Prioritize Cisco’s September 2026 firewall updates by confirmed exploitation, then by whether your product, software release, configuration, and network exposure match the vulnerability. Cisco says two vulnerabilities in its September hardening release are actively exploited; that statement does not apply to every CVE in the September cycle or mean that every Cisco firewall is equally exposed.
Which Cisco firewall CVEs are being actively exploited?
Cisco’s September 16, 2026 hardening advisory, updated September 18, says two vulnerabilities in that release are actively exploited and points to advisories concerning FMC static credentials and authentication bypass. Those findings deserve immediate attention from operators of affected Firewall Management Center (FMC) systems. Cisco does not say that all 18 CVEs implied by the September-cycle count are being exploited.
As an Amazon Associate I earn from qualifying purchases.
The hardening advisory groups findings by common weakness enumeration (CWE) class, assigning one CVE to each of eight groups. Its CVSS figures are the maximum potential severity of the most impactful underlying vulnerability in each group—not a score for every flaw in the group, a measure of exposure on a particular device, or proof that the group represents one independent flaw. Cisco says it is not aware of public announcements or malicious use for the other hardening findings unless an advisory says otherwise.
Free tools Windows power users keep installed
One-click scans. No signup required.
| CVE in Cisco’s hardening advisory | Maximum CVSS score for its CWE group |
|---|---|
| CVE-2026-20329 | 9.9 |
| CVE-2026-20330 | 9.9 |
| CVE-2026-20331 | 9.6 |
| CVE-2026-20332 | 9.0 |
| CVE-2026-20333 | 8.8 |
| CVE-2026-20334 | 8.4 |
| CVE-2026-20335 | 8.1 |
| CVE-2026-20336 | 7.5 |
These are Cisco’s 2026 maximum group scores. Treat them as a severity signal to investigate, not a standalone patch order. The September materials also describe separate issues; they do not provide a complete, verified per-CVE mapping and analysis of all 18 CVEs implied by the cycle count.
#1 Best Overall
- Firewall Protection Supported: Malware Protection
- Firewall Protection Supported: Threat Protection
- Firewall Protection Supported: URL Filtering
- Firewall Protection Supported: Intrusion Prevention
- Total Number of Ports: 8
How should you rank the remaining September findings?
After addressing confirmed active exploitation, establish whether each issue applies to your product and release, then check the conditions an attacker would need to exploit it. Consider potential impact and the availability of a suitable fixed release before scheduling deployment.
- Check for known exploitation. Give the two actively exploited hardening-release vulnerabilities priority on affected FMC deployments. Do not transfer that status to other September issues without Cisco saying so.
- Identify the product and software train. The hardening advisory covers ASA, FTD, and FMC software regardless of configuration. Other advisories can have narrower scope: the cited multi-vulnerability advisory applies to FMC, not ASA or FTD, while the EIGRP denial-of-service issue requires EIGRP to be enabled.
- Confirm reachability and prerequisites. Determine whether the vulnerable service or protocol is enabled and whether an attacker can reach or influence the relevant traffic. For example, Cisco says the TCP DNS issue requires an attacker able to respond to device DNS queries, such as by controlling DNS or occupying a machine-in-the-middle position.
- Weigh impact as well as severity. The cited EIGRP and TCP DNS issues can cause a device reload and service interruption. The FMC issues include root access, administrator impersonation, or session effects; the precise impact and prerequisites depend on the individual vulnerability.
- Plan against the exact fixed-release guidance. Use Cisco’s release-specific checker and advisory tables for the product and running version. Check compatibility, memory, and support status before upgrading, and verify the full advisory table for affected hot-fix releases.
What other September issues have distinct exposure conditions?
EIGRP denial of service: CVE-2026-20222
Cisco assigns CVE-2026-20222 a 2026 CVSS score of 7.4. Exposure requires EIGRP to be enabled. Cisco says ASA releases 9.18 and earlier and FTD releases 7.4 and earlier are not vulnerable; for later affected trains, use the advisory’s fixed-release table. Cisco reported no known public announcements or malicious use and said the issue was found while resolving a Cisco TAC support case. It recommends upgrading to a first fixed release, noting that those releases include fixes for multiple vulnerabilities.
Rank #2
- Cisco asa 5525-x firewall edition - 8 port - gigabit Ethernet
- Cisco asa 5525-x firewall edition
- 8 port - gigabit Ethernet
Cisco identifies EIGRP authentication as a risk-reduction best practice, but advises customers to assess environment-specific impacts. That is not a replacement for fixed software.
TCP DNS denial of service: CVE-2026-20248
Cisco assigns CVE-2026-20248 a 2026 CVSS score of 6.8. The attacker must be able to respond to DNS queries made by the device—for example, by controlling the DNS service or intercepting traffic from a machine-in-the-middle position. The issue can cause a reload and service interruption. Cisco’s advisory provides first fixed releases for ASA and FTD trains; confirm the entry for the actual device in the full table. Cisco says there is no workaround addressing this vulnerability.
