Cisco Confirms Active Exploitation of Maximum-Severity FMC Vulnerability
Cisco has confirmed that its Secure Firewall Management Center (FMC) software is being actively exploited by attackers due to a maximum-severity authentication bypass vulnerability, CVE-2026-20079. The flaw allows unauthenticated, remote attackers to bypass authentication and execute scripts and commands as root on vulnerable devices.
The vulnerability has a maximum CVSS score of 10.0 and affects Cisco Secure FMC Software and Cisco Security Cloud Control Firewall Management. Cisco says it has already patched the cloud-hosted Security Cloud Control service, but recommends that customers upgrade to the latest software release immediately.
Cisco's security team became aware of active exploitation in August, but evidence suggests the flaw may have been exploited earlier, as far back as July 23. The company advises customers who discover indicators of compromise to contact its Technical Assistance Center for support, warning that installing hot fixes will prevent future exploitation but not remediate devices already compromised.