Active attacks put Cisco identity and firewall controls at risk

Active attacks put Cisco identity and firewall controls at risk. Cisco says weaknesses affecting core network trust controls are already being exploited.

This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Thursday, September 17th, 2026.

Cisco says weaknesses affecting core network trust controls are already being exploited. Its September hardening releases cover multiple issues across Secure Firewall products, Firewall Management Center, Identity Services Engine and related components. Cisco says two firewall-management issues and one Identity Services Engine authentication-bypass issue are known to be actively exploited. Fixed software is available, and the relevant hardening advisories don’t provide workarounds.

The business risk is broader than a single appliance. If attackers compromise an identity or firewall management system, they may undermine controls used to protect the rest of the network. Internet-facing management interfaces raise the exposure, but internal access paths also need attention.

Leaders should treat this as an emergency change with clear ownership and planning for any service impact. Defenders should identify affected systems, restrict management access, install the fixed releases and investigate whether earlier compromise occurred. Trust-boundary systems deserve faster action because their failure can weaken every system behind them. Patch the affected identity and firewall management systems immediately, then review access and configuration history for signs of misuse.

For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.

Active attacks put Cisco identity and firewall controls at risk
Broadcast by