Critical Cisco Firewall Management Flaw Exploited in Attacks


Cisco has alerted customers regarding a critical authentication bypass flaw inside the Secure Firewall Management Center (FMC) software that is being actively exploited in the attacks. 

The vulnerability, known as CVE-2026-20079, is given a maximum CVSS score 10.0, which makes it one of the most dangerous flaws impacting Cisco’s firewall management products. 

The flaw was first disclosed in March 2026 by Cisco, but on September 9, Cisco updated its security advisory to confirm about the active exploitation in August that its Product Security Incident Response Team (PSIRT) became aware about. Cisco has advised users to update impacted systems immediately. 

About the vulnerability

The flaw impacts the web interface of Cisco Secure Firewall Management Center Software. When an improper system process is created after the starting of the impacted device, it results in the flaw. 

The threat actor does not require authentic credentials to abuse the vulnerability. A remote attacker can escape verification by sending specially tailored HTTP requests to a compromised FMC device. 

Cisco has listed the problem as authentication bypass using a different channel or path, or CWE-288. As the flaw can be abused remotely without user interaction or verification, Cisco has given it a CVSS score of 10.0.

Impacted products

Vulnerable products

According to Cisco, regardless of device configuration, the flaw impacts Cisco Secure FMC Software and Cisco Security Cloud Control (SCC) Firewall Management.

Not vulnerable products

The following products are not impacted by the vulnerability:

  • Firewall Device Manager (FDM)
  • Secure Firewall Adaptive Security Appliance (ASA) Software
  • Secure Firewall Threat Defense (FTD) Software
  • Security Cloud Control (SCC), formerly Defense Orchestrator

Impact on organizations

The flaw could have severe impact for enterprises using Cisco Secure Firewall Management Center for managing their security infrastructure

If a threat actor gains root access, they may modify system configurations, install additional malware, use the infected management system as a base for future attacks and run malicious commands.

The vulnerability could have serious consequences for organizations using Cisco Secure Firewall Management Center to manage their security infrastructure.

An attacker who gains root access could potentially alter system configurations, execute malicious commands, install additional malware or use the compromised management system as a foothold for further attacks.

“To determine if this vulnerability may have been exploited, use the zgrep "package_info.*license" messages* CLI command in expert mode,” Cisco said. 

According to Cisco, if organizations suspect exploit, they should reach out to the Cisco Technical Assistance Center (TAC) for help with recovery options. 

This article has been indexed from CySecurity News – Latest Information Security and Hacking Incidents

Read the original article: