Cisco Firewall Flaw Exploited by Hackers for Root Access and Malware Deployment
Cisco's Secure Firewall Management Center (FMC) Software has been hit by two critical vulnerabilities, allowing hackers to gain root access and deploy malware. The flaws were exploited by state-sponsored groups and a ransomware affiliate, causing one of the year's most serious enterprise security incidents.
The more severe bug, tracked as CVE-2026-20079, carries a perfect CVSS score of 10.0 and allows an unauthenticated remote attacker to bypass login controls entirely. This flaw stems from an improper system process created when an FMC device boots up, which can be hijacked by an attacker to execute scripts with root privileges.
Cisco patched the issue in March 2026, but confirmed that its Product Security Incident Response Team became aware of in-the-wild abuse beginning in August. The U.S. Cybersecurity and Infrastructure Security Agency has since added the vulnerability to its Known Exploited Vulnerabilities catalog, giving federal agencies until September 12 to remediate.