Cisco FMC authentication bypass CVE-2026-20079 has CVSS 10.0
Cisco Secure Firewall Management Center has a CVE-2026-20079 vulnerability rated CVSS 10.0: an unauthenticated attacker can gain root on the management console via an HTTP request. Cisco Talos confirmed exploitation on September 9, 2026, and CISA added the bug to its KEV catalog with a September 12 fix deadline.
- CVE-2026-20079 is a pre-auth bypass with CVSS 10.0 giving root on FMC
- Talos identified three attack clusters: UAT-12197, UAT-11823 and UAT-11988
- UAT-11823 is linked to Sandworm, UAT-11988 to Qilin ransomware
- CISA added the vulnerability to KEV, government deadline is September 12
Read next
Security