ZeroHour
SOCRadarpublished ()ingested ameer
Part of a story covered by 13 sources: “Cisco Secure FMC flaws CVE-2026-20079 and CVE-2026-20316 actively exploited by Sandworm-linked APT and Qilin ransomware affiliates” — merged summary and timeline →

Cisco FMC CVE-2026-20079 Actively Exploited

criticalExploit / PoC exploited in the wildimportance 85CVE-2026-20079
AI summary · glm-5.3-flash

Cisco confirms active exploitation of CVE-2026-20079, a maximum-severity authentication bypass in Secure Firewall Management Center.

Cisco has confirmed that CVE-2026-20079, a critical authentication bypass in Cisco Secure Firewall Management Center (FMC), is being actively exploited in the wild. The vulnerability carries a maximum CVSS severity, and defenders are urged to treat it as an urgent patch priority. FMC centrally manages Cisco Secure Firewall deployments, so exposure across enterprise environments is likely.

  • CVE-2026-20079 is a critical authentication bypass in Cisco FMC
  • Cisco confirmed the flaw is being actively exploited
  • FMC is widely deployed to centrally manage Cisco Secure Firewalls

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-20079
Authentication bypass to root access in Cisco Secure Firewall Management Center

CVE-2026-20079 is an authentication bypass (CWE-288) in the web interface of Cisco Secure Firewall Management Center (FMC) Software, caused by an improper system process created at boot time. An unauthenticated, remote attacker can exploit it by sending crafted HTTP requests to the FMC web interface, which allows the execution of script files and commands on the device. A successful exploit grants the attacker root access to the underlying operating system, giving full control of the management platform (CVSS 3.1: 10.0, network-exploitable, no privileges or user interaction required, scope changed). The flaw affects Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management deployments. Cisco has confirmed the vulnerability is being exploited in active attacks, it carries a 35.9% EPSS score (98th percentile), and CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-09.

Do: Upgrade FMC (and SCC Firewall Management tenants) to the fixed release specified in Cisco's advisory, prioritizing internet-exposed or externally reachable management interfaces; CISA KEV action applies to federal agencies under BOD 26-04. Until patching, restrict FMC web interface access to trusted management networks and VPNs and check devices for signs of exploitation such as unexpected script execution, unfamiliar processes, or root-level changes. Triage per CISA's Forensics Triage Requirements if compromise is suspected.

10.076% KEV PoC ×2
  • Cisco Secure Firewall Management Center (FMC) Software (web interface)
  • Cisco Security Cloud Control (SCC) Firewall Management
largeplausibly tens of thousands of FMC deployments worldwide (internet-exposed instances likely a smaller subset, likely thousands)
Full article

Cisco FMC CVE-2026-20079 Actively Exploited Cisco has confirmed active exploitation of CVE-2026-20079 , a critical authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC) with a maximum CVSS

The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at socradar.io.