Skip to content
Tech News
← Back to articles

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

read original get YubiKey 5 NFC Security Key → more articles
Why This Matters

A CVSS 10.0 authentication bypass in Cisco Secure Firewall Management Center is now confirmed as actively exploited, letting unauthenticated attackers run commands as root on the very appliances that manage enterprise firewall policy. With no workarounds available and CISA issuing a September 12 federal patching deadline, this is an urgent patch-now situation for anyone running FMC.

Key Takeaways
Worth a Look

YubiKey 5 NFC Security Key — When authentication bypass bugs are being actively exploited, hardware-backed MFA is one of the strongest defenses admins can add to their own accounts. The YubiKey 5 NFC supports FIDO2/WebAuthn, OTP and smart card protocols, works over USB-A and NFC, and needs no batteries or network connection.

See YubiKey 5 NFC Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks.

The vulnerability has a maximum CVSS score of 10.0 and allows unauthenticated, remote attackers to bypass authentication and execute scripts and commands as root on vulnerable devices.

"In August 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability," Cisco updated its CVE-2026-20079 advisory to say on Wednesday.

Cisco did not disclose when the attacks began, who was behind them, or what post-exploitation activity was observed.

Cisco first disclosed CVE-2026-20079 in March, when the company said it had no evidence that the vulnerability was being exploited in attacks.

The flaw is caused by an improper system process created at boot time and can be exploited by sending crafted HTTP requests to the web interface of an affected device.

A successful attack can allow an unauthenticated attacker to execute scripts and commands on the device with root privileges.

The vulnerability affects Cisco Secure FMC Software and Cisco Security Cloud Control Firewall Management. Cisco says it has already patched the cloud-hosted Security Cloud Control service.

Cisco says there are no workarounds and recommends that customers upgrade to the latest software release.

Today, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog, ordering Federal Civilian Executive Branch agencies to secure vulnerable systems by September 12, 2026.

... continue reading