Cisco warns of active exploitation of critical firewall management flaw

Cisco has confirmed that a maximum-severity authentication bypass vulnerability in its Secure Firewall Management Center software is being actively exploited. The flaw, tracked as CVE-2026-20079, allows unauthenticated remote attackers to execute commands with root privileges. Cisco has no workarounds and urges customers to upgrade, while CISA has added the bug to its known exploited vulnerabilities catalog.
The flaw originates from an improperly initialized system process at boot, enabling attackers to send malicious web requests to the device interface and gain root-level access. Although Cisco's security team only confirmed active exploitation in August, a log entry dated July 23 indicates attackers may have been leveraging the vulnerability weeks earlier.