Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks
-
Cisco has confirmed that a maximum-severity authentication bypass vulnerability in its Secure Firewall Management Center (FMC) software is being actively exploited in the wild. The flaw, tracked as CVE-2026-20079, allows an unauthenticated attacker to bypass authentication mechanisms on affected devices. Given the critical nature of the issue, Cisco has urged users to apply available patches immediately, noting that exploitation activity has already been observed.
The vulnerability impacts multiple versions of the Secure FMC platform. Specifically, affected releases include:
- Versions 7.4.1.2 and earlier in the 7.4 train
- Versions 7.6.0.2 and earlier in the 7.6 train
- Versions 7.8.0 in the 7.8 train
Cisco’s advisory indicates that the vulnerability stems from improper handling of authentication requests, which can be triggered remotely without any user interaction or prior credentials. The company has also noted that there are no workarounds that fully mitigate the issue, making patching the only reliable remediation step.
Administrators are strongly advised to upgrade to the fixed releases as specified in Cisco’s security advisory. As a precaution, organizations should also review their firewall management access logs for any suspicious or unauthorized activity, particularly if their systems are exposed to untrusted networks. Given the active exploitation status, prompt action is critical to prevent potential compromise of security infrastructure.
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login