Serial number: AV26-932
Date: September 17, 2026
As of September 16, 2026, Cisco is affected by vulnerabilities in the following products:
- Cisco Secure Firewall Threat Defense (FTD) Software
- Prior to 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 10.0.2 and 10.1.0
- Cisco Secure Firewall Management Center (FMC) Software
- Prior to 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 10.0.2 and 10.1.0
- Cisco Identity Services Engine (ISE) Software
- Prior to 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4
- Cisco ISE Passive Identity Connector (ISE-PIC) Software
- Prior to 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4
- Cisco Nexus Dashboard
- Prior to 4.3.1.175
- Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
- Prior to 9.16.4.103, 9.18.4.94, 9.20.4.49, 9.22.3.26, 9.23.1.47 and 9.24.1.26
On September 16, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-76460 to their Known Exploited Vulnerabilities (KEV) Database.
The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
- Cisco Identity Services Engine Authentication Bypass Vulnerability
- Cisco Identity Services Engine Hardening Release: September 2026
- Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026
- Cisco Security Advisories
- CISA KEV: CVE-2026-76460