Cisco Talos: Three Clusters Exploit Cisco FMC Vulnerabilities
Cisco Talos confirmed that two vulnerabilities in Cisco Secure Firewall Management Center (FMC) are being exploited by three clusters. Critical CVE-2026-20079 (CVSS 10.0) allows an unauthenticated attacker to bypass login and execute scripts with root privileges; CVE-2026-20316 (CVSS 5.3) involves static credentials. CISA added the first to its KEV catalog with a September 12, 2026 deadline.
- CVE-2026-20079: auth bypass and root code execution, CVSS 10.0
- CVE-2026-20316: static credentials for low-privilege account, CVSS 5.3
- UAT-11823 linked to Sandworm, UAT-11988 to Qilin ransomware
- Cisco released hotfixes July 31, consolidated release week of September 14
Read next
Security