CVE-2026-20079 Exploit Activated: Secure FMC Under Siege
Cisco has confirmed a critical vulnerability in its Secure FMC management environment. The flaw, CVE-2026-20079, allows remote, unauthenticated attackers to bypass authentication and execute commands with root privileges.
The issue was discovered in March but no attacks were reported at that time. However, Cisco's PSIRT team has been aware of the attacks since August. The company released an update on September 9 and rates the issue a CVSS 10.0, its highest severity rating.
Cisco Secure FMC Software and Security Cloud Control Firewall Management are affected by the vulnerability, regardless of device configuration. However, hosted Security Cloud Control has already been automatically patched.