• Request consultation
  • Newsletter
  • Deutsch Deutsch German de
  • English English English en
  • Italiano Italiano Italian it
  • Nederlands Nederlands Dutch nl
Greenbone
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for Your Sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap & Lifecycle
  • Service & Support
    • Professional Services
    • Documents
    • Technical Support
  • Events
    • MSP GLOBAL 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Our History
    • Careers
    • Contact
  • Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
      • Vulnerability Management
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for your sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap and Lifecycle
    • Request IT Security
  • Service & Support
    • Professional Services
    • Documents
    • Technical Support
  • Events
    • MSP GLOBAL 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Our History
    • Careers
    • Contact
    • Newsletter
  • Our Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
      • Vulnerability Management
  • German
  • English
  • Italian
  • Dutch
Joseph Lee

Patch Now! Heightened Risk Across Cisco Products in September 2026

Blog

So far, Cisco has published 97 new CVE IDs affecting its products this month. Although cyber security experts have noted that raw CVE count is not a direct measure of risk, the total makes September Cisco’s largest-ever month for coordinated CVE disclosures. Also, 32 of the CVEs are “umbrella CVEs”—clusters of multiple underlying vulnerabilities grouped by CWE classification. Despite being officially discouraged by the CVE program, the approach is part of Cisco’s new disclosure policy to tackle AI-accelerated vulnerability discovery.

CVE-2026-76461 (CVSS 9.8, EPSS ≥ 80th pctl) affecting Secure Email Gateway and CVE-2026-76460 (CVSS 10, EPSS ≥ 58th pctl) affecting Cisco Identity Services Engine (ISE), have been flagged for active exploitation and added to CISA’s KEV list [1][2]. CVE-2026-20079 (CVSS 10, EPSS ≥ 99th pctl), affecting Cisco Secure Firewall Management Center (FMC) was also added to CISA’s KEV list this month. CVE-2026-20079 was disclosed in early 2026 and covered by the Greenbone Threat Report for March 2026.

Cisco security alert banner: Cisco Hits Record 97 CVEs in September

Detect These Vulnerabilities With OPENVAS

Greenbone’s OPENVAS ENTERPRISE FEED includes regular detection coverage for Cisco vulnerabilities, including those disclosed in September 2026. This includes detection for all new actively exploited flaws [1][2][3][4]. For defenders seeking to detect and protect, a trial copy of OPENVAS SCAN includes a free two-week trial of the OPENVAS ENTERPRISE FEED. Greenbone’s cyber security products are a surefire way to gain the deepest insight into where software vulnerabilities exist across your organization’s infrastructure.

Below is a consolidated view of emerging vulnerabilities affecting Cisco products so far in September 2026.

CVE-2026-76460: Identity Services Engine (ISE) Actively Exploited for Root-Level Command Execution

CVSS 10 · CriticalEPSS 0.9% (58th)Actively exploitedIn CISA KEV

On September 16th, Cisco disclosed 42 new CVE IDs affecting ISE. CVE-2026-76460 (CVSS 10) was immediately marked as actively exploited and added to CISA’s KEV list. CVE-2026-76460 is classified as a critical authentication bypass in an API [CWE-648]. Exploitation allows an unauthenticated remote attacker to bypass authentication, gain unauthorized access to the web-based management interface, and execute commands with root privileges. The flaw can be exploited via HTTP request to an affected API endpoint.

Affected Versions and Mitigation for CVE-2026-76460

Product Affected release Fixed release

Cisco ISE / ISE-PIC

3.1

3.1 Patch 12

Cisco ISE / ISE-PIC

3.2

3.2 Patch 11

Cisco ISE / ISE-PIC

3.3

3.3 Patch 12

Cisco ISE / ISE-PIC

3.4

3.4 Patch 7

Cisco ISE / ISE-PIC

3.5

3.5 Patch 4

Where immediate patching is not possible, Cisco advises limiting traffic to the affected device by restricting management and control-plane traffic. The vendor also provides incident response guidance to identify any potential compromise. The OPENVAS ENTERPRISE FEED includes package-level detection for CVE-2026-76460 and broad vulnerability detection for Cisco flaws, including all new CVEs affecting ISE.

