Tough week for Cisco admins: network security system under attack, firewall management center vulnerable
Cisco drops a batch of 16 critical security advisories in three days.

Cisco company logo on mobile screen. Image by PJ McDonnell / Shutterstock.com
- Cisco says attackers are exploiting a critical Identity Services Engine flaw that needs an immediate software update.
- The bug lets remote hackers bypass login checks and take full control without credentials or user action.
- Cisco also fixed critical Secure Firewall Management Center bugs, but says it has not seen exploitation.
- The US cyber agency ordered federal agencies to patch the exploited Cisco vulnerability within three days.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Cisco has disclosed its second drop-everything zero-day in a week. Hackers are bypassing authentication on the Identity Services Engine, the product that centralizes network access control for a large swath of the enterprise world. Critical bugs are affecting Cisco’s Secure Firewall Management Center.
Cisco dropped a batch of 14 critical security advisories 2 days after unveiling a separate actively exploited zero-day in its Secure Email Gateway – an email security filter was defeated by emails with injected SQL code.
An extremely serious bug, rated 10 out of 10 on the severity scale, affects Identity Services Engine (ISE), and attackers are already exploiting it.
ISE centrally manages enterprise network access control and policies, unifying authentication.
Remote hackers can reliably breach it with zero credentials or privileges, and no victim interaction. The worst-case vulnerability, tracked as CVE-2026-76460, enables attackers to gain complete control.
“The Cisco PSIRT is aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability,” Cisco said in an advisory.
The bug is caused by insufficient authentication controls – attackers can send a crafted request to an affected API endpoint, bypass the web-based management interface, and gain unauthorized access.
Cisco warned that all configurations of Cisco ISE and Cisco ISE Passive Identity Connector are vulnerable, and there are no other workarounds but upgrading to the latest software.
The Cybersecurity and Infrastructure Security Agency (CISA) has added the bug to its Known Exploited Vulnerabilities list, urging federal agencies to update before the 3-day deadline ends.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Successful exploitation allows attackers to run commands with root privileges, enabling them to remove any indicators of compromise. Cisco still recommends reviewing access logs on each node for suspicious usernames, as well as cross-checking network logs on the firewalls for unexpected uploads, downloads, and IPs.
But firewalls, apparently, are critically vulnerable, too. Hackers can exploit multiple newly discovered critical bugs in Cisco Secure Firewall Management Center (FMC). FMC is the central console that administrators use to manage a fleet of Cisco firewalls – one thing that controls all the boxes.
One of 14 advisories details a 9.9/10 bug that allows an authenticated, remote attacker to execute arbitrary commands as root.
“Multiple vulnerabilities in Cisco Secure FMC Software could allow a remote attacker to gain root access and perform session forgery or session impersonation,” reads yet another of the advisories.
Cisco is not yet aware of any exploitation in the wild of the FMC bugs.
Cisco Nexus Dashboard software, a control center for managing, monitoring, and automating multiple data centers from a single platform, has also been hardened to address critical vulnerabilities.
The full list of Cisco’s security advisories is available here.
ShadowServer Foundation’s honeypots are showing increased targeting of Cisco vulnerabilities – hundreds of IPs were caught scanning for older bugs, activity not seen the day before.
The platform hasn’t yet been updated to include the latest vulnerabilities and only scans for previously known bugs. Over 500 IPs in one day were caught scanning for a Cisco IOS XE Software bug from 2023, while over 300 more IPs probed for a Cisco Adaptive Security Appliance vulnerability from 2020.