Cisco's Firewall Management Center Hit by Third Critical Vulnerability in 2026
Cisco's Firewall Management Center (FMC) has been hit by its third critical vulnerability this year, according to the Cybersecurity and Infrastructure Security Agency (CISA). CVE-2026-20079 is a CVSS score of 10.0 authentication bypass flaw that allows an unauthenticated remote attacker to execute scripts and gain root access to the management interface.
The vulnerability stems from an improperly created system process at boot time, categorized under CWE-288. This is the third FMC vulnerability added to the CISA Known Exploited Vulnerabilities (KEV) catalog in 2026, following CVE-2026-20316 and CVE-2026-20131.
Cisco Talos has observed three distinct threat actor clusters exploiting the FMC management plane. UAT-12197 has utilized JSP web shells and cmd.jar to extract credentials from FMC databases. Meanwhile, UAT-11823, attributed to the Russian Sandworm/GRU group, has leveraged both CVE-2026-20079 and CVE-2026-20316 to deploy Cyclops Blink malware.
The severity of CVE-2026-20079 is compounded by its changed CVSS scope. Successful exploitation of the FMC does not merely compromise the management console; it provides a pathway to compromise managed FTD firewall devices downstream, allowing an attacker to propagate commands from the management plane to the managed firewall infrastructure.