Cisco FMC Zero-Day Rated CVSS 10.0 Exploited by Three Threat Clusters
A critical pre-authentication remote code execution vulnerability, CVE-2026-20079, was discovered in Cisco Secure Firewall Management Center, carrying a maximum CVSS score of 10.0. Cisco Talos confirmed active exploitation on 9 September 2026, attributing attacks to three distinct intrusion clusters, including one linked to Sandworm and another to a Qilin ransomware affiliate. The flaw allows unauthenticated attackers to execute commands as root via a crafted HTTP request, with one cluster also chaining a second static credential vulnerability. External internet scanning tools returned near-zero results for exposed FMC instances, as the management console is typically kept behind VPNs or internal network segments rather than exposed publicly. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on 9 September 2026, setting a federal remediation deadline of 12 September 2026.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in