Cisco Firewall Management Center vulnerabilities actively exploited

Cisco Talos confirmed on September 10, 2026, that CVE-2026-20079 and CVE-2026-20316, maximum-severity vulnerabilities in Cisco Secure Firewall Management Center (FMC), were being actively exploited by state-sponsored actors, ransomware gangs, and financially motivated threat groups. CISA added CVE-2026-20079 to its Known Exploited Vulnerabilities list on September 9.

25 reports · 24 independentother · tech

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

Cisco Talos reports active exploitation of CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center by threat actors deploying malware, web shells, and ransomware. Customers are st

mastodon:infosec-exchangeother20d ago kagi ↗

Cisco Talos reports active exploitation of CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center by threat actors deploying malware, web shells, and ransomware. Customers are strongly urged to apply security patches immediately to prevent unauthorized access and potential compromise. https:// blog.talosintelligence.com/fmc -ongoing-exploitation/

Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in

mastodon:infosec-exchangeother19d ago kagi ↗

Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched instances of Cisco’s Secure FMC Software, which allows an unauthenticated, remote attacker to bypass authentications and execute scripts on impacted devices to obtain root access to the und

Cisco confirms active exploitation of Secure FMC flaws

kite:cybersecurityother19d ago kagi ↗

Cisco confirmed attackers are exploiting CVE-2026-20079, a maximum-severity authentication bypass flaw in Cisco Secure Firewall Management Center software. The flaw has a CVSS score of 10.0 and can let an unauthenticated remote attacker run scripts and commands as root on vulnerable devices [talosintelligence.com#1][bleepingcomputer.com#1][reddit.com#1]. Cisco Talos said it is also tracking exploi

Cisco confirms CVE-2026-20079 in Secure Firewall Management Center is actively exploited by APT Sandworm and Qilin ransomware affiliates. The maximum-severity flaw https:// deafnews.it/en/article/cisc

mastodon:infosec-exchangeother19d ago kagi ↗

Cisco confirms CVE-2026-20079 in Secure Firewall Management Center is actively exploited by APT Sandworm and Qilin ransomware affiliates. The maximum-severity flaw https:// deafnews.it/en/article/cisco-c onfirms-cve-2026-20079-in-fmc-actively-exploited-by-sandworm-and-qilin

Cisco confirmed active exploitation of CVE-2026-20079, a CVSS 10.0 authentication bypass in Secure FMC. Unauthenticated remote attackers can execute commands as root via crafted HTTP requests, comprom

mastodon:infosec-exchangeother19d ago kagi ↗

Cisco confirmed active exploitation of CVE-2026-20079, a CVSS 10.0 authentication bypass in Secure FMC. Unauthenticated remote attackers can execute commands as root via crafted HTTP requests, compromising firewall management. Immediate patching and exposure review are critical. # CiscoFmc # AuthBypass # CriticalVulnerability https:// cyberworldops.eu/en/cisco-secu re-fmc-authentication-bypass-exp

🤖 Cisco confirms CVE-2026-20079: maximum-severity authentication bypass in Secure Firewall Management Center (FMC), now actively exploited in attacks. Administrators should prioritize patching affect

mastodon:infosec-exchangeother19d ago kagi ↗

🤖 Cisco confirms CVE-2026-20079: maximum-severity authentication bypass in Secure Firewall Management Center (FMC), now actively exploited in attacks. Administrators should prioritize patching affected deployments. 🔗 https://www. bleepingcomputer.com/news/secu rity/cisco-confirms-cve-2026-20079-secure-fmc-flaw-exploited-in-attacks/ # CVE # Cisco # CyberSec

