Cisco has disclosed and patched a batch of critical security vulnerabilities across its Secure Firewall Management Center (FMC) and Identity Services Engine (ISE), with five flaws scoring the maximum CVSS rating of 10 out of 10. The company confirms that attackers are already actively exploiting several of these vulnerabilities.
The most severe flaw (CVE-2026-20079) in Secure Firewall Management Center allows unauthenticated remote attackers to send crafted HTTP requests and gain root privileges on affected devices. Once exploited, attackers can modify security policies or completely disable security functions. This vulnerability has been known since March 2026, but patches have not yet been widely deployed.
Four critical flaws in Identity Services Engine (CVE-2026-20130, CVE-2026-20192, CVE-2026-76460, CVE-2026-76423) enable authentication bypass, remote code execution, and command injection attacks. Cisco notes that ISE versions up to 3.0 are end-of-life and cannot be patched — administrators must upgrade.
Patched versions for FMC include 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 10.0.2, and 10.1.0. For ISE, the patched versions are 3.1 Patch 12 through 3.5 Patch 4.
Given the severity and active exploitation, organizations running Cisco firewall and network access infrastructure should prioritize immediate patching.




