โ† Back to Feed

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

CVE-2026-20079

September 9, 2026 ยท BleepingComputer ยท Severity: HIGH

This article reports that Cisco confirmed active exploitation of a critical authentication bypass vulnerability in Secure Firewall Management Center. The flaw allows unauthenticated attackers to gain administrative control, and Cisco has released patches urging immediate application. ๐Ÿ“Œ **Analyst Note:** This is a critical threat because Secure FMC is a central management point for firewall policies; a compromise could allow attackers to disable or reconfigure network defenses. Security teams should treat this as an emergency and verify patching across all instances.

Key Takeaways

  • Cisco has confirmed active exploitation of CVE-2026-20079, a maximum-severity authentication bypass vulnerability in Secure Firewall Management Center that allows unauthenticated remote attackers to gain full administrative control over affected devices.
  • Organizations using Cisco Secure FMC should immediately apply the patches released by Cisco, as the flaw requires no authentication and can lead to complete compromise of the firewall management infrastructure.
  • The vulnerability's CVSS score of 10.0 highlights the critical nature of this issue, and security teams must prioritize patching to prevent attackers from taking over network security appliances.
โ˜• Buy a Coffee