Cisco’s September Firewall Fix Creates Two Checkpoints for FMC Closure
Cover image: Enterprise firewall routing appliances and high-density server infrastructure deployed in a mission-critical data center. Photo by Taylor Vick on Unsplash Miles Park IT engineer and technology analyst based in Virginia. About the author Cisco’s September 16, 2026 Secure Firewall hardening release establishes new fixed-software baselines for Adaptive Security Appliance (ASA), Firewall Threat Defense (FTD), and Firewall Management Center (FMC). For customer-operated FMC, however, reaching a fixed version does not by itself resolve the possibility of compromise before the upgrade. That distinction comes from Cisco’s own recovery language. Its advisories for two actively exploited FMC vulnerabilities say that earlier hotfixes prevented future exploitation but might not address an existing compromise. Cisco Talos separately documented intrusions that moved from FMC access to credential theft, persistence, configuration collection, tunneling, and ransomware deployment...