Cisco Secure Firewall Management Center Under Active Attack Cisco Talos warns of active exploitation of two vulnerabilities (CVE-2026-20079 and CVE-2026-20316) in Secure Firewall Management Center, al

mastodon:infosec-exchangeother19d ago kagi ↗

Cisco Secure Firewall Management Center Under Active Attack Cisco Talos warns of active exploitation of two vulnerabilities (CVE-2026-20079 and CVE-2026-20316) in Secure Firewall Management Center, allowing attackers to gain root access and deploy malware like Cyclops Blink and Qilin ransomware. **If you run Cisco Secure Firewall Management Center (versions 7.0.x, 7.1.x, or 7.2–7.7), apply Cisco's

Your firewall management plane has a CVSS 10.0 root vulnerability, and the attackers have been inside for six weeks. Cisco confirmed active exploitation of CVE-2026-20079 in Secure Firewall Management

mastodon:infosec-exchangeother19d ago kagi ↗

Your firewall management plane has a CVSS 10.0 root vulnerability, and the attackers have been inside for six weeks. Cisco confirmed active exploitation of CVE-2026-20079 in Secure Firewall Management Center this week. Unauthenticated. No credentials. Root on the box. No workaround. The web interface is the entry point. The compromised system is the one that pushes policy to every firewall you own

The vulnerability has a maximum CVSS score of 10.0 and allows unauthenticated, remote attackers to bypass authentication and execute scripts and commands as root on vulnerable devices. https://www. bl

mastodon:infosec-exchangeother19d ago kagi ↗

The vulnerability has a maximum CVSS score of 10.0 and allows unauthenticated, remote attackers to bypass authentication and execute scripts and commands as root on vulnerable devices. https://www. bleepingcomputer.com/news/secu rity/cisco-confirms-cve-2026-20079-secure-fmc-flaw-exploited-in-attacks/

🤖 CISA adds three actively exploited flaws (Cisco, Citrix, Fortinet) to its KEV catalog. Cisco's CVE-2026-20079 (CVSS 10.0) is an authentication bypass. Federal agencies must patch by Sept 12. 🔗 htt

mastodon:infosec-exchangeother19d ago kagi ↗

🤖 CISA adds three actively exploited flaws (Cisco, Citrix, Fortinet) to its KEV catalog. Cisco's CVE-2026-20079 (CVSS 10.0) is an authentication bypass. Federal agencies must patch by Sept 12. 🔗 https:// thehackernews.com/2026/09/cisa -flags-exploited-cisco-citrix.html # CVE # KEV # CyberSec

Cisco says hackers exploited FMC flaws

kite:cybersecurityother19d ago kagi ↗

Cisco Talos said state-sponsored and financially motivated attackers exploited two Cisco Secure Firewall Management Center vulnerabilities to compromise enterprise firewall management systems. The flaws include CVE-2026-20079, a maximum-severity authentication bypass flaw, and CVE-2026-20316, a static-credential flaw affecting FMC’s web interface [bleepingcomputer.com#1][cybersecuritynews.com#1][h

Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. ht

mastodon:infosec-exchangeother19d ago kagi ↗

Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. https://www. bleepingcomputer.com/news/secu rity/cisco-fmc-flaws-exploited-by-ransomware-gang-state-sponsored-hackers/

Cisco Talos reports active exploitation of CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center by Qilin ransomware, credential-theft actors, and Sandworm-linked groups. The au

mastodon:infosec-exchangeother19d ago kagi ↗

Cisco Talos reports active exploitation of CVE-2026-20079 and CVE-2026-20316 in Cisco Secure Firewall Management Center by Qilin ransomware, credential-theft actors, and Sandworm-linked groups. The auth bypass provides root command execution and the static credential exposure broadens initial access. # CiscoFMC # ThreatIntelligence # VulnerabilityManagement # Qilin https:// cyberworldops.eu/en/cis

Three threat clusters, including state-sponsored actors and Qilin ransomware affiliates, have exploited two critical Cisco FMC vulnerabilities to deploy web shells, Cyclops Blink malware, and steal se

mastodon:infosec-exchangeother19d ago kagi ↗

Three threat clusters, including state-sponsored actors and Qilin ransomware affiliates, have exploited two critical Cisco FMC vulnerabilities to deploy web shells, Cyclops Blink malware, and steal sensitive credentials. Cisco has confirmed the exploitation of CVE-2026-20079 and CVE-2026-20316 and urges all customers to install the released hotfixes immediately. https://www. bleepingcomputer.com/n

