Cisco Confirms CVE-2026-20079 Secure FMC Flaw Exploited in Attacks
Cisco confirms a CVE-2026-20079 vulnerability in its Secure Firewall Management Center software is being actively exploited in attacks.
Intelligence analysis by Qwen 2.5 (3B)

Cisco has confirmed a security flaw in its Secure Firewall Management Center software is being exploited, with evidence of attacks dating back to July.
This is like a big security hole in a computer system that lets bad guys pretend to be the system and do whatever they want, even if they don't know the password.
Analysis
{"heading":"The CVE-2026-20079 Vulnerability","subheading":"Details and Impact","paragraphs":["Cisco has confirmed that a maximum-severity authentication bypass vulnerability, CVE-2026-20079, in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks.","The vulnerability has a maximum CVSS score of 10.0 and allows unauthenticated, remote attackers to bypass authentication and execute scripts and commands as root on vulnerable devices.","The flaw is caused by an improper system process created at boot time and can be exploited by sending crafted HTTP requests to the web interface of an affected device.","A successful attack can allow an unauthenticated attacker to execute scripts and commands on the device with root privileges."]}
Key points
- Cisco confirms CVE-2026-20079 vulnerability in Secure FMC software is being exploited
- Vulnerability allows unauthenticated, remote attackers to bypass authentication and execute commands as root
- Evidence of attacks dating back to July
- Vulnerability affects Cisco Secure FMC Software and Cisco Security Cloud Control Firewall Management
- CISA orders Federal Civilian Executive Branch agencies to secure vulnerable systems by September 12, 2026
The quick patching of this vulnerability by Cisco and the actions of the U.S. Cybersecurity and Infrastructure Security Agency (CISA) can help prevent more attacks.
Even with the patch, attackers who have already compromised systems might still be able to use this vulnerability to cause damage.