CVE-2026-76461: Cisco Secure Email Gateway Actively Exploited for Root-Level RCE

CVSS 9.8 · CriticalEPSS 2.0% (80th)Actively exploitedIn CISA KEV

CVE-2026-76461 (CVSS 9.8) is an SQL injection vulnerability [CWE-89] in the email parsing logic of Cisco AsyncOS Software for Cisco Secure Email Gateway. The flaw is considered actively exploited and has been added to CISA’s KEV list. According to Cisco, a remote unauthenticated attacker can achieve root-level remote code execution (RCE) by sending a crafted email that contains malicious SQL statements to an affected device.

Affected Versions and Mitigation for CVE-2026-76461

Product Affected release Fixed release

Cisco Secure Email Gateway

15.5 and earlier

15.5.5-014

Cisco Secure Email Gateway

16.0

16.0.4-302

Cisco Secure Email Gateway

16.5

16.5.0-780

The OPENVAS ENTERPRISE FEED includes package-level detection for CVE-2026-76461 in Cisco Secure Email Gateway. Cisco advises users to review logs for suspicious entries, including the SQL command pattern COPY…TO PROGRAM. A breach carries additional risk of lateral movement for clustered deployments since exploitation may expose private SSH keys used between cluster members.

Broader Exposure for Cisco Secure Email Platform

In two separate advisories, Cisco issued seven additional CVE IDs that included five CVE clusters, covering various components of the Secure Email product family [1][2]. Four of the CVE IDs are rated critical severity, indicating they are remotely exploitable without authentication. The OPENVAS ENTERPRISE FEED includes package-level detection for the actively exploited CVE-2026-76461 and all other new vulnerabilities affecting Cisco Secure Email Gateway [1][2].

Critical-Severity CVE Clusters Across Cisco Secure Firewall Products

Cisco also disclosed 29 CVE IDs affecting Secure Firewall Adaptive Security Appliance (ASA), Secure Firewall Threat Defense (FTD), and Secure Firewall Management Center (FMC). Eight of the IDs are rated critical severity, indicating they include unauthenticated, remotely exploitable security issues. None have yet been tagged as actively exploited.

In a blog post, Cisco also provided details for active campaigns targeting CVE-2026-20079 (CVSS 10, EPSS ≥ 99th pctl) and CVE-2026-20316 (CVSS 5.3, EPSS ≥ 96th pctl) affecting FMC. Both are on CISA’s KEV list [4][5]. The latter, CVE-2026-20316, was added in July and is known to be associated with ransomware attacks, while CVE-2026-20079 is a new KEV list addition in September 2026.

The OPENVAS ENTERPRISE FEED includes separate package-level detection tests for all new CVEs affecting ASA [1], FTD [2], and FMC [3] and has included detection for the actively exploited CVE-2026-20079 [4][5] and CVE-2026-20316 [6] since their disclosure.

Critical-Severity CVE Clusters Affecting Cisco IOS XR

Seven CVE clusters were disclosed in Cisco’s September IOS XR Software Security Hardening Release. Two of the seven clusters are rated critical severity, indicating they include unauthenticated, remotely exploitable flaws. None have yet been tagged as actively exploited.

All IOS XR Software releases, including IOS XR7 (LNT), are affected regardless of device configuration. Fixes are available in IOS XR 26.2.2 and 26.3.1. No workarounds are available. Older supported trains, including 7.3, 7.9, 7.10, 7.11, 24.1–24.4, 25.1–25.4, 26.1, and 26.2, must first be upgraded to a maintenance release and then patched with the applicable Software Maintenance Updates (SMUs). See Cisco’s release advisory for more details. The OPENVAS ENTERPRISE FEED includes a remote banner check that covers all CVE clusters from the September IOS XR Software Security Hardening Release.

