Full Report
Cisco security advisory (AV26-932)
Analysis Summary
# Vulnerability: Cisco Multi-Product Authentication Bypass and Hardening Updates
## CVE Details
- **CVE ID:** CVE-2026-76460 (Primary)
- **CVSS Score:** 9.8 (Estimated/Critical)
- **CWE:** CWE-287 (Improper Authentication)
## Affected Systems
- **Products:**
- Cisco Secure Firewall Threat Defense (FTD)
- Cisco Secure Firewall Management Center (FMC)
- Cisco Identity Services Engine (ISE)
- Cisco ISE Passive Identity Connector (ISE-PIC)
- Cisco Nexus Dashboard
- Cisco Secure Firewall Adaptive Security Appliance (ASA)
- **Versions:**
- **FTD/FMC:** Prior to 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13, 10.0.2, 10.1.0
- **ISE/ISE-PIC:** Prior to 3.1 P12, 3.2 P11, 3.3 P12, 3.4 P7, 3.5 P4
- **Nexus Dashboard:** Prior to 4.3.1.175
- **ASA:** Prior to 9.16.4.103, 9.18.4.94, 9.20.4.49, 9.22.3.26, 9.23.1.47, 9.24.1.26
- **Configurations:** Systems utilizing default authentication configurations or specific vulnerable identity services.
## Vulnerability Description
The primary vulnerability (CVE-2026-76460) involves an authentication bypass mechanism within Cisco Identity Services Engine (ISE). This flaw allows a remote, unauthenticated attacker to bypass authentication and gain unauthorized access to the affected system's management interface or sensitive resources. The September 2026 release also includes significant "Hardening" updates for ASA, FTD, and FMC to address systemic security weaknesses.
## Exploitation
- **Status:** **Exploited in the wild**. CISA added CVE-2026-76460 to the Known Exploited Vulnerabilities (KEV) Catalog on September 16, 2026.
- **Complexity:** Low
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** High (Full access to system data and credentials)
- **Integrity:** High (Unauthorized modifications to security policies)
- **Availability:** High (Potential for complete system takeover or denial of service)
## Remediation
### Patches
Cisco has released software updates to address these flaws. Administrators are urged to upgrade to the following versions or later:
- **ISE:** 3.1 P12, 3.2 P11, 3.3 P12, 3.4 P7, 3.5 P4
- **ASA:** 9.16.4.103 / 9.18.4.94 / 9.20.4.49 / 9.22.3.26 / 9.23.1.47 / 9.24.1.26
- **FTD/FMC:** 7.0.10, 7.2.12, 7.4.8, 7.6.6, 7.7.13
- **Nexus Dashboard:** 4.3.1.175
### Workarounds
- No specific workarounds were provided to fully mitigate the bypass; patching is the only recommended course of action.
- Implement strict Access Control Lists (ACLs) to limit management access to trusted IP addresses only.
## Detection
- **Indicators of Compromise:** Monitor logs for unusual administrative logins from unexpected source IPs or unauthorized configuration changes.
- **Detection methods and tools:** Use CISA’s KEV catalog to track active exploitation and verify system integrity using Cisco Software Integrity Checks.
## References
- [Cisco ISE Authentication Bypass Advisory] hxxps[://]sec[.]cloudapps[.]cisco[.]com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5
- [Cisco ISE Hardening Release] hxxps[://]sec[.]cloudapps[.]cisco[.]com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ise-XU5EwX5T
- [Cisco ASA/FTD/FMC Hardening Release] hxxps[://]sec[.]cloudapps[.]cisco[.]com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-asaftdfmc-uvpPROhN
- [CISA KEV Catalog] hxxps[://]www[.]cisa[.]gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76460