Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
World desk5 min

Cisco September 2026 Firewall Updates: What to Patch First

Cisco says two September hardening-release vulnerabilities are actively exploited. Learn how to assess ASA, FTD, and FMC exposure and choose the correct fixed release.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Prioritize Cisco’s September 2026 firewall updates by confirmed exploitation, then by whether your product, software release, configuration, and network exposure match the vulnerability. Cisco says two vulnerabilities in its September hardening release are actively exploited; that statement does not apply to every CVE in the September cycle or mean that every Cisco firewall is equally exposed.

Which Cisco firewall CVEs are being actively exploited?

Cisco’s September 16, 2026 hardening advisory, updated September 18, says two vulnerabilities in that release are actively exploited and points to advisories concerning FMC static credentials and authentication bypass. Those findings deserve immediate attention from operators of affected Firewall Management Center (FMC) systems. Cisco does not say that all 18 CVEs implied by the September-cycle count are being exploited.

As an Amazon Associate I earn from qualifying purchases.

The hardening advisory groups findings by common weakness enumeration (CWE) class, assigning one CVE to each of eight groups. Its CVSS figures are the maximum potential severity of the most impactful underlying vulnerability in each group—not a score for every flaw in the group, a measure of exposure on a particular device, or proof that the group represents one independent flaw. Cisco says it is not aware of public announcements or malicious use for the other hardening findings unless an advisory says otherwise.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
CVE in Cisco’s hardening advisory Maximum CVSS score for its CWE group
CVE-2026-20329 9.9
CVE-2026-20330 9.9
CVE-2026-20331 9.6
CVE-2026-20332 9.0
CVE-2026-20333 8.8
CVE-2026-20334 8.4
CVE-2026-20335 8.1
CVE-2026-20336 7.5

These are Cisco’s 2026 maximum group scores. Treat them as a severity signal to investigate, not a standalone patch order. The September materials also describe separate issues; they do not provide a complete, verified per-CVE mapping and analysis of all 18 CVEs implied by the cycle count.

#1 Best Overall
Cisco FPR1010-NGFW-K9 FirePower 1010 Next-Generation Firewall w/ AC Adapter [Unclaimed & No License] (Renewed)
  • Firewall Protection Supported: Malware Protection
  • Firewall Protection Supported: Threat Protection
  • Firewall Protection Supported: URL Filtering
  • Firewall Protection Supported: Intrusion Prevention
  • Total Number of Ports: 8

How should you rank the remaining September findings?

After addressing confirmed active exploitation, establish whether each issue applies to your product and release, then check the conditions an attacker would need to exploit it. Consider potential impact and the availability of a suitable fixed release before scheduling deployment.

  1. Check for known exploitation. Give the two actively exploited hardening-release vulnerabilities priority on affected FMC deployments. Do not transfer that status to other September issues without Cisco saying so.
  2. Identify the product and software train. The hardening advisory covers ASA, FTD, and FMC software regardless of configuration. Other advisories can have narrower scope: the cited multi-vulnerability advisory applies to FMC, not ASA or FTD, while the EIGRP denial-of-service issue requires EIGRP to be enabled.
  3. Confirm reachability and prerequisites. Determine whether the vulnerable service or protocol is enabled and whether an attacker can reach or influence the relevant traffic. For example, Cisco says the TCP DNS issue requires an attacker able to respond to device DNS queries, such as by controlling DNS or occupying a machine-in-the-middle position.
  4. Weigh impact as well as severity. The cited EIGRP and TCP DNS issues can cause a device reload and service interruption. The FMC issues include root access, administrator impersonation, or session effects; the precise impact and prerequisites depend on the individual vulnerability.
  5. Plan against the exact fixed-release guidance. Use Cisco’s release-specific checker and advisory tables for the product and running version. Check compatibility, memory, and support status before upgrading, and verify the full advisory table for affected hot-fix releases.

What other September issues have distinct exposure conditions?

EIGRP denial of service: CVE-2026-20222

Cisco assigns CVE-2026-20222 a 2026 CVSS score of 7.4. Exposure requires EIGRP to be enabled. Cisco says ASA releases 9.18 and earlier and FTD releases 7.4 and earlier are not vulnerable; for later affected trains, use the advisory’s fixed-release table. Cisco reported no known public announcements or malicious use and said the issue was found while resolving a Cisco TAC support case. It recommends upgrading to a first fixed release, noting that those releases include fixes for multiple vulnerabilities.

