Security Advisory Desk
criticalQCS priority 100/100Cisco

Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026

Cisco discovered multiple security weaknesses in its Secure Firewall products during internal testing, including some that have already been exploited by attackers. These issues could allow unauthorized access or cause serious security problems. Cisco has released updated software versions to fix these vulnerabilities and strongly advises users to upgrade without delay since no workarounds are available.

Published 18/9/2026, 3:50:33 pmVerified 18/9/2026, 9:04:01 pmRevision 1
Cisco critical network security advisory visual

In plain language

What this advisory means

Cisco discovered multiple security weaknesses in its Secure Firewall products during internal testing, including some that have already been exploited by attackers. These issues could allow unauthorized access or cause serious security problems. Cisco has released updated software versions to fix these vulnerabilities and strongly advises users to upgrade without delay since no workarounds are available.

Technical explanation

How the issue affects the environment

Through a comprehensive internal security review using standard processes and AI-assisted testing, Cisco identified several critical vulnerabilities across the Secure Firewall Adaptive Security Appliance (ASA), Threat Defense (FTD), and Management Center (FMC) software. The issues span multiple CWE categories such as improper handling of exceptions (CWE-703), malformed data validation (CWE-707), insufficient protection mechanisms (CWE-693), and improper access control (CWE-284). Eight CVEs with highest CVSS scores up to 9.9 affect these products; two vulnerabilities related to static credentials and authentication bypass are known to be actively exploited. Cisco released fixed software versions starting from ASA 9.16.4.103, FTD/FMC 7.0.10, and later releases. No mitigating workarounds exist. Users must upgrade to first fixed releases to remediate all issues securely.

Operational impact

Why teams should care

If unaddressed, these critical vulnerabilities can lead to unauthorized access, data breaches, or disruption of firewall security services. This exposes organizations to increased risk of cyber attacks, potential data loss, and operational downtime, undermining corporate network defenses and compliance obligations.

Immediate action

Cisco strongly recommends that all customers promptly upgrade to the fixed software releases listed to fully address these vulnerabilities. The upgrades include patches that remediate multiple critical vulnerabilities grouped by their CWE classifications.

Affected and fixed releases

Affected versionsASA Software versions 9.16 and earlier, FTD Software versions 7.0 and earlier, FMC Software versions 7.0 and earlier
Fixed versionsASA Software 9.16.4.103 and later, FTD Software 7.0.10 and later, FMC Software 7.0.10 and later

Temporary risk reduction

No workarounds exist for these vulnerabilities; only upgrading to the fixed software versions will mitigate the risks.

Evidence and validation checklist

  • Cisco conducted internal security testing including AI-assisted methods.
  • Multiple vulnerabilities were internally discovered impacting ASA, FTD, and FMC products.
  • Cisco confirmed two vulnerabilities are actively exploited.
  • Cisco released fixed software versions addressing grouped CWEs and assigned CVEs.
  • No workarounds address these vulnerabilities, remediation requires software update.
  • Cisco published these details and fixed release information in official advisory dated September 16, 2026.

Authoritative reference

Cisco PSIRT Advisories

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source