Connect with us

Cybersecurity

Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard

Published

on

Cisco has released security updates addressing dozens of vulnerabilities across its Secure Firewall Management Center (FMC), Identity Services Engine (ISE), and Nexus Dashboard platforms.

The flaws include critical security weaknesses that could allow attackers to execute arbitrary commands, gain root privileges, bypass authentication controls, perform SQL injection, access or modify sensitive information, and potentially execute code remotely.

Cisco ISE Receives 20 Security Fixes

Cisco’s Identity Services Engine (ISE) received patches for 20 vulnerabilities, including 12 rated critical. The company also warned that three of the vulnerabilities have already been publicly disclosed.

The publicly disclosed issues are tracked as CVE-2026-20282, CVE-2026-20283, and CVE-2026-20284.

The first two vulnerabilities are classified as medium severity but are considered high risk by Cisco because successful exploitation could provide attackers with elevated privileges that may ultimately lead to root-level access.

All three vulnerabilities require administrative access to exploit.

CVE-2026-20284, rated critical, involves insufficient validation of user-supplied input. An attacker could potentially exploit the flaw to view or modify data and trigger a denial-of-service (DoS) condition.

Cisco’s Product Security Incident Response Team (PSIRT) said it is aware that public information about the three vulnerabilities is available.

Critical ISE Vulnerabilities Could Enable Remote Code Execution

Cisco also addressed six additional critical vulnerabilities affecting ISE.

The issues include:

  • Three vulnerabilities capable of enabling remote code execution (RCE)
  • Two command-injection flaws that could result in command execution with root privileges
  • An authentication-bypass vulnerability affecting the REST API

The company also fixed several other critical security weaknesses involving injection attacks, cross-site scripting (XSS), authentication or security bypasses, information disclosure and path traversal.

These additional vulnerabilities are grouped under five CVE identifiers.

Cisco FMC Updates Fix 18 Vulnerabilities

Cisco’s Secure Firewall Management Center updates address 18 CVEs, including eight critical-severity vulnerabilities.

Depending on the specific weakness, successful exploitation could allow remote attackers to execute arbitrary commands with root privileges, obtain elevated access, bypass security protections or authentication mechanisms, and conduct other malicious activities.

The concentration of critical flaws in FMC is particularly significant because the platform is used to centrally manage Cisco security infrastructure. A successful compromise could therefore provide an attacker with powerful access to security management functions.

Nexus Dashboard Also Receives Security Updates

Cisco’s security release also includes fixes for vulnerabilities affecting Nexus Dashboard, the company’s platform for managing data-center networking infrastructure.

The vulnerabilities across the affected Cisco products demonstrate a broad range of attack techniques, including command injection, SQL injection, authentication bypass, path traversal, cross-site scripting, information disclosure and remote code execution.

Some of these weaknesses require authenticated or administrative access, while others may present more significant risks depending on how the affected systems are deployed and exposed.

Administrators Urged to Apply Cisco Security Updates

The presence of publicly disclosed vulnerabilities among the ISE issues increases the importance of reviewing Cisco’s security advisories and applying the appropriate software updates.

Organizations running Cisco FMC, ISE or Nexus Dashboard should identify affected versions in their environments, review Cisco’s remediation guidance and prioritize patching based on exposure and potential impact.

The vulnerabilities highlight the importance of maintaining security management platforms as carefully as the network infrastructure they control, since weaknesses in centralized management systems can provide attackers with access to highly privileged

Advertisement
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Copyright © 2026 Cyber Reports Cyber Security News All Rights Reserved Website by Top Search SEO