In plain language
What this advisory means
Cisco discovered multiple security weaknesses in its Secure Firewall products during internal testing, including some that have already been exploited by attackers. These issues could allow unauthorized access or cause serious security problems. Cisco has released updated software versions to fix these vulnerabilities and strongly advises users to upgrade without delay since no workarounds are available.
Technical explanation
How the issue affects the environment
Through a comprehensive internal security review using standard processes and AI-assisted testing, Cisco identified several critical vulnerabilities across the Secure Firewall Adaptive Security Appliance (ASA), Threat Defense (FTD), and Management Center (FMC) software. The issues span multiple CWE categories such as improper handling of exceptions (CWE-703), malformed data validation (CWE-707), insufficient protection mechanisms (CWE-693), and improper access control (CWE-284). Eight CVEs with highest CVSS scores up to 9.9 affect these products; two vulnerabilities related to static credentials and authentication bypass are known to be actively exploited. Cisco released fixed software versions starting from ASA 9.16.4.103, FTD/FMC 7.0.10, and later releases. No mitigating workarounds exist. Users must upgrade to first fixed releases to remediate all issues securely.
Operational impact
Why teams should care
If unaddressed, these critical vulnerabilities can lead to unauthorized access, data breaches, or disruption of firewall security services. This exposes organizations to increased risk of cyber attacks, potential data loss, and operational downtime, undermining corporate network defenses and compliance obligations.
Immediate action
Cisco strongly recommends that all customers promptly upgrade to the fixed software releases listed to fully address these vulnerabilities. The upgrades include patches that remediate multiple critical vulnerabilities grouped by their CWE classifications.
Affected and fixed releases
Temporary risk reduction
No workarounds exist for these vulnerabilities; only upgrading to the fixed software versions will mitigate the risks.
Evidence and validation checklist
- Cisco conducted internal security testing including AI-assisted methods.
- Multiple vulnerabilities were internally discovered impacting ASA, FTD, and FMC products.
- Cisco confirmed two vulnerabilities are actively exploited.
- Cisco released fixed software versions addressing grouped CWEs and assigned CVEs.
- No workarounds address these vulnerabilities, remediation requires software update.
- Cisco published these details and fixed release information in official advisory dated September 16, 2026.
Authoritative reference
Cisco PSIRT Advisories
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
