Cisco Confirms Active Exploitation of Critical Firewall Management Flaw
Cisco has confirmed that threat actors are actively exploiting a critical vulnerability in Secure Firewall Management Center. The flaw, known as CVE-2026-20079, allows an unauthenticated attacker to bypass authentication and execute commands with root privileges on an affected management appliance.
The vulnerability was first disclosed by Cisco on March 4, 2026, but it wasn't until September 9 that the company confirmed it had been exploited in real-world attacks. The CVSS severity score is 10.0 out of 10, indicating a maximum-severity risk.
Cisco's Secure Firewall Management Center is a highly trusted system within an organization's security architecture. Root-level access to an FMC appliance could potentially expose sensitive configuration data and administrative information, making it a serious concern for affected organizations.