Rank #2
Cisco ASA5525-X ASA5525-K9 Security Appliance Firewall (Renewed)
  • Cisco asa 5525-x firewall edition - 8 port - gigabit Ethernet
  • Cisco asa 5525-x firewall edition
  • 8 port - gigabit Ethernet

Cisco identifies EIGRP authentication as a risk-reduction best practice, but advises customers to assess environment-specific impacts. That is not a replacement for fixed software.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

TCP DNS denial of service: CVE-2026-20248

Cisco assigns CVE-2026-20248 a 2026 CVSS score of 6.8. The attacker must be able to respond to DNS queries made by the device—for example, by controlling the DNS service or intercepting traffic from a machine-in-the-middle position. The issue can cause a reload and service interruption. Cisco’s advisory provides first fixed releases for ASA and FTD trains; confirm the entry for the actual device in the full table. Cisco says there is no workaround addressing this vulnerability.

Rank #3
Cisco Meraki MX68-HW Wired Network Security/Firewall - Appliance Only
  • 10 × GbE (2 WAN, 2 PoE+), 1 × USB 2.0 for 3G/4G failover
  • Stateful firewall throughput: 450 Mbps, VPN throughput: 200 Mbps
  • Recommended maximum clients: 50, Layer 7 application visibility and traffic shaping
  • Automatic firmware upgrades and security patches, VLAN support and DHCP services
  • Includes 100W DC Power Supply, requires Enterprise or Advanced Security License

FMC-only multi-vulnerability advisory

The cited FMC advisory says its vulnerabilities affect FMC regardless of configuration and do not affect ASA or FTD. It lists CVE-2026-76420 at CVSS 9.0 and CVE-2026-76412 and CVE-2026-76413 at CVSS 8.5 each. Cisco describes the vulnerabilities as independent: exploiting one is not a prerequisite for exploiting another, and a release affected by one may not be affected by the others. The advisory reports no known public announcements or malicious use.

One described FMC peer-impersonation issue can be exploited only when the valid sftunnel connection between FMC and FTD is down. Check the advisory for each vulnerability’s specific conditions rather than assuming that every FMC issue shares this prerequisite.

Rank #4
Sale
Cisco FPR1120-NGFW-K9 Firepower 1120 NGFW Firewall Appliance (Renewed)
  • REMOTE-WORKER READY: Pre-integrated support for additional Cisco Security capabilities, including Cisco AnyConnect remote access VPN and Cisco Duo multi-factor authentication.
  • COMPACT: 1RU design for small and mid-sized offices
  • PERFORMANCE WITHOUT SACRIFICE: Firepower 1000 Series firewalls include hardware-based acceleration, maintaining firewall performance in all conditions
  • CONFIGURABLE: With available Firepower Threat Defense (FTD) base software, add network-based content inspection, Intrusion Prevention System (IPS), and URL filtering
  • PEACE OF MIND: 90-day limited warranty

How do I check whether my Cisco ASA or FTD version is affected?

  1. Record the exact product—ASA, FTD, or FMC—and its running software release. For an FMC-managed deployment, check both the management center and the managed firewall where the advisory applies.
  2. Run the release through Cisco Software Checker. Cisco says the tool maps a running release to applicable advisories and first fixed releases, and can report a combined first fixed release.
  3. Open each relevant September advisory and confirm its product scope, release train, exposure conditions, and any hot-fix notes. Do not infer vulnerability from a CVE score alone.
  4. For configuration-dependent findings, verify the relevant setting or service. In particular, confirm whether EIGRP is enabled and assess whether an attacker could respond to device DNS queries for the TCP DNS issue.
  5. Compare the installed version with the advisory’s current fixed-release table. Confirm that the proposed target is supported by the hardware and compatible with the deployment before scheduling the change.

What is the first fixed release for my Cisco Secure Firewall software?

