A High-Severity Cisco FMC Vulnerability Has Been Actively Exploited in Attacks
Cisco has confirmed that a critical vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being exploited by attackers. The flaw, which allows unauthenticated remote access to execute scripts and commands with root privileges, has been identified as having a maximum CVSS score of 10.0.
The vulnerability affects Cisco’s Secure FMC Software and Security Cloud Control Firewall Management, but the company has already patched the cloud-hosted Security Cloud Control service. Unfortunately for affected customers, there are no workarounds to prevent exploitation; instead, they must upgrade to the latest software release as soon as possible.
This news is particularly concerning because the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog just hours ago, requiring Federal Civilian Executive Branch agencies to secure vulnerable systems by September 12, 2026.
According to Cisco, evidence of exploitation was first seen in July, although the company’s security team didn’t become aware of it until August. This lag time is worrying, as it suggests that attackers may have been exploiting this vulnerability for weeks or even months before Cisco’s PSIRT was alerted.
The vulnerability itself is caused by an improper system process created at boot time, which can be exploited by sending crafted HTTP requests to the web interface of an affected device. A successful attack allows an unauthenticated attacker to execute scripts and commands on the device with root privileges, essentially giving them complete control over the device.
What’s even more concerning is that this vulnerability may not have been the only one exploited in these attacks. Cisco released hot fixes for both CVE-2026-20316 and CVE-2026-20079, which share identical indicators of compromise (IOCs). This suggests that attackers may have combined multiple vulnerabilities to elevate privileges on affected devices.
For customers who discover the IOCs, Cisco advises them to contact its Technical Assistance Center (TAC) for support. Installing the hot fixes will prevent future exploitation but will not remediate devices already compromised.
In light of this news, it’s essential for all organizations using Cisco Secure FMC Software or Security Cloud Control Firewall Management to take immediate action. System administrators should check their logs for any signs of compromise and apply the latest software updates as soon as possible to prevent further exploitation.
Source: Bleeping Computer — 2026-09-09