Cybersecurity Research

Cisco Firewall Management Software Under Active Attack: Patch Now

Cisco Talos · 10 Sept 2026
Key Takeaway If your business uses Cisco Secure Firewall Management Center, apply the available hotfixes immediately and watch for Cisco's upcoming hardening update rather than waiting for a routine patch cycle.

Cisco Talos has identified real-world attacks exploiting two vulnerabilities in Cisco's Secure Firewall Management Center (FMC) Software. The more serious flaw, CVE-2026-20079, has a maximum severity score of 10.0 and lets an unauthenticated attacker bypass login controls, run scripts, and gain root access to the underlying system. A second flaw, CVE-2026-20316, scores lower at 5.3 but allows attackers to log in with a low-privileged account, and can be combined with other weaknesses to gain deeper access.

Talos has observed these vulnerabilities being used by multiple threat groups, including state-sponsored and financially motivated actors. In one case, attackers deployed web shells, a tool for executing commands, and stole credentials. In another, attackers used the flaws to install remote access tools and ultimately deployed a variant of Cyclops Blink, malware previously linked to the Russian state-backed group Sandworm.

Cisco has already released hotfixes for both vulnerabilities and is preparing a broader hardening update, expected the week of September 14th, that will address these issues along with other internally found flaws. Organisations running Secure FMC Software should treat this as urgent, given confirmed exploitation in the wild.

Summarised by CISO AI from Cisco Talos. We link back to every original so you can read it yourself.