9.22, 9.23 and 9.24; FTD and FMC 7.0 and earlier, 7.2, 7.4, 7.6, 7.7, 10.0 and 10.1.

  • Fixed: ASA 9.16.4.103, 9.18.4.94, 9.20.4.49, 9.22.3.26, 9.23.1.47 and 9.24.1.26; FTD and FMC 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 10.0.2 and 10.1.0.

  • Not affected: Only Secure Firewall ASA, FTD and FMC products listed by Cisco are known to be affected.

  • Source: Cisco Secure Firewall ASA, FTD and FMC Software Hardening Release: September 2026

Cisco Secure FMC - CVE-2026-76420

  • Affected: Cisco Secure FMC Software, regardless of device configuration. The vendor has not specified an exact affected-version range as of 16 September 2026.

  • Fixed: Cisco directs customers to use Cisco Software Checker to identify the first fixed release for their software release and platform.

  • Not affected: Cisco Secure Firewall ASA Software and Secure Firewall Threat Defense Software.

  • Source: Cisco Secure Firewall Management Center Software Vulnerabilities

Vulnerability Breakdown

CVE-2026-20234 - Insufficiently Protected Credentials

  • Severity: Critical

  • CVSS: 9.9

  • Description: Cisco groups this issue under CWE-522, insufficiently protected credentials, in its September ISE and ISE-PIC hardening release.

  • Impact: Cisco assigns a maximum potential severity of 9.9 for this vulnerability class.

  • Conditions: Cisco states that ISE and ISE-PIC are affected regardless of device configuration.

  • Source: Cisco Identity Services Engine Hardening Release: September 2026

CVE-2026-20305 - Command Injection in Diagnostic Tools

  • Severity: Critical

  • CVSS: 9.1

  • Description: Improper validation of user-supplied input in ISE and ISE-PIC diagnostic tools can allow command injection through the web-based management interface.

  • Impact: An attacker can execute arbitrary commands on the underlying operating system and elevate privileges to root. A successful attack against a single-node deployment can make the ISE node unavailable and prevent unauthenticated endpoints from accessing the network until recovery.

  • Conditions: Authenticated remote access with valid administrative credentials is required.

  • Source: Cisco Identity Services Engine Command Injection Vulnerabilities

CVE-2026-20306 - Command Injection in the REST API

  • Severity: Critical

  • CVSS: 9.1

  • Description: Improper validation of user-supplied input in the ISE and ISE-PIC REST API can allow command injection through the web-based management interface.

  • Impact: An attacker can execute arbitrary commands and elevate privileges to root. In a single-node deployment, exploitation can cause an ISE node outage and disrupt new endpoint access.

  • Conditions: Authenticated remote access with valid administrative credentials is required.

  • Source: Cisco Identity Services Engine Command Injection Vulnerabilities

CVE-2026-20307 - Remote Code Execution Through Insecure Deserialisation

  • Severity: Critical

  • CVSS: 9.9

  • Description: Insecure deserialisation of a user-supplied Java byte stream in the ISE web-based management interface can enable arbitrary command execution.

  • Impact: An attacker can execute arbitrary code and elevate privileges to root. A successful attack can also make a single-node ISE deployment unavailable.

  • Conditions: Authenticated remote access with at least low-privileged administrative credentials is required.

  • Source: Cisco Identity Services Engine Remote Code Execution Vulnerabilities

CVE-2026-20331 - Failure of Protection Mechanisms

  • Severity: Critical

  • CVSS: 9.6

  • Description: Cisco groups this issue under CWE-693, a failure to use a protection mechanism that provides sufficient defence against directed attacks.

  • Impact: Cisco assigns a maximum potential severity of 9.6 for this vulnerability class.

  • Conditions: Cisco states that affected Secure Firewall ASA, FTD and FMC products are vulnerable regardless of device configuration.

  • Source: Cisco Secure Firewall ASA, FTD and FMC Software Hardening Release: September 2026

CVE-2026-76420 - Secure FMC Peer Impersonation

  • Severity: Critical

  • CVSS: 9.0

  • Description: Incorrect initialisation of AJP connector encryption parameters at boot can allow an unauthenticated remote attacker to impersonate a peer device.

  • Impact: An attacker can execute commands as root and gain full control of FMC REST APIs.

  • Conditions: Exploitation is possible only when the valid sftunnel connection between Secure FMC and Secure FTD is down.

  • Source: Cisco Secure Firewall Management Center Software Vulnerabilities

Mitigation

  • Identify all Cisco ISE, ISE-PIC, Secure Firewall ASA, FTD and FMC deployments.

  • Upgrade ISE and ISE-PIC to the first fixed release listed for each applicable CVE.

  • Upgrade Secure Firewall ASA, FTD and FMC to Cisco's first fixed release for the relevant branch. For CVE-2026-76420, use Cisco Software Checker to validate the exact fixed release for the deployed platform.

  • Review and restrict administrative access to ISE management interfaces and APIs. Use strong access controls and MFA for administrative accounts.

  • Monitor ISE, FMC and firewall management logs for unexpected administrative activity, command execution attempts and authentication anomalies.

  • There are no workarounds for these vulnerabilities. Apply Cisco software updates as the remediation path.

Summary for IT Teams

  • Products: Cisco ISE, ISE-PIC, Secure Firewall ASA, Secure Firewall FTD and Secure FMC

  • Threat Level: Critical, CVSS 9.0 to 9.9

  • Action Required: Prioritise deployment of Cisco's fixed releases. Restrict and review administrative access while patching, and verify the health of FMC-to-FTD sftunnel connections.

References

Need Help?

Secure ISS can help assess exposure, plan upgrades and strengthen administrative access controls. Contact us on 1300 769 460 or email the Secure ISS team.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.