🤖 Cisco Talos: three threat clusters (ransomware + state-sponsored) exploited two patched Cisco Secure Firewall Management Center flaws — CVE-2026-20079 and CVE-2026-20316 — in the wild. Patch FMC de

mastodon:infosec-exchangeother18d ago kagi ↗

🤖 Cisco Talos: three threat clusters (ransomware + state-sponsored) exploited two patched Cisco Secure Firewall Management Center flaws — CVE-2026-20079 and CVE-2026-20316 — in the wild. Patch FMC deployments now. 🔗 https://www. bleepingcomputer.com/news/secu rity/cisco-fmc-flaws-exploited-by-ransomware-gang-state-sponsored-hackers/ # CyberSec # CVE # Exploit # Cisco

CVE-2026-20316 - Changed to Known Ransomware Status Cisco Secure Firewall Management Center Use of Hard-coded Password VulnerabilityVendor: CiscoProduct: Secure Firewall Management Center (FMC)Cisco S

mastodon:infosec-exchangeother18d ago kagi ↗

CVE-2026-20316 - Changed to Known Ransomware Status Cisco Secure Firewall Management Center Use of Hard-coded Password VulnerabilityVendor: CiscoProduct: Secure Firewall Management Center (FMC)Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in

🤖 Cisco FMC auth bypass (CVE-2026-20079, CVSS 10.0) actively exploited: three threat clusters — ransomware and state-sponsored — steal credentials and deploy Qilin ransomware on unpatched FMC applian

mastodon:infosec-exchangeother18d ago kagi ↗

🤖 Cisco FMC auth bypass (CVE-2026-20079, CVSS 10.0) actively exploited: three threat clusters — ransomware and state-sponsored — steal credentials and deploy Qilin ransomware on unpatched FMC appliances. 🔗 https:// thehackernews.com/2026/09/cisc o-fmc-flaws-exploited-to-steal.html # CVE # Ransomware # CyberSec

Reward: You've unlocked the Mandatory Remediation Sprint — a stackable negative buff. Enjoy your weekend. https:// tech-insider.org/cisco-fmc-cve -2026-20079-sandworm-qilin-2026 # CiscoFMC # CyberSecu

mastodon:infosec-exchangeother18d ago kagi ↗

Reward: You've unlocked the Mandatory Remediation Sprint — a stackable negative buff. Enjoy your weekend. https:// tech-insider.org/cisco-fmc-cve -2026-20079-sandworm-qilin-2026 # CiscoFMC # CyberSecurity # CriticalVulnerability # Ransomware # CVSS10 # BudgetJustified (3/3)

🔵 THREAT INTELLIGENCE Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware Vulnerability | CRITICAL CVEs: CVE-2026-20079 Cisco Talos says two recently patched Secure Firewall Ma

mastodon:infosec-exchangeother17d ago kagi ↗

🔵 THREAT INTELLIGENCE Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware Vulnerability | CRITICAL CVEs: CVE-2026-20079 Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters... Full analysis: https://www. yazoul.net/news/article/cisco- fmc-flaws-exploited-to-steal-credentials-and-d

CISA put CVE-2026-20079 on the Known Exploited Vulnerabilities list on September 9, and if you're running a Cisco Secure Firewall Management Center (FMC) or Security Cloud Control (SCC), you've got a

mastodon:infosec-exchangeother17d ago kagi ↗

CISA put CVE-2026-20079 on the Known Exploited Vulnerabilities list on September 9, and if you're running a Cisco Secure Firewall Management Center (FMC) or Security Cloud Control (SCC), you've got a federal patch… https:// theperimetersite.com/report/250 # vulnerability # infosec