Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
Brief
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software.
First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched instances of Cisco’s Secure FMC Software, which allows an unauthenticated, remote attacker to bypass authentications and execute scripts on impacted devices to obtain root access to the underlying operating system. Second, CVE-2026-20316 is a vulnerability that allows a remote attacker to log in using a low-privileged account.
CVE-2026-20079 is a critical vulnerability with a CVSS score of 10.
- Customers are strongly advised to follow Cisco’s guidance provided in the security advisory and apply the security patches previously made available.
CVE-2026-20316 has a CVSS score of 5.3, however it can be used with other Cisco Secure FMC vulnerabilities to elevate privileges.
