Cisco FMC Users Warned of Active Exploitation of Critical Vulnerability
Cisco and the US Cybersecurity and Infrastructure Security Agency (CISA) have issued a warning about the exploitation of a critical vulnerability in Cisco Secure Firewall Management Center (FMC). The vulnerability, tracked as CVE-2026-20079, is an authentication bypass issue that can be exploited by a remote attacker to gain root access to the underlying operating system.
Cisco patched the vulnerability in early March and updated its advisory with indicators of compromise in late July. However, it was not until September 9 that Cisco warned about active exploitation. CISA has added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog and instructed federal agencies to address the issue by September 12.
Cisco FMC users can protect themselves by installing available patches and ensuring the FMC interface is not accessible from the internet. Three activity clusters exploiting CVE-2026-20079 have been identified, including state-sponsored threat actors and financially motivated groups.