Cisco FMC CVE-2026-20079: CVSS 10.0 auth bypass exploited in the wild
Cisco confirmed exploitation of CVE-2026-20079 in Secure Firewall Management Center: an authentication bypass in the management interface rated CVSS 10.0 allows root code execution. CISA added it to the KEV catalog on September 9, giving federal agencies until September 12 to patch. Talos linked the activity to three clusters, including Sandworm and Qilin ransomware delivery.
- CVSS 10.0: crafted HTTP request bypasses auth regardless of device configuration
- CISA added the CVE to KEV on September 9 with a three-day deadline
- Cluster UAT-11823 assessed as linked to Sandworm and Cyclops Blink
- Affected FMC branches: 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0
Read next
Security