Cisco's Firewall Flaw Exposes 700 Boxes to Root Access Attackers
Cisco has confirmed that its Secure Firewall Management Center software contains a maximum-severity flaw, tracked as CVE-2026-20079, which is being actively exploited by both Russian state-sponsored hackers and a ransomware affiliate.
The vulnerability, discovered in March 2026 but only now confirmed to be under active attack, allows an unauthenticated attacker to send crafted HTTP requests to the FMC device's web interface and gain root access. Cisco's security advisory and reporting from BleepingComputer note that this flaw earns a perfect CVSS score of 10.0.
Cisco has also disclosed a companion bug, CVE-2026-20316, involving static, hard-coded credentials baked into the FMC web interface. While this flaw is not as severe on its own, it can be chained with other vulnerabilities to escalate into full root access.
The U.S. Cybersecurity and Infrastructure Security Agency added both bugs to its Known Exploited Vulnerabilities catalog, giving federal civilian agencies until September 12 to patch the flaws. However, security experts advise all organizations running Cisco Secure Firewall Management Center to assume compromise and prioritize patching immediately.