Cisco Firewall Management Console Flaw CVE-2026-20079 Rated 10.0, Actively Exploited
A critical authentication bypass vulnerability, CVE-2026-20079, has been identified in Cisco's Secure Firewall Management Center (FMC), receiving a maximum CVSS score of 10.0. The flaw allows attackers to access the FMC management interface without any credentials, potentially granting control over every firewall the console manages. Cisco confirmed that both nation-state actors and ransomware groups have been actively exploiting the vulnerability in unpatched deployments. A patch was initially released in March 2026, but organizations that had not applied it remained exposed to subsequent exploitation. Administrators are urged to apply the patch immediately, restrict management interface access to trusted networks, rotate stored credentials, and preserve logs on external systems to ensure reliable evidence in the event of a breach.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.



Discussion (0)
Log in to join the discussion and vote.
Log in