Hackers Exploit Critical Cisco Firewall Flaw for Root Access
Cisco has confirmed that hackers are actively exploiting two critical vulnerabilities in its Secure Firewall Management Center (FMC) Software, allowing them to gain root access and deploy malware.
The more severe of the two bugs, tracked as CVE-2026-20079, allows an unauthenticated remote attacker to bypass login controls entirely. This flaw stems from an improper system process created when an FMC device boots up, which can be hijacked by an attacker if not claimed by a legitimate user.
Cisco patched the issue in March 2026, but confirmed that its Product Security Incident Response Team became aware of in-the-wild abuse beginning in August. The U.S. Cybersecurity and Infrastructure Security Agency has since added the vulnerability to its Known Exploited Vulnerabilities catalog, giving federal agencies until September 12 to remediate.
Cisco is urging every organization running Secure FMC to apply the already-released hotfixes for both CVE-2026-20079 and CVE-2026-20316 immediately, rather than waiting for a broader hardening release scheduled for the week of September 14.