CISA Urges Federal Agencies to Patch Critical Cisco Vulnerability
Cisco's Secure Firewall Management Center (FMC) is being targeted by attackers who are exploiting a critical vulnerability, CVE-2026-20079. This flaw, which has a CVSS score of 10.0, allows an attacker to bypass authentication and run scripts and commands as root on the affected device.
The US Cybersecurity and Infrastructure Security Agency (CISA) gave federal agencies until today to patch this vulnerability, but the deadline is not just for government agencies. Any organization that uses Cisco's FMC should prioritize patching this flaw to prevent a potential breach.
Cisco has released hotfixes for Secure FMC release branches 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0, but applying these fixes does not clean up devices that have already been compromised. Cisco's advisory warns that customers who have been affected should contact their Technical Assistance Center (TAC) for recovery guidance.
This vulnerability is particularly concerning because it affects the management console of Cisco firewalls, which means an attacker can potentially gain access to everything behind the firewall.