Cisco has confirmed that a maximum-severity authentication bypass vulnerability (CVE-2026-20079, CVSS 10.0) in its Secure Firewall Management Center (FMC) Software is being actively exploited. Attackers can gain root access to the management system without any valid credentials.
Why the flaw is so dangerous
The root cause is an improper system process that is created when the device boots. An unauthenticated, remote attacker can send crafted HTTP requests to the web interface, execute script files and obtain full root access to the underlying operating system. Because the FMC centrally manages numerous firewalls, a single compromise effectively opens the door to the entire protected network. A second, chained vulnerability (CVE-2026-20316, CVSS 5.3) additionally enables privilege escalation from a low-privileged account.
Multiple threat actors involved
Cisco’s PSIRT became aware of ongoing attacks back in August 2026. On September 9 Cisco updated its advisory, and the US agency CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog. Cisco’s Talos team attributes the intrusions to three separate clusters, including an APT overlapping with the Sandworm group and an affiliate of the Qilin ransomware operation.
What administrators should do now
Affected releases are FMC versions 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0. Cisco provides a hotfix for each branch (for example HG-7.4.7.1-3 for the 7.4 line). There is no effective workaround, so operators should apply the patches immediately and must never expose the management interface directly to the internet.
Source: Cisco Security Advisory on CVE-2026-20079.














