← Back to Feed
Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers
September 10, 2026 · BleepingComputer · Severity: CRITICAL
This BleepingComputer article warns that Cisco FMC flaws (CVE-2026-20079) are being actively exploited by both ransomware gangs and state-sponsored hackers. The authentication bypass vulnerability grants full administrative control, enabling attackers to compromise networks. Cisco has provided patches and advisories to address the issue.
Key Takeaways
- Cisco Secure Firewall Management Center flaws tracked as CVE-2026-20079 are being actively exploited by ransomware gangs and state-sponsored hackers to gain full administrative control over affected devices. The authentication bypass vulnerability allows attackers to take over Cisco FMC appliances without credentials.
- Exploitation of Cisco FMC vulnerabilities enables attackers to pivot within networks, deploy ransomware, or conduct espionage, posing a severe risk to organisations relying on Cisco firewalls. Cisco has released security advisories urging immediate patching of these actively exploited flaws.
- Organisations using Cisco Secure Firewall Management Center should apply available patches or mitigations urgently to prevent takeover by threat actors. The active exploitation by diverse groups highlights the critical nature of this vulnerability and the need for rapid response.