CVE Tools
Back to feed
Exploited in the wild Secure Firewall Management Center (FMC) Sandworm auth-bypass Cisco Qilin

Active exploitation of Cisco Secure Firewall Management Center vulnerabilities

Cisco Talos·By Cisco Talos··8 min read

Wednesday, September 9, 2026 12:08

Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched instances of Cisco’s Secure FMC Software, which allows an unauthenticated, remote attacker to bypass authentications and execute scripts on impacted devices to obtain root access to the underlying operating system. Second, CVE-2026-20316 is a vulnerability that allows a remote attacker to log in using a low-privileged account.…

Continue reading on Cisco Talos