Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks
What happened
Cisco confirmed that an unauthenticated, remote attacker is actively exploiting CVE-2026-20079, a maximum-severity authentication bypass in Secure Firewall Management Center software that grants root-level command execution. The flaw, caused by an improper system process created at boot, allows attackers to bypass authentication via crafted HTTP requests to the web interface. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, ordering federal agencies to patch the system by September 12, 2026.
Why it ranks #1
Cisco confirmed that an unauthenticated, remote attacker is actively exploiting CVE-2026-20079, a maximum-severity authentication bypass in Secure Firewall Management Center software that grants root-level command execution via crafted HTTP requests to the web interface.
Who should care
Application security teams, Identity and access teams, IT and platform operations, SOC and incident response teams
- Impact
- high
- Urgency
- immediate
- Confidence
- high
- Scope
- product
- Status
- actively exploited