Cisco FMC Under Attack: Critical Vulnerability Exploited in the Wild
Cisco has confirmed active exploitation of CVE-2026-20079, a critical authentication bypass in its Secure Firewall Management Center (FMC) Software. An unauthenticated remote attacker can gain root access by crafting HTTP requests to the web interface.
The vulnerability carries a CVSS base score of 10.0 and affects Cisco Secure FMC Software regardless of device configuration. Administrators should identify installed releases, determine if the management interface was reachable from the public internet while vulnerable, and run a documented log check before closing the case.
Installing a hotfix at this stage closes the known entry route but does not remove persistence, restore exposed credentials, or establish that the appliance is trustworthy. Cisco Technical Assistance Center should be contacted for recovery options if there is credible evidence of compromise.