Cisco Advance Notification for Publication of September 16, 2026, Security Advisories

Low Riskcisco-sa-notice-jfxK98ZPSep 9, 2026
Cisco
IT in OT - Cisco networking products are commonly deployed in OT environments
Summary

Cisco will publish security advisories on September 16, 2026, disclosing vulnerabilities in Secure Firewall ASA, FMC, FTD, Identity Services Engine (ISE), Nexus Dashboard, BroadWorks, and ThousandEyes Enterprise Agent. Cisco states that fixed software releases will be available for all affected products. The Cisco Talos blog indicates ongoing exploitation of FMC vulnerabilities in the wild. Customers are advised to upgrade to patched versions when available.

What this means
What could happen
Cisco will disclose multiple security vulnerabilities affecting firewall, authentication, and network monitoring products on September 16, 2026. Until patches are available, organizations using these products face unknown but potentially significant risks.
Who's at risk
This advance notification affects organizations operating Cisco Secure Firewall products (ASA, FMC, FTD) used for network perimeter security, Identity Services Engine (ISE) used for network access control and authentication, Nexus Dashboard used for infrastructure management, BroadWorks for VoIP/communications, and ThousandEyes for network monitoring. Water utilities and municipal electric providers using Cisco security infrastructure should treat this as high priority.
How it could be exploited
Attack vectors are unknown pending the September 16 disclosure. However, vulnerabilities in Secure Firewall ASA, FMC, and FTD could allow attackers to bypass security controls or compromise network perimeter defenses. ISE vulnerabilities could compromise authentication infrastructure. ThousandEyes and Nexus Dashboard vulnerabilities could provide visibility into network topology or management access.
Prerequisites
  • Specific prerequisites unknown until advisories published on September 16, 2026
  • Expected to range from unauthenticated network access to authenticated management console access
Impacts critical security infrastructure (firewall, authentication, management)Vulnerabilities affecting multiple Cisco product lines simultaneouslyExploits may be developed and released after public disclosureUnknown severity and complexity until September 16 advisory publicationOrganizations have limited time to plan and execute patching
Affected products (7)
7 pending
ProductAffected VersionsFix Status
Secure Firewall Adaptive Security Appliance (ASA) SoftwareAll versionsNo fix yet
Identity Services Engine SoftwareAll versionsNo fix yet
Secure Firewall Management Center (FMC)All versionsNo fix yet
Secure Firewall Threat Defense (FTD) SoftwareAll versionsNo fix yet
Nexus DashboardAll versionsNo fix yet
BroadWorksAll versionsNo fix yet
ThousandEyes Enterprise AgentAll versionsNo fix yet
Remediation & Mitigation
0/4
Do now
0/3
HARDENINGMonitor Cisco PSIRT advisories published September 16, 2026 for specific vulnerability details and determine which products in your environment are affected
HARDENINGReview Cisco Talos blog and PSIRT advisories to understand attack vectors and prioritize patching of highest-risk products first (likely Secure Firewall products based on history)
WORKAROUNDUntil patches are available, apply network access restrictions (firewall rules, VLANs) to limit management access to Cisco security appliances to authorized personnel and networks only
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Secure Firewall Adaptive Security Appliance (ASA) Software
HOTFIXPlan maintenance windows for September/October 2026 to deploy patches for Secure Firewall ASA, FMC, FTD, ISE, Nexus Dashboard, BroadWorks, and ThousandEyes as they become available
API: /api/v1/advisories/bba22190-7bc3-426a-860b-ae79c1f6aee7

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.