Cisco Talos confirmed on September 10, 2026, that CVE-2026-20079 and CVE-2026-20316, maximum-severity vulnerabilities in Cisco Secure Firewall Management Center (FMC), were being actively exploited by state-sponsored actors, ransomware gangs, and financially motivated threat groups. CISA added CVE-2026-20079 to its Known Exploited Vulnerabilities list on September 9.
25 reports · 24 independentother · tech
Claim audit
No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.
Cisco Talos reports active exploitation of CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center by threat actors deploying malware, web shells, and ransomware. Customers are strongly urged to apply security patches immediately to prevent unauthorized access and potential compromise. https:// blog.talosintelligence.com/fmc -ongoing-exploitation/
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched instances of Cisco’s Secure FMC Software, which allows an unauthenticated, remote attacker to bypass authentications and execute scripts on impacted devices to obtain root access to the und
Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. [...]
Cisco confirmed attackers are exploiting CVE-2026-20079, a maximum-severity authentication bypass flaw in Cisco Secure Firewall Management Center software. The flaw has a CVSS score of 10.0 and can let an unauthenticated remote attacker run scripts and commands as root on vulnerable devices [talosintelligence.com#1][bleepingcomputer.com#1][reddit.com#1]. Cisco Talos said it is also tracking exploi
Cisco confirms CVE-2026-20079 in Secure Firewall Management Center is actively exploited by APT Sandworm and Qilin ransomware affiliates. The maximum-severity flaw https:// deafnews.it/en/article/cisco-c onfirms-cve-2026-20079-in-fmc-actively-exploited-by-sandworm-and-qilin
Cisco confirmed active exploitation of CVE-2026-20079, a CVSS 10.0 authentication bypass in Secure FMC. Unauthenticated remote attackers can execute commands as root via crafted HTTP requests, compromising firewall management. Immediate patching and exposure review are critical. # CiscoFmc # AuthBypass # CriticalVulnerability https:// cyberworldops.eu/en/cisco-secu re-fmc-authentication-bypass-exp
Cisco Secure Firewall Management Center Under Active Attack Cisco Talos warns of active exploitation of two vulnerabilities (CVE-2026-20079 and CVE-2026-20316) in Secure Firewall Management Center, allowing attackers to gain root access and deploy malware like Cyclops Blink and Qilin ransomware. **If you run Cisco Secure Firewall Management Center (versions 7.0.x, 7.1.x, or 7.2–7.7), apply Cisco's
Your firewall management plane has a CVSS 10.0 root vulnerability, and the attackers have been inside for six weeks. Cisco confirmed active exploitation of CVE-2026-20079 in Secure Firewall Management Center this week. Unauthenticated. No credentials. Root on the box. No workaround. The web interface is the entry point. The compromised system is the one that pushes policy to every firewall you own
The vulnerability has a maximum CVSS score of 10.0 and allows unauthenticated, remote attackers to bypass authentication and execute scripts and commands as root on vulnerable devices. https://www. bleepingcomputer.com/news/secu rity/cisco-confirms-cve-2026-20079-secure-fmc-flaw-exploited-in-attacks/
🤖 CISA adds three actively exploited flaws (Cisco, Citrix, Fortinet) to its KEV catalog. Cisco's CVE-2026-20079 (CVSS 10.0) is an authentication bypass. Federal agencies must patch by Sept 12. 🔗 https:// thehackernews.com/2026/09/cisa -flags-exploited-cisco-citrix.html # CVE # KEV # CyberSec
Cisco Talos said state-sponsored and financially motivated attackers exploited two Cisco Secure Firewall Management Center vulnerabilities to compromise enterprise firewall management systems. The flaws include CVE-2026-20079, a maximum-severity authentication bypass flaw, and CVE-2026-20316, a static-credential flaw affecting FMC’s web interface [bleepingcomputer.com#1][cybersecuritynews.com#1][h
Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. [...]
Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. https://www. bleepingcomputer.com/news/secu rity/cisco-fmc-flaws-exploited-by-ransomware-gang-state-sponsored-hackers/
Cisco Talos reports active exploitation of CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center by Qilin ransomware, credential-theft actors, and Sandworm-linked groups. The auth bypass provides root command execution and the static credential exposure broadens initial access. # CiscoFMC # ThreatIntelligence # VulnerabilityManagement # Qilin https:// cyberworldops.eu/en/cis
Three threat clusters, including state-sponsored actors and Qilin ransomware affiliates, have exploited two critical Cisco FMC vulnerabilities to deploy web shells, Cyclops Blink malware, and steal sensitive credentials. Cisco has confirmed the exploitation of CVE-2026-20079 and CVE-2026-20316 and urges all customers to install the released hotfixes immediately. https://www. bleepingcomputer.com/n
CVE-2026-20316 - Changed to Known Ransomware Status Cisco Secure Firewall Management Center Use of Hard-coded Password VulnerabilityVendor: CiscoProduct: Secure Firewall Management Center (FMC)Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in
🔵 THREAT INTELLIGENCE Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware Vulnerability | CRITICAL CVEs: CVE-2026-20079 Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters... Full analysis: https://www. yazoul.net/news/article/cisco- fmc-flaws-exploited-to-steal-credentials-and-d
CISA put CVE-2026-20079 on the Known Exploited Vulnerabilities list on September 9, and if you're running a Cisco Secure Firewall Management Center (FMC) or Security Cloud Control (SCC), you've got a federal patch… https:// theperimetersite.com/report/250 # vulnerability # infosec