Cisco Firewall Management Center Flaws Exploited in Wild, One Scores Perfect 10
Cisco Talos disclosed on 9 September 2026 that two vulnerabilities in the web interface of Cisco Secure Firewall Management Center were being actively exploited by three separate threat clusters. The more critical flaw, CVE-2026-20079, carries a maximum CVSS score of 10.0 and allows a pre-authentication bypass, enabling attackers to execute scripts and gain root access via a crafted HTTP request. A second vulnerability, CVE-2026-20316, scores a relatively low 5.3 but was chained with the first flaw to serve as initial access in at least one ransomware attack. Although CVE-2026-20079 was patched in March 2026, Cisco updated its advisory in September after learning in August that exploitation had occurred in the wild. Because FMC serves as the central console for managing entire Cisco firewall fleets, a compromised instance can allow attackers to alter firewall rules, erase logs, and push malicious configurations across all managed devices.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in