Threat Intel
Cisco Faces Multi‑Vulnerability Storm – Remote Code, Privilege Escalation & DoS
Cisco’s latest advisory reveals a cascade of flaws across ASA, FMC, FTD and ISE platforms. Several CVEs enable attackers to execute code remotely, elevate privileges, and trigger denial‑of‑service attacks. Notably, CVE‑2026‑76460 is actively exploited. Versions 3.2 and 3.1 of ISE are unsupported and lack patches for multiple critical bugs. Immediate patching and hardening are required to protect network infrastructure.
Overview
On 17 September 2026, the French CERT released a comprehensive alert detailing dozens of newly discovered vulnerabilities in Cisco products. The flaws span a range of impact classes—from remote code execution (RCE) and privilege escalation to distributed denial‑of‑service (DoS).
Affected Products
- Adaptive Security Appliance (ASA)
- Firewall Management Center (FMC)
- Firewall Threat Defense (FTD)
- Identity Services Engine (ISE) – all versions up to 3.5
- ISE‑PIC – only the 3.4 branch remains maintained
Key CVEs & Impact
- CVE‑2026‑76460 – Remote code execution, actively exploited.
- CVE‑2026‑20247, 20282, 20300, 76424‑76428 – RCE, privilege escalation, DoS on ISE 3.1 & 3.2.
- Multiple CVEs in ASA/FTD/FMC causing DoS and potential RCE via malformed TLS, DTLS, and logging packets.
- SQL injection in ISE and command‑injection vulnerabilities affecting authentication flows.
Mitigation Steps
- Check the Cisco Security Advisories portal for the latest patches for each affected component.
- Apply firmware updates to all ASA, FMC, and FTD devices immediately.
- Upgrade ISE to the latest supported release (≥3.5 Patch 4). If using 3.2 or 3.1, migrate to a newer version or replace the system—no patches will be released.
- Disable or restrict unused protocols (DTLS, IKEv2, EIGRP) that are leveraged by the exploits.
- Implement network segmentation and strict access controls around Cisco management interfaces.
- Enable logging and monitor for anomalous traffic patterns that could indicate exploitation attempts.
"CVE‑2026‑76460 is actively exploited in the wild. If your environment runs any of the affected Cisco products, patching is non‑negotiable." – French CERT advisory.
What You Should Do Now
1. Run a quick inventory scan to identify any Cisco ASA, FMC, FTD or ISE devices in your network.
2. Cross‑reference the device firmware with the list of affected versions.
3. Schedule patching windows—prioritize RCE‑capable CVEs first.
4. If you are still on ISE 3.1 or 3.2, plan an immediate migration strategy; these branches will not receive security updates beyond November 2027.