[CRITICAL] "Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks"
criticalDetails
A maximum-severity authentication bypass vulnerability in Cisco's Secure Firewall Management Center (FMC) software is confirmed to be actively exploited. This flaw could allow an unauthenticated, remote attacker to gain unauthorized access to the device.
Affected Systems
Cisco Secure Firewall Management Center (FMC) software
Potential Impact
Compromise of network security management, allowing attackers to alter firewall policies, monitor traffic, and pivot to other network segments. This represents a critical risk to network integrity and data confidentiality.
Mitigations
Apply patches immediately. Per CISA's Known Exploited Vulnerabilities (KEV) catalog, federal agencies must remediate this vulnerability by September 12, 2026.