Multiple Threat Groups Exploit Critical Cisco Flaw for Enterprise Network Access
Cisco has warned that a high-severity flaw in its Secure Firewall Management Center software is being actively exploited by multiple threat groups to break into enterprise networks. The vulnerability, tracked as CVE-2026-20079, carries a CVSS score of 10.0 and allows an unauthenticated remote attacker to bypass FMC's authentication controls entirely and run scripts that can lead to root-level access on the underlying operating system.
The exploitation is already tied to both state-sponsored espionage activity and a financially motivated ransomware operation. A second, lower-severity flaw, CVE-2026-20316, rated 5.3 on the CVSS scale, is being chained with CVE-2026-20079 in some intrusions.
Cisco has released hotfixes for both vulnerabilities and is urging every organization running affected FMC deployments to apply them immediately. A broader hardening release is planned for the week of September 14, but the current hotfixes are meant as an emergency stopgap rather than a final patch.