Critical Cisco FMC Authentication Bypass Vulnerability Under Active Exploitation

Critical Cisco FMC Authentication Bypass Vulnerability Under Active Exploitation

First seen 9 Sep 2026, 20:44 UTC Sec.Cloudapps.Ciscoblog.talosintelligence.comRedpacketsecurity 79.5

Article Content

Browse articles
ThreatCluster

Cisco's Secure Firewall Management Center (FMC) Software has a critical authentication bypass vulnerability (CVE-2026-20079) that allows unauthenticated remote attackers to execute scripts and gain root access to affected devices. This vulnerability is due to improper system processes created at boot time and can be exploited via crafted HTTP requests. Cisco has released patches, but active exploitation is confirmed, with attackers deploying web shells and other malicious tools. Another related vulnerability (CVE-2026-20316) allows low-privileged account logins and can be exploited in conjunction with CVE-2026-20079. Cisco advises immediate patching to mitigate risks. The vulnerabilities are particularly concerning for organizations with internet-facing management interfaces. Talos Intelligence has identified multiple clusters of exploitation linked to various threat actors, including ransomware operators.

Key Points: • CVE-2026-20079 allows unauthenticated remote access to Cisco FMC devices. • Active exploitation is confirmed, with attackers deploying web shells and malware. • Immediate patching is critical to mitigate risks associated with these vulnerabilities.

Ask AI about this cluster

Timeline

2026-03-04
CVE-2026-20079 published
Cisco disclosed a critical authentication bypass vulnerability in FMC Software.
Sec.Cloudapps.Cisco
2026-07-29
CVE-2026-20316 published
Cisco disclosed a vulnerability allowing remote login with low-privileged accounts.
blog.talosintelligence.com
2026-09-09
CVE-2026-20079 added to CISA KEV
CISA confirmed active exploitation of CVE-2026-20079 and added it to the KEV catalog.
blog.talosintelligence.com
2026-09-09
Cisco advises immediate patching
Cisco released security patches for both CVE-2026-20079 and CVE-2026-20316, urging customers to apply them.
Sec.Cloudapps.Cisco