Cisco Patch Decision Sheet: September 2026 (sample)

Data as of 2026-09-18 • CISA KEV catalog 2026.09.18 (1,715 entries) • Sample, format test

Fifteen CVEs, three jobs. Two are emergencies with a federal deadline and confirmed exploitation (FMC, ISE). One is a routine hardening batch on IOS XR with no known exploitation. The six ISE hardening CVEs are not a job at all: the ISE emergency upgrade closes them. Treating fifteen CVEs as fifteen equal tickets is the treadmill this sheet exists to stop.

Example inventory

Device roleSoftwareVersion
Firewall managementCisco Secure FMC (appliance)7.4.2.3
Core routerCisco IOS XR (NCS 540, LNT)24.3.2
Edge routerCisco IOS XR (ASR 9000, 64-bit)7.11.21
Network access controlCisco ISE (2 node deployment)3.3 Patch 9

The subscriber provides versions once. Every advisory below is matched against this list. The inventory here is illustrative.

Decision sheet

1. Secure FMC authentication bypass

Emergency change, this week

cisco-sa-onprem-fmc-authbypass-5JPp45V2, rev 2.6, 2026-09-16 (first published 2026-03-04)

One sentence for the change board
The federal deadline is behind you and exploitation is confirmed. First run the compromise check from the advisory and involve TAC if anything looks wrong, then upgrade 7.4.2.3 to 7.4.8. Keep the FMC web interface unreachable from the internet until it is done.
CVE and CVSS
CVE-2026-20079, CVSS 10.0. Unauthenticated authentication bypass to root through the web interface.
KEV status and federal due date
In KEV since 2026-09-09, federal due date 2026-09-12 (3-day), already passed. Cisco PSIRT became aware of active exploitation in August 2026. Talos (2026-09-09) describes three clusters of post-compromise activity: web shells and credential exfiltration; an APT whose tooling overlaps with Sandworm, deploying a Cyclops Blink variant; and a Qilin ransomware operator who logged in with static credentials (CVE-2026-20316, a separate advisory, not scored here).
Applies to your inventory
Yes. FMC 7.4.2.3 is on the advisory's Known Affected list (72 FMC releases). Security Cloud Control Firewall Management (SaaS) was fixed by Cisco, no customer action.
Fixed release
No workaround. First fixed release per train: 7.0 and earlier 7.0.10, 7.2 7.2.12, 7.4 7.4.8, 7.6 7.6.6, 7.7 7.7.13, 10.0 10.0.2. Rev 2.6 replaced the earlier hot fixes with these hardening releases.
Confidence
Affected: confirmed (Known Affected list). Fixed release: confirmed (CVRF Fixed Software table, rev 2.6). If you applied a hot fix before 2026-09-16, the advisory now points to the hardening release instead: plan that upgrade anyway.

2. IOS XR security hardening release, September 2026

Standard change, next maintenance window

cisco-sa-hardening-iosxr-qg64NcM, rev 2.2, 2026-09-17 (first published 2026-09-02, ten revisions in 15 days)

One sentence for the change board
Not exploited and no federal clock, so this goes into the next window within 30 days. Apply the SMU set for 24.3.2 and 7.11.21, or plan the move to 26.2.2. Read the functional-area table first: IS-IS, MPLS-TE and Segment Routing IPv6 have release-specific SMU IDs and some were superseded.
CVE and CVSS
Seven CVEs, one per CWE category: CVE-2026-20274 (9.8), CVE-2026-20279 (9.8), CVE-2026-20275 (8.8), CVE-2026-20278 (8.8), CVE-2026-20280 (8.8), CVE-2026-20276 (8.6), CVE-2026-20277 (8.2). Found by Cisco's internal security review.
KEV status and federal due date
Not in KEV (all seven). Cisco PSIRT is not aware of public announcements or malicious use.
Applies to your inventory
Yes, both routers. The advisory covers all IOS XR releases including XR7 (LNT), regardless of configuration.
Fixed release
No workaround. First fixed releases: 26.2.2 and 26.3.1. SMU route per train: SMUs for 24.3.2 are released; 7.11 has SMUs for 7.11.2 and 7.11.21. Expect around 16 SMUs per release.
Confidence
Affected: confirmed at train level (advisory). Exact SMU list per platform: verify in Software Center. The advisory keeps changing (rev 2.1 and 2.2 each marked another release's SMUs as released), so read the revision you are acting on.

3. ISE authentication bypass

Emergency change, before the federal date

cisco-sa-ISE-ABP-VNSW7Tn5, rev 1.0, 2026-09-16

One sentence for the change board
ISE decides who gets on the network, so an authentication bypass on it is an access policy problem for every device that trusts this node, not a single box problem. Apply the infrastructure ACL today, then move 3.3 Patch 9 to 3.3 Patch 12.
CVE and CVSS
CVE-2026-76460, CVSS 10.0 (CWE-648). Unauthenticated authentication bypass through an API endpoint.
KEV status and federal due date
In KEV since 2026-09-16, federal due date 2026-09-19 (3-day). Cisco PSIRT is aware of active exploitation.
Applies to your inventory
Yes. Cisco ISE and ISE-PIC are affected regardless of device configuration, and 3.3 Patch 9 is below the first fixed release for the 3.3 train.
Fixed release
No workaround. Mitigation only: infrastructure ACLs that limit management and control plane traffic to the node. First fixed per train: 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4. Release 3.0 is past End of Software Maintenance: no fix, migrate.
Confidence
Affected, fixed release and exploitation: confirmed (CVRF). Patch level is as provided by the subscriber.

4. ISE hardening release, September 2026

No separate change

cisco-sa-hardening-ise-XU5EwX5T, rev 1.0, 2026-09-16

One sentence for the change board
These six are closed by the same upgrade as the ISE emergency. Do not open six tickets and do not look for six mitigations: each CVE here stands for a category of fixes, and the hardened release is the only remediation Cisco offers for it.
CVE and CVSS
Six CVEs, one per CWE category: CVE-2026-20130 (10.0, CWE-74), CVE-2026-20192 (10.0, CWE-284), CVE-2026-20234 (9.9, CWE-522), CVE-2026-20194 (9.1, CWE-669), CVE-2026-20237 (9.1, CWE-20), CVE-2026-20287 (6.5, CWE-269).
KEV status and federal due date
Not in KEV (all six). Cisco PSIRT is not aware of public announcements or malicious use.
Applies to your inventory
Yes. Same affected scope as the ISE authentication bypass above.
Fixed release
Same table as the row above: 3.3 Patch 12 closes all six. Releases 3.1 and 3.2 receive Critical fixes only. ISE-PIC is end of sale and 3.4 is its last supported release.
Confidence
Affected and fixed release: confirmed (CVRF). Per-CVE CWE and CVSS: confirmed (NVD API 2.0, source [email protected]). The advisory is rated Critical while CVE-2026-20287 scores 6.5, because the rating describes the release as a whole.

What changed during the month

  • 2026-09-09: FMC advisory rev 2.5 adds confirmed active exploitation. KEV adds CVE-2026-20079 with a 3-day due date. Talos publishes three intrusion clusters.
  • 2026-09-11: IOS XR advisory rev 2.0 marks fixed releases 26.2.2 and 26.3.1 as available.
  • 2026-09-16: Cisco publishes 16 ISE advisories in one scheduled drop. CVE-2026-76460 enters KEV the same day with a 3-day due date.
  • 2026-09-16: FMC advisory rev 2.6 replaces the hot fixes with hardening releases. The fix column of this sheet changed from a hot fix name to 7.4.8.
  • 2026-09-15 to 2026-09-17: IOS XR advisory rev 2.1 and 2.2 mark SMUs for 25.1.2 and 24.1.2 as released.

Method and limits

  • Sources are read at primary: Cisco advisories through the PSIRT API and CVRF (revision history, Known Affected list, fixed software, exploitation note), NVD API 2.0 (CVSS, CWE), the CISA KEV feed (date added, due date), and the Talos blog for the FMC intrusion clusters.
  • "Applies to your inventory" is matched on the advisory's Known Affected list. Where Cisco names a different base release than yours, the cell says verify. If Cisco did not write it, the sheet does not guess it.
  • Hardening release rule. Since July 2026 Cisco publishes on the first and third Wednesday of the month with seven days of advance notice, and in a hardening release it assigns one CVE per CWE category, not one per defect. On this sheet a hardening release is therefore one row and at most one job. Its CVEs are never scored as separate tickets and the row never offers a per-CVE mitigation.
  • Calendar. The same cadence makes the sheet schedulable. Next scheduled Cisco drop: 2026-10-07, with the advance notice expected around 2026-09-30.
  • Not covered in this sample: SD-WAN, FTD, ASA, the other 14 ISE advisories of 2026-09-16, and the rest of September. It is four advisories chosen to show the format, not the full month.
  • The inventory is illustrative, not a real customer.

Want this for your versions? This is a format test. If a monthly sheet like this, matched to your own software list, would save you the reading, send the list (product and version, nothing else) to [email protected] and say so. No form, no signup. The free CVE Analyzer already does the matching for IOS XE and ISE one version at a time.