<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks]]></title><description><![CDATA[<p dir="auto">Cisco has confirmed that a maximum-severity authentication bypass vulnerability in its Secure Firewall Management Center (FMC) software is being actively exploited in the wild. The flaw, tracked as <strong><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20079" target="_blank" rel="noopener noreferrer nofollow ugc">CVE-2026-20079</a></strong>, allows an unauthenticated attacker to bypass authentication mechanisms on affected devices. Given the critical nature of the issue, Cisco has urged users to apply available patches immediately, noting that exploitation activity has already been observed.</p>
<p dir="auto">The vulnerability impacts multiple versions of the Secure FMC platform. Specifically, affected releases include:</p>
<ul>
<li>Versions <strong>7.4.1.2</strong> and earlier in the 7.4 train</li>
<li>Versions <strong>7.6.0.2</strong> and earlier in the 7.6 train</li>
<li>Versions <strong>7.8.0</strong> in the 7.8 train</li>
</ul>
<p dir="auto">Cisco’s advisory indicates that the vulnerability stems from improper handling of authentication requests, which can be triggered remotely without any user interaction or prior credentials. The company has also noted that there are no workarounds that fully mitigate the issue, making patching the only reliable remediation step.</p>
<p dir="auto">Administrators are strongly advised to upgrade to the fixed releases as specified in Cisco’s security advisory. As a precaution, organizations should also review their firewall management access logs for any suspicious or unauthorized activity, particularly if their systems are exposed to untrusted networks. Given the active exploitation status, prompt action is critical to prevent potential compromise of security infrastructure.</p>
]]></description><link>https://xploitlk.com/topic/278/cisco-confirms-cve-2026-20079-secure-fmc-flaw-exploited-in-attacks</link><generator>RSS for Node</generator><lastBuildDate>Sat, 12 Sep 2026 05:50:30 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/278.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 09 Sep 2026 22:30:22 GMT</pubDate><ttl>60</ttl></channel></rss>