Heightened Patch Risks Across Cisco Products in September 2026

Cisco has disclosed 97 new CVE IDs affecting its products so far this month. Cybersecurity researchers have pointed out that the raw number of CVEs is not, by itself, a direct indicator of actual security risk. Even so, September represents the largest coordinated CVE disclosure month in Cisco’s history.

Of the 97 CVE IDs, 32 are “umbrella CVEs.” These identifiers combine multiple underlying vulnerabilities under a shared CWE classification. Although this practice is officially discouraged by the CVE Program, Cisco has incorporated it into its new vulnerability disclosure policy as part of its response to AI-accelerated vulnerability discovery.

CVE-2026-76461, affecting Cisco Secure Email Gateway, carries a CVSS score of 9.8 and an EPSS ranking at or above the 80th percentile. CVE-2026-76460, which affects Cisco Identity Services Engine (ISE), has a CVSS score of 10 and an EPSS ranking at or above the 58th percentile. Both vulnerabilities have been identified as actively exploited and added to CISA’s Known Exploited Vulnerabilities catalog.

Another Cisco vulnerability, CVE-2026-20079, affects Cisco Secure Firewall Management Center (FMC). It has a CVSS score of 10 and an EPSS ranking at or above the 99th percentile. The vulnerability was also added to CISA’s KEV catalog this month. CVE-2026-20079 was originally disclosed earlier in 2026 and was discussed in the Greenbone Threat Report for March 2026.

CVE-2026-76460: Identity Services Engine (ISE) Actively Exploited for Root-Level Command Execution

  • CVSS 10 · Critical
  • EPSS 0.9% (58th percentile)
  • Actively exploited
  • Included in CISA KEV

On September 16, Cisco disclosed 42 new CVE IDs affecting Identity Services Engine. Among them, CVE-2026-76460, with a CVSS score of 10, was immediately identified as being actively exploited. It was also added to CISA’s KEV catalog.

CVE-2026-76460 is classified as a critical API authentication bypass vulnerability [CWE-648]. Successful exploitation allows a remote attacker without authentication to bypass access controls and obtain unauthorized access to the web-based management interface. Commands can then be executed with root privileges. Exploitation is possible through an HTTP request sent to an affected API endpoint.

Affected Versions and Mitigation for CVE-2026-76460

ProductAffected releaseFixed release
Cisco ISE / ISE-PIC3.13.1 Patch 12
Cisco ISE / ISE-PIC3.23.2 Patch 11
Cisco ISE / ISE-PIC3.33.3 Patch 12
Cisco ISE / ISE-PIC3.43.4 Patch 7
Cisco ISE / ISE-PIC3.53.5 Patch 4

If immediate patching cannot be completed, Cisco recommends reducing exposure to the affected device by restricting management-plane and control-plane traffic. The vendor has also published incident response guidance for identifying signs of a possible compromise.

The OPENVAS ENTERPRISE FEED provides package-level detection for CVE-2026-76460. It also offers broad vulnerability detection coverage for Cisco, including all newly disclosed CVEs affecting ISE.

CVE-2026-76461: Cisco Secure Email Gateway Actively Exploited for Root-Level RCE

  • CVSS 9.8 · Critical
  • EPSS 2.0% (80th percentile)
  • Actively exploited
  • Included in CISA KEV

CVE-2026-76461, with a CVSS score of 9.8, is an SQL injection vulnerability [CWE-89] in the email-processing logic of Cisco AsyncOS Software used by Cisco Secure Email Gateway. The vulnerability is considered to be under active exploitation and has been included in CISA’s KEV catalog.

According to Cisco, a remote attacker who does not have valid credentials can exploit the flaw by sending a specially crafted email containing malicious SQL statements to an affected appliance. Successful exploitation can result in remote code execution with root-level privileges.

Affected Versions and Mitigation for CVE-2026-76461

Product Affected releaseFixed release
Cisco Secure Email Gateway15.5 and earlier15.5.5-014
Cisco Secure Email Gateway16.016.0.4-302
Cisco Secure Email Gateway16.516.5.0-780

The OPENVAS ENTERPRISE FEED provides package-level detection for CVE-2026-76461 in Cisco Secure Email Gateway.
Cisco recommends examining logs for suspicious activity, including occurrences of the SQL command pattern COPY…TO PROGRAM. A successful compromise creates an additional lateral-movement risk in clustered environments. Exploitation may expose private SSH keys used for communication between cluster members.

