Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-10 ยท updated: 2026-09-10 ยท tags: [incident, cisco, secure-fmc, vulnerability, kev, active-exploitation] ยท confidence: verified ยท affected_sectors: [technology, government, financial-services] ยท au_impact: true

Cisco confirmed that CVE-2026-20079 โ€” a maximum-severity (CVSS 10.0) authentication-bypass vulnerability in its Secure Firewall Management Center (FMC) software โ€” was being actively exploited, allowing unauthenticated remote attackers to execute scripts and commands as root on vulnerable devices via crafted HTTP requests to the web interface. Cisco's PSIRT became aware of exploitation in August, though indicators released in a July advisory for the related static-credential flaw CVE-2026-20316 (with an example log entry dated July 23) suggested both vulnerabilities may have been used in the same attacks as early as July. There is no workaround; Cisco patched the cloud-hosted Security Cloud Control service and pushed hot fixes, and on 9 September CISA added the flaw to its Known Exploited Vulnerabilities catalogue, ordering federal civilian agencies to patch by 12 September.

Attribute Detail
Date Confirmed 2026-09-09
Type Auth-bypass RCE, exploited in the wild
CVE CVE-2026-20079 (CVSS 10.0); related CVE-2026-20316
KEV order FCEB patch by 2026-09-12
Source Cisco / CISA โ€” Tier 1/4

Source