Cisco has confirmed that CVE-2026-20079, a maximum-severity authentication bypass flaw in Secure Firewall Management Center, is being actively exploited and can let unauthenticated attackers gain root-level access through crafted HTTP requests. The company and CISA urge immediate patching, as the vulnerability affects Cisco Secure FMC Software and Cisco Security Cloud Control Firewall Management, with evidence suggesting it may have been exploited alongside CVE-2026-20316. #Cisco #CVE-2026-20079 #CVE-2026-20316 #SecureFirewallManagementCenter #SecurityCloudControlFirewallManagement
Keypoints
- CVE-2026-20079 is a critical authentication bypass in Cisco Secure FMC.
- The flaw allows remote, unauthenticated code execution as root.
- Cisco says the vulnerability is being actively exploited in the wild.
- CISA added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog.
- Cisco advises upgrading immediately; hot fixes stop future attacks but do not clean compromised systems.