The following are first fixed releases listed in Cisco’s September 2026 hardening advisory, updated September 18. Match the software train, not just the product family. These entries are a starting point: Cisco flags certain affected hot-fix releases in the full table, so check the latest advisory before upgrading.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Product line Software train First fixed release
ASA 9.16 and earlier 9.16.4.103
ASA 9.18 9.18.4.94
ASA 9.20 9.20.4.49
ASA 9.22 9.22.3.26
ASA 9.23 9.23.1.47
ASA 9.24 9.24.1.26
FTD and FMC 7.0 and earlier 7.0.10
FTD and FMC 7.2 7.2.12
FTD and FMC 7.4 7.4.8
FTD and FMC 7.6 7.6.6
FTD and FMC 7.7 7.7.13
FTD and FMC 10.0 10.0.2
FTD and FMC 10.1 10.1.0
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Can I use a workaround instead of upgrading?

Cisco says there are no workarounds addressing the cited hardening, EIGRP, and TCP DNS vulnerabilities. EIGRP authentication may reduce risk for the EIGRP issue, but Cisco presents it as a best practice to assess for the local environment, not as a fix. A workaround or a lack of known exploitation does not establish that an affected device is safe to leave unpatched.

Best Value
Cisco Meraki Firewall Appliance Rack Mount - 1U Server Rack Shelf with Easy Access Front Network Connections, Properly Vented, Customized 19 Inch Rack - RM-CI-T14 by Rackmount.IT
  • More Secured Server Mounting Setup: RM-CI-T14 by Rackmount.IT IU rack mount kits have dedicated slots to safely install compatible Cisco Meraki models, including Cisco Meraki MX68, MX68W, MX68CW, and MX75.
  • Improves Cable Management: All console ports of the Cisco Meraki appliance are brought to the front for easy access and user convenience — all while preventing overheating with custom-made cut-outs.
  • Straightforward Installation Process: Mounting your appliance to a 19 inch shelf only takes 2-5 mins. as our network tray kits have everything a user needs — bolts, hex keys, zip ties, port labels, cables, and an assembly guide.
  • Suitable for Any Type of Business: Our 1U rack shelf kits are designed to fit your appliance in 19-inch network rack shelves, making them ideal for small business owners, large corporations, and government agencies looking to improve their cloud management and network connectivity.
  • Passionate for Smart Design and Customization: Rackmount.IT offers innovative solutions to common user needs by producing high-quality custom rack mounted shelf with excellent features that support major desktop appliance manufacturers.

For upgrade entitlement or support questions, Cisco directs customers to Cisco TAC or their maintenance providers. Confirm support and compatibility for the actual hardware and software configuration before deployment.

Quick Recap

Bestseller No. 1
Cisco FPR1010-NGFW-K9 FirePower 1010 Next-Generation Firewall w/ AC Adapter [Unclaimed & No License] (Renewed)
Cisco FPR1010-NGFW-K9 FirePower 1010 Next-Generation Firewall w/ AC Adapter [Unclaimed & No License] (Renewed)
Firewall Protection Supported: Malware Protection; Firewall Protection Supported: Threat Protection
$635.00
Bestseller No. 2
Cisco ASA5525-X ASA5525-K9 Security Appliance Firewall (Renewed)
Cisco ASA5525-X ASA5525-K9 Security Appliance Firewall (Renewed)
Cisco asa 5525-x firewall edition - 8 port - gigabit Ethernet; Cisco asa 5525-x firewall edition
$110.88
Bestseller No. 3
Cisco Meraki MX68-HW Wired Network Security/Firewall - Appliance Only
Cisco Meraki MX68-HW Wired Network Security/Firewall - Appliance Only
10 × GbE (2 WAN, 2 PoE+), 1 × USB 2.0 for 3G/4G failover; Stateful firewall throughput: 450 Mbps, VPN throughput: 200 Mbps
$620.00
SaleBestseller No. 4
Cisco FPR1120-NGFW-K9 Firepower 1120 NGFW Firewall Appliance (Renewed)
Cisco FPR1120-NGFW-K9 Firepower 1120 NGFW Firewall Appliance (Renewed)
COMPACT: 1RU design for small and mid-sized offices; PEACE OF MIND: 90-day limited warranty
$1,099.90

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.