Rank #3
- 10 × GbE (2 WAN, 2 PoE+), 1 × USB 2.0 for 3G/4G failover
- Stateful firewall throughput: 450 Mbps, VPN throughput: 200 Mbps
- Recommended maximum clients: 50, Layer 7 application visibility and traffic shaping
- Automatic firmware upgrades and security patches, VLAN support and DHCP services
- Includes 100W DC Power Supply, requires Enterprise or Advanced Security License
FMC-only multi-vulnerability advisory
The cited FMC advisory says its vulnerabilities affect FMC regardless of configuration and do not affect ASA or FTD. It lists CVE-2026-76420 at CVSS 9.0 and CVE-2026-76412 and CVE-2026-76413 at CVSS 8.5 each. Cisco describes the vulnerabilities as independent: exploiting one is not a prerequisite for exploiting another, and a release affected by one may not be affected by the others. The advisory reports no known public announcements or malicious use.
One described FMC peer-impersonation issue can be exploited only when the valid sftunnel connection between FMC and FTD is down. Check the advisory for each vulnerability’s specific conditions rather than assuming that every FMC issue shares this prerequisite.
Rank #4
- REMOTE-WORKER READY: Pre-integrated support for additional Cisco Security capabilities, including Cisco AnyConnect remote access VPN and Cisco Duo multi-factor authentication.
- COMPACT: 1RU design for small and mid-sized offices
- PERFORMANCE WITHOUT SACRIFICE: Firepower 1000 Series firewalls include hardware-based acceleration, maintaining firewall performance in all conditions
- CONFIGURABLE: With available Firepower Threat Defense (FTD) base software, add network-based content inspection, Intrusion Prevention System (IPS), and URL filtering
- PEACE OF MIND: 90-day limited warranty
How do I check whether my Cisco ASA or FTD version is affected?
- Record the exact product—ASA, FTD, or FMC—and its running software release. For an FMC-managed deployment, check both the management center and the managed firewall where the advisory applies.
- Run the release through Cisco Software Checker. Cisco says the tool maps a running release to applicable advisories and first fixed releases, and can report a combined first fixed release.
- Open each relevant September advisory and confirm its product scope, release train, exposure conditions, and any hot-fix notes. Do not infer vulnerability from a CVE score alone.
- For configuration-dependent findings, verify the relevant setting or service. In particular, confirm whether EIGRP is enabled and assess whether an attacker could respond to device DNS queries for the TCP DNS issue.
- Compare the installed version with the advisory’s current fixed-release table. Confirm that the proposed target is supported by the hardware and compatible with the deployment before scheduling the change.
What is the first fixed release for my Cisco Secure Firewall software?
The following are first fixed releases listed in Cisco’s September 2026 hardening advisory, updated September 18. Match the software train, not just the product family. These entries are a starting point: Cisco flags certain affected hot-fix releases in the full table, so check the latest advisory before upgrading.
| Product line | Software train | First fixed release |
|---|---|---|
| ASA | 9.16 and earlier | 9.16.4.103 |
| ASA | 9.18 | 9.18.4.94 |
| ASA | 9.20 | 9.20.4.49 |
| ASA | 9.22 | 9.22.3.26 |
| ASA | 9.23 | 9.23.1.47 |
| ASA | 9.24 | 9.24.1.26 |
| FTD and FMC | 7.0 and earlier | 7.0.10 |
| FTD and FMC | 7.2 | 7.2.12 |
| FTD and FMC | 7.4 | 7.4.8 |
| FTD and FMC | 7.6 | 7.6.6 |
| FTD and FMC | 7.7 | 7.7.13 |
| FTD and FMC | 10.0 | 10.0.2 |
| FTD and FMC | 10.1 | 10.1.0 |
Can I use a workaround instead of upgrading?
Cisco says there are no workarounds addressing the cited hardening, EIGRP, and TCP DNS vulnerabilities. EIGRP authentication may reduce risk for the EIGRP issue, but Cisco presents it as a best practice to assess for the local environment, not as a fix. A workaround or a lack of known exploitation does not establish that an affected device is safe to leave unpatched.
Best Value
- More Secured Server Mounting Setup: RM-CI-T14 by Rackmount.IT IU rack mount kits have dedicated slots to safely install compatible Cisco Meraki models, including Cisco Meraki MX68, MX68W, MX68CW, and MX75.
- Improves Cable Management: All console ports of the Cisco Meraki appliance are brought to the front for easy access and user convenience — all while preventing overheating with custom-made cut-outs.
- Straightforward Installation Process: Mounting your appliance to a 19 inch shelf only takes 2-5 mins. as our network tray kits have everything a user needs — bolts, hex keys, zip ties, port labels, cables, and an assembly guide.
- Suitable for Any Type of Business: Our 1U rack shelf kits are designed to fit your appliance in 19-inch network rack shelves, making them ideal for small business owners, large corporations, and government agencies looking to improve their cloud management and network connectivity.
- Passionate for Smart Design and Customization: Rackmount.IT offers innovative solutions to common user needs by producing high-quality custom rack mounted shelf with excellent features that support major desktop appliance manufacturers.
For upgrade entitlement or support questions, Cisco directs customers to Cisco TAC or their maintenance providers. Confirm support and compatibility for the actual hardware and software configuration before deployment.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




