Cisco hardening releases address actively exploited security gaps
This is a DailyCyber.News update, brought to you by BareMetalCyber.com, for Friday, September 18th, 2026.
Network access and firewall management systems need urgent review following major Cisco hardening releases. Updates for Secure Firewall products address multiple internally discovered security issues, including two that Cisco says are known to be actively exploited. A separate Identity Services Engine hardening release addresses another issue known to be under active exploitation. Cisco has supplied fixed software and says there are no workarounds for the issues covered by these hardening releases.
Security management and identity systems hold a privileged position in enterprise networks. If one of these platforms is compromised, the controls protecting the rest of the environment may be weakened or bypassed. Leaders should give security appliances and identity platforms the same disciplined patch governance applied to critical servers. Defenders should inventory affected deployments, confirm that fixed software is installed, and determine whether any management interfaces are externally reachable. The larger lesson is that defensive infrastructure attracts attackers precisely because it is trusted and powerful. Prioritize the fixed releases, validate every affected appliance, and investigate prior exposure before declaring the work complete.
For the sources and the full Daily Cyber newsletter, visit DailyCyber.News.