Cisco has recently addressed dozens of critical vulnerabilities in its Secure Firewall Management Center (FMC), Identity Services Engine (ISE), and Nexus Dashboard. These security updates are crucial as they cover a range of severe flaws, including remote code execution (RCE) and SQL injection vulnerabilities. Notably, the ISE updates include patches for 20 CVEs, with 12 categorized as critical. Among these, three vulnerabilities have already been publicly disclosed, raising the stakes for immediate remediation. Identified as CVE-2026-20282, CVE-2026-20283, and CVE-2026-20284, these flaws allow remote attackers to perform SQL injection, data tampering, and arbitrary command execution, though administrative access is required to exploit them.

CVE-2026-20284 is particularly severe, involving insufficient validation of user-supplied input, thereby enabling attackers to view or modify data and initiate denial-of-service conditions. Cisco has also highlighted several other critical vulnerabilities in ISE, including RCE issues, command injection flaws, and an authentication bypass in the REST API. For the FMC, Cisco has patched 18 CVEs, eight of which are critical and could permit remote attackers to execute commands as root, gain root privileges, bypass protections, and carry out various attacks.

Additionally, the company has addressed critical vulnerabilities in its Nexus Dashboard, tackling issues like authentication bypass, code and command injection, cleartext storage, SQL injection, and path traversal. A particular point of concern is a critical authentication bypass in ISE that has been actively exploited as a zero-day vulnerability. Cisco encourages users to review their security advisories for more detailed information on these vulnerabilities and their respective patches.