CVE Tools
Back to feed
Exploited in the wild Secure Firewall Management Center (FMC) auth-bypass Security Cloud Control Firewall Management Cisco network-edge

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

BleepingComputer·By Lawrence Abrams··3 min read
CVE Tools coverage

Cisco has confirmed that CVE-2026-20079, a critical authentication bypass vulnerability in its Secure Firewall Management Center (FMC) software, is under active attack. This flaw, rated with a maximum CVSS score of 10.0, allows unauthenticated remote attackers to execute arbitrary scripts with root privileges by sending crafted HTTP requests to the device web interface.

The incident affects both Cisco Secure FMC Software and Security Cloud Control Firewall Management, though Cisco states the cloud-hosted service has already been patched. With no available workarounds, the vendor urges customers to immediately upgrade to the latest software release to mitigate the risk of full system compromise.