Critical-Severity CVE Clusters Affecting Cisco Nexus Dashboard

Cisco disclosed six CVE clusters in its Nexus Dashboard Hardening Release. Three of the six clusters are rated critical severity, indicating they include unauthenticated, remotely exploitable security issues. None have yet been tagged as actively exploited. No workarounds can mitigate the flaws, and all configurations of Cisco Nexus Dashboard are affected.

Product Affected release Fixed release

Cisco Nexus Dashboard

4.2 and earlier

Migrate to a fixed release

Cisco Nexus Dashboard

4.3

4.3.1.175

The OPENVAS ENTERPRISE FEED includes a remote banner check for all CVE clusters in the Nexus Dashboard Hardening Release. Users should update to a fixed version as soon as possible.

Summary

September 2026 marks Cisco’s largest coordinated vulnerability disclosure period to date, with 97 new CVE IDs spanning major enterprise security and networking products. Thirty-two are umbrella CVEs, meaning the actual number of underlying software flaws is unknown. So far this month, Cisco ISE, Secure Email Gateway, and FMC flaws have been added to CISA’s KEV list indicating active exploitation. Users should conduct regular vulnerability scans of their IT networks and endpoints to detect emerging security risks and prioritize mitigation.

Detect These Vulnerabilities With OPENVAS

Greenbone’s OPENVAS ENTERPRISE FEED includes regular detection coverage for Cisco vulnerabilities including those disclosed in September 2026. This includes detection for all new actively exploited flaws [1][2][3][4]. For defenders seeking to detect and protect, a trial copy of OPENVAS SCAN includes a free two-week trial of the OPENVAS ENTERPRISE FEED. Greenbone’s cyber security products are a surefire way to gain the deepest insight into where software vulnerabilities exist across your organization’s infrastructure.

 

Contact Test Now Buy Here Back to Overview
Joseph Lee
Joseph Lee

Joseph has had a varied and passionate background in IT and cyber security since the late 1980s. His early technical experience included working on an IBM PS/2, assembling PCs and programming in C++.

He also pursued academic studies in computer and systems engineering, anthropology and an MBA in technology forecasting.

Joseph has worked in data analytics, software development and, in particular, enterprise IT security. He specialises in vulnerability management, encryption and penetration testing.

LinkedIn

22. September 2026/by Joseph Lee
Share this entry
  • Share on LinkedIn
  • Share by Mail
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-09-22 14:34:332026-09-22 14:34:33Patch Now! Heightened Risk Across Cisco Products in September 2026

Search

Search Search

Archive

  • 2026
  • 2025

Newsletter

Subscribe Now

OPENVAS BASIC

Our entry-level enterprise product

Test 14 Days Free of Charge

Products & Solutions

  • OPENVAS PRODUCTS
  • OPENVAS SECURITY INTELLIGENCE
  • OPENVAS SCAN
  • OPENVAS BASIC
  • OPENVAS FREE
  • OPENVAS AI
ISO9001-EN

Service & Support

  • Professional Services
  • Documents
  • Technical Support
  • FAQ
  • Warranty
  • Cyber Resilience Act
ISO27001-EN

About us

  • About Greenbone
  • Partners
  • MSSP
  • License information
  • Privacy Statement
  • Terms & Conditions
ISO14001-EN

Contact with us

  • Contact
  • Newsletter
  • Media Contact
  • Careers
  • Security Response
  • Imprint
  • Grounding Page

Community

  • Community Portal
  • Community Forum
© Copyright - Greenbone AG 2020-2026
  • Link to LinkedIn
Link to: CVE-2026-85706: CVSS 10 GitLab CE/EE API Flaw Actively Exploited Link to: CVE-2026-85706: CVSS 10 GitLab CE/EE API Flaw Actively Exploited CVE-2026-85706: CVSS 10 GitLab CE/EE API Flaw Actively Exploited
Scroll to top Scroll to top Scroll to top
Contact
Request IT Security Contact Us Subscribe to Newsletter Follow on LinkedIn