Broader Exposure for Cisco Secure Email Platform

Cisco published two additional advisories covering seven CVE IDs across different components of the Secure Email product family. Five of these CVE IDs represent CVE clusters. Four of the seven CVE IDs have critical severity ratings. This indicates that they include security vulnerabilities that can be exploited remotely without authentication. The OPENVAS ENTERPRISE FEED includes package-level detection for the actively exploited CVE-2026-76461. Detection is also available for all other newly disclosed vulnerabilities affecting Cisco Secure Email Gateway.

Critical-Severity CVE Clusters Across Cisco Secure Firewall Products

Cisco also disclosed 29 CVE IDs affecting Secure Firewall Adaptive Security Appliance (ASA), Secure Firewall Threat Defense (FTD), and Secure Firewall Management Center (FMC). Eight of these identifiers have critical severity ratings. This means they include security issues that can be remotely exploited without authentication. None of the newly disclosed vulnerabilities in this group have yet been identified as actively exploited.

In a separate blog post, Cisco provided further information about active campaigns targeting CVE-2026-20079 and CVE-2026-20316, both of which affect FMC.

CVE-2026-20079 has a CVSS score of 10 and an EPSS ranking at or above the 99th percentile. CVE-2026-20316 has a CVSS score of 5.3 and an EPSS ranking at or above the 96th percentile.

Both vulnerabilities are included in CISA’s KEV catalog. CVE-2026-20316 was added to the catalog in July and is known to be linked to ransomware activity. CVE-2026-20079, meanwhile, became a new KEV addition in September 2026.
The OPENVAS ENTERPRISE FEED contains dedicated package-level detection tests for every newly disclosed CVE affecting ASA, FTD, and FMC.

Detection for the actively exploited CVE-2026-20079 and CVE-2026-20316 has been available in the feed since the respective vulnerabilities were disclosed.

Critical-Severity CVE Clusters Affecting Cisco IOS XR

Seven CVE clusters were disclosed as part of Cisco’s September IOS XR Software Security Hardening Release. Two of the seven clusters received critical severity ratings. This means that they contain vulnerabilities capable of remote exploitation without authentication. None of these clusters have so far been identified as actively exploited.

Every IOS XR Software release is affected, including IOS XR7 (LNT), irrespective of device configuration. Fixed versions are available in IOS XR 26.2.2 and 26.3.1. No workarounds are available.

Older supported release trains – including 7.3, 7.9, 7.10, 7.11, 24.1–24.4, 25.1–25.4, 26.1, and 26.2 – require an upgrade to a maintenance release before the applicable Software Maintenance Updates (SMUs) can be installed. Additional information is available in Cisco’s release advisory.

The OPENVAS ENTERPRISE FEED includes a remote banner check covering every CVE cluster included in the September IOS XR Software Security Hardening Release.

Critical-Severity CVE Clusters Affecting Cisco Nexus Dashboard

Cisco disclosed six CVE clusters in its Nexus Dashboard Hardening Release. Three of the six clusters received critical severity ratings. This indicates that they contain security issues that can be exploited remotely without authentication. None of these vulnerabilities have so far been classified as actively exploited. No workaround is available to mitigate the affected flaws, and every Cisco Nexus Dashboard configuration is impacted.

ProductAffected releaseFixed release
Cisco Nexus Dashboard4.2 and earlierMigrate to a fixed release
Cisco Nexus Dashboard4.34.3.1.175

The OPENVAS ENTERPRISE FEED provides a remote banner check covering all CVE clusters included in the Nexus Dashboard Hardening Release. Migration to an available fixed version is recommended as soon as possible.

Summary

September 2026 represents Cisco’s largest coordinated vulnerability disclosure period on record, with 97 newly published CVE IDs affecting major enterprise networking and security products.

Thirty-two of those identifiers are umbrella CVEs. Because each umbrella CVE may represent multiple underlying vulnerabilities, the precise number of individual software flaws represented by the disclosures is not known.

During September, vulnerabilities affecting Cisco ISE, Secure Email Gateway, and FMC were added to CISA’s KEV catalog, confirming that exploitation has been observed in the wild.

Regular vulnerability scanning across IT networks and endpoints can help identify newly emerging security risks and support remediation prioritization.

Request a free trial OPENVAS (Enterprise)



    Subscribe to news