# Cisco's September 2026 Patchocalypse: 97 CVEs, Active Exploits, and Zero-Days You Can't Ignore

In what cybersecurity experts are calling a landmark month for enterprise security, Cisco has unleashed its largest-ever coordinated vulnerability disclosure, publishing 97 new CVE IDs affecting its product lineup in September 2026. With three critical vulnerabilities already confirmed as actively exploited and added to CISA's Known Exploited Vulnerabilities (KEV) list, defenders need to act now to protect their infrastructure from a wave of sophisticated attacks targeting Secure Email Gateway, Identity Services Engine, and Firewall Management Center deployments.

## The Record-Breaking Disclosure: What You Need to Know

Cisco's September 2026 security disclosure represents a paradigm shift in how the networking giant handles vulnerability reporting. While raw CVE counts historically haven't been considered a direct measure of risk, the sheer volume—combined with the severity ratings and active exploitation—makes this month's advisory dump impossible to ignore. Among the 97 CVEs, 32 are classified as "umbrella CVEs," which are clusters of multiple underlying vulnerabilities grouped by Common Weakness Enumeration (CWE) classification. This approach, while officially discouraged by the CVE program, reflects Cisco's new disclosure strategy to address AI-accelerated vulnerability discovery. The implications are staggering: the actual number of software flaws lurking beneath these umbrella CVEs remains unknown, creating a compliance and patching nightmare for security teams worldwide.

## Critical Zero-Days Exploited in the Wild

### CVE-2026-76460: Identity Services Engine Root-Level Takeover

On September 16th, Cisco disclosed 42 new CVE IDs affecting Identity Services Engine (ISE), but one flaw stands out as an immediate emergency. CVE-2026-76460 carries a perfect CVSS 10.0 critical rating with an EPSS score in the 58th percentile, indicating it's actively being targeted in the wild. This authentication bypass vulnerability (CWE-648) in an API endpoint allows unauthenticated remote attackers to bypass security controls, gain unauthorized access to the web-based management interface, and execute commands with root privileges. The exploitation vector is deceptively simple: a single HTTP request to an affected API endpoint is all it takes to compromise an entire identity infrastructure. Given that ISE is the cornerstone of network access control for most enterprise environments, this vulnerability represents a catastrophic risk. CISA has already added this flaw to its KEV list, and Cisco has released incident response guidance to help organizations identify potential compromises.

**Mitigation Strategy:** Where immediate patching isn't feasible, restrict management and control-plane traffic to trusted networks. The OPENVAS ENTERPRISE FEED provides package-level detection for CVE-2026-76460, allowing defenders to identify vulnerable systems before attackers do.

### CVE-2026-76461: Secure Email Gateway Compromised via Malicious SQL

The second actively exploited vulnerability, CVE-2026-76461, targets Cisco AsyncOS Software for Secure Email Gateway with a critical CVSS 9.8 rating and an EPSS score in the 80th percentile. This SQL injection flaw (CWE-89) in the email parsing logic enables remote unauthenticated attackers to achieve root-level remote code execution simply by sending a crafted email containing malicious SQL statements. What makes this particularly dangerous is the lateral movement potential: in clustered deployments, exploitation can expose private SSH keys shared between cluster members, potentially giving attackers a beachhead into the entire email infrastructure. Cisco advises reviewing logs for suspicious entries, including the SQL command pattern COPY…TO PROGRAM, which indicates attempted exploitation.

### CVE-2026-20079: Firewall Management Center Under Siege

The third KEV addition, CVE-2026-20079, affects Cisco Secure Firewall Management Center (FMC) with a perfect CVSS 10.0 rating and a 99th percentile EPSS score. This vulnerability was initially disclosed in early 2026 and has been on security researchers' radar for months. What's new is its September 2026 addition to CISA's KEV list, confirming active exploitation campaigns. Cisco has also provided details about campaigns targeting CVE-2026-20316 (CVSS 5.3, EPSS ≥ 96th percentile), another FMC flaw associated with ransomware attacks that was added to the KEV list in July. The combination of these two actively exploited FMC vulnerabilities presents a severe risk to organizations relying on Cisco's next-generation firewall management platform.

## Broader Exposure: The Full September 2026 Vulnerability Landscape

Beyond the headline zero-days, Cisco's September disclosure reveals systemic vulnerabilities across multiple product families. The Secure Email product family alone received seven additional CVE IDs, including five CVE clusters, with four rated critical severity indicating unauthenticated remote exploitability. The Secure Firewall product line—covering Adaptive Security Appliance (ASA), Threat Defense (FTD), and Management Center (FMC)—received 29 CVE IDs, eight of which are critical severity. While none have been tagged as actively exploited yet, the EPSS scores suggest attackers are circling.

### Cisco IOS XR: No Workarounds Available

The September IOS XR Software Security Hardening Release disclosed seven CVE clusters, two rated critical severity. All IOS XR Software releases, including IOS XR7 (LNT), are affected regardless of device configuration. Fixes are available in IOS XR 26.2.2 and 26.3.1, but older supported trains face a complex upgrade path: administrators must first upgrade to a maintenance release before applying the applicable Software Maintenance Updates (SMUs). With no workarounds available, organizations running affected versions are exposed until they complete the patching process.

### Cisco Nexus Dashboard: Critical Cluster Risks

Six CVE clusters were disclosed in the Nexus Dashboard Hardening Release, with three rated critical severity. All configurations are affected, and no workarounds exist to mitigate the flaws. The only course of action is updating to fixed versions as soon as possible, making this another urgent priority for network operations teams managing data center fabrics.

## Conclusion: Your Action Plan for September 2026

September 2026 marks Cisco's largest coordinated vulnerability disclosure period to date, with 97 new CVE IDs spanning major enterprise security and networking products. Thirty-two of these are umbrella CVEs, meaning the actual number of underlying software flaws is unknown, and three vulnerabilities are confirmed as actively exploited and added to CISA's KEV list. For security teams, the message is clear: conduct regular vulnerability scans of your IT networks and endpoints to detect emerging risks, prioritize remediation based on EPSS scores and KEV status, and implement comprehensive detection coverage. Greenbone's OPENVAS ENTERPRISE FEED includes regular detection coverage for all Cisco vulnerabilities disclosed in September 2026, including package-level detection for every actively exploited flaw. For defenders seeking to detect and protect their infrastructure, a trial copy of OPENVAS SCAN includes a free two-week trial of the OPENVAS ENTERPRISE FEED, providing the deepest insight into where software vulnerabilities exist across your organization's infrastructure. The threat landscape is evolving faster than ever—ensure your vulnerability management strategy can keep pace.