Cisco FMC Flaws Exploited by Threat Actors for Root Access and Malware Deployment
Cisco has issued hotfixes for two critical vulnerabilities in its Secure Firewall Management Center (FMC) software, which threat actors are actively exploiting to gain root access and deploy malware.
The most severe issue, CVE-2026-20079, allows unauthenticated remote attackers to bypass authentication and run scripts that grant root access to the underlying operating system. This flaw has a CVSS score of 10.0.
A second vulnerability, CVE-2026-20316, permits remote login through a low-privileged static account and has been chained with other FMC flaws to escalate privileges and execute malicious packages.