Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)
State-sponsored and financially-motivated attackers are actively exploiting CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC), which is used for centrally managing multiple Cisco Secure Firewall devices across a network. Two FMC vulnerabilities under active attack “Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software,” the company’s researchers confirmed on Wednesday. These are the above mentioned CVE-2026-20079 and CVE-2026-20316, which Cisco flagged … More → The post Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316) appeared first on Help Net Security .
We summarise and link; this source is not one we hold a licence to reproduce. Everything below is what NexaPulse adds: the vulnerabilities involved, whether they are being exploited, who is named, and who else covered it.
At a glance
- Severity
- Criticalhighest referenced CVSS 10.0
- Exploitation
- Confirmed — 2 of 2 referenced vulnerabilities are on the CISA Known Exploited Vulnerabilities catalogue
- Vulnerabilities
- CVE-2026-20079CVE-2026-20316
- Vendors & products
- Cisco
- Threat actors & malware
- None named
- Industries
- Not industry-specific
- Coverage
- 1 outlet· first seen 2026-09-10 11:22 UTC
- Priority
- 98/100Source tier, category, exploitation and corroboration. Not a risk score for your environment.
Vulnerabilities referenced
- CVE-2026-20079Exploited· due 2026-09-12Critical10.0
Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
Added to KEV 2026-09-09
Full record → - CVE-2026-20316Exploited· due 2026-08-01
Cisco Secure Firewall Management Center (FMC)
Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.
Used in ransomware · Added to KEV 2026-07-29
Full record →
Coverage
One outlet has carried this so far.
2026-09-10 11:22 UTC
Related stories
- OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
The Hacker News · 2026-09-12
- GitLab security advisory (AV26-917)
Canadian Centre for Cyber Security · 2026-09-11
- Hackers abused Claude to extract secrets from 1.8M Android apps
BleepingComputer · 2026-09-11
- n8n security advisory (AV26-916)
Canadian Centre for Cyber Security · 2026-09-11
- Progress security advisory (AV26-915)
Canadian Centre for Cyber Security · 2026-09-11