cisco-sa-notice-jfxK98ZP: Cisco Advance Notification for Publication of September 16, 2026, Security Advisories
On September 16, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products:BroadWorks CommPilot Application Software Identity Services Engine (ISE) (security hardening release)Nexus Dashboard (security hardening release)Secure Firewall Adaptive Security Appliance (ASA) (security hardening release)Secure Firewall Management Center (FMC) (security hardening release)Secure FirewallThreat Defense (FTD) (security hardening release)ThousandEyes Virtual ApplianceNote: All three Cisco Secure Firewall products will be included in the same security hardening release. For more information about Cisco Secure FMC Software, including recently disclosed vulnerabilities and their available fixes, see the Cisco Talos blog post.To remediate vulnerabilities to be disclosed on September 16, 2026, Cisco strongly recommends that customers upgrade to the fixed software indicated in the advisories.For more information about changes in Cisco PSIRT vulnerability disclosure, see Cisco's Transition to a Risk-Based Vulnerability Disclosure Model.
Event History
Frequently Asked Questions
Which products are expected to receive fixed software releases on September 16, 2026?
Cisco plans to publish advisories with fixed releases for BroadWorks CommPilot Application Software and ThousandEyes Virtual Appliance. Security hardening releases are planned for Identity Services Engine, Nexus Dashboard, and Cisco Secure Firewall ASA, FMC, and FTD.
Are the Cisco Secure Firewall products being handled separately?
No. Cisco states that ASA, FMC, and FTD will all be included in the same security hardening release.
What action should organizations plan to take?
Review the product-specific advisories when they are published on September 16, 2026, and upgrade to the fixed software releases identified there. The notice does not provide vulnerability details or affected versions before publication.