Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)

Used in attacksCriticalCVSS 10.0Help Net Security · Zeljka Zorz·

At a glance

Severity
CriticalCVSS 10.0
Used in attacks
Yes, 2 of 2 flaws named
Vendors and products
Cisco
Reported by
1 outlet

State-sponsored and financially-motivated attackers are actively exploiting CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC), which is used for centrally managing multiple Cisco Secure Firewall devices across a network. Two FMC vulnerabilities under active attack “Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software,” the company’s researchers confirmed on Wednesday. These are the above mentioned CVE-2026-20079 and CVE-2026-20316, which Cisco flagged … More → The post Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316) appeared first on Help Net Security .

We summarise and link; this source is not one we hold a licence to reproduce. Everything below is what CyberBrief adds: the vulnerabilities involved, whether they are being exploited, who is named, and who else covered it.

Vulnerabilities referenced

  • CVE-2026-2007910.0Critical

    Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management

    Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.

    Used in attacks

    Added to CISA's list 2026-09-09 · Exploit code published · Patch or advisory available

    Full record →
  • CVE-2026-20316Not scored yet

    Cisco Secure Firewall Management Center (FMC)

    Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.

    Used in attacksUsed by ransomware gangs

    Added to CISA's list 2026-07-29

    Full record →

Coverage

One outlet has carried this so far.

  1. Help Net SecurityEstablished SourceFirst reported

    2026-09-10 11:22 UTC

Related stories