Cisco is rolling out fixes for dozens of vulnerabilities across its Secure Firewall Management Center (FMC), Identity Services Engine (ISE) and Nexus Dashboard platforms, addressing critical flaws that allow command execution, authentication bypass and remote code execution on core network management systems.
On the FMC side, a command injection vulnerability in the web-based management interface allows an authenticated remote attacker with administrative credentials to run arbitrary commands on the underlying operating system, potentially escalating to root or pivoting into managed Firepower Threat Defense (FTD) devices. According to regional advisories, successful exploitation can also trigger denial-of-service conditions in single-node deployments, underscoring the risk of using FMC as a central controller without strong access controls. Cisco has shipped updated FMC software to remediate these issues and organizations are being urged to move to fixed releases as soon as possible.
Cisco’s identity stack is under particular pressure, with multiple critical ISE flaws disclosed over the past year that attack both authentication workflows and management APIs. One vulnerability, tracked as CVE-2025-20286, is a “use of hard-coded password” issue carrying a CVSS v3 score of 9.9, giving attackers a direct path to privileged access if credentials are exposed. Another, CVE-2025-20282, allows an unauthenticated remote attacker to upload and execute malicious files with root privileges on ISE 3.4 and the ISE Passive Identity Connector, effectively turning the appliance into a beachhead for deeper network compromise. National CERTs have also flagged RADIUS configuration bugs that can be abused to force unexpected system restarts and insecure deserialization and authorization bypass flaws in the ISE management plane, all now covered by Cisco PSIRT advisories and patched images.
The latest disclosure wave is a nine-CVE ISE advisory that dramatically expands the attack surface for identity infrastructure, including multiple bugs already under active exploitation. Cisco’s PSIRT confirms that CVE-2026-76460, a REST API authentication bypass rated at CVSS 10.0, is being used in the wild to sidestep ISE login protections and gain direct access to administrative functions. The same batch includes CVE-2026-76423, another CVSS 10.0 REST API auth bypass, and CVE-2026-76424, an arbitrary file access bug that can be chained into remote code execution, as well as command injection issues in diagnostic tools and API endpoints. Cisco advises customers to upgrade to ISE 3.2 Patch 8 or later, ISE 3.3 Patch 8, and ISE 3.4 Patch 4 depending on their deployment, while ISE 3.5 is reported as not vulnerable in recent guidance.
Nexus Dashboard and its related components have also seen significant hardening as Cisco addresses a mix of legacy and newly reported flaws. Earlier patches closed CVE-2022-20857, a CVSS 9.8 vulnerability that allowed an unauthenticated remote attacker to access a specific API and execute arbitrary commands, along with two high-severity bugs, CVE-2022-20861 and CVE-2022-20858, linked to CSRF and malicious container image upload, respectively; all were fixed in Nexus Dashboard 2.2(1e). More recent advisories cover missing authorization checks in Nexus Dashboard and Nexus Dashboard Fabric Controller REST APIs that let low-privileged remote users view sensitive information or upload and modify files, as well as CVEs in Nexus Dashboard Insights and NDFC such as CVE‑2024‑20432 and CVE‑2026‑20041 that could lead to arbitrary code execution if left unpatched.
Because FMC, ISE and Nexus Dashboard sit at the center of policy, identity and fabric management for many Cisco-heavy environments, compromise of these platforms gives attackers disproportionate control over firewalls, switches and authentication flows. Security agencies warn that the combination of CVSS 9.8–10.0 scores, unauthenticated attack paths and confirmed exploitation of key ISE API flaws make these bugs attractive targets for both criminal and state-linked actors looking to quietly subvert core network controls.
Defenders should immediately inventory where FMC, ISE and Nexus Dashboard are deployed, map software versions against Cisco PSIRT advisories, and prioritize upgrades to fixed releases, especially in internet-exposed or VPN-adjacent management zones. Where patching cannot be done quickly, organizations should restrict access to web-based management interfaces, enforce multi-factor authentication, and monitor logs for unusual API calls or configuration changes that could indicate exploitation of command-injection or authentication-bypass flaws. Several Nexus Dashboard REST API vulnerabilities have no documented workarounds beyond software updates, making timely patching essential to keep orchestration layers from becoming a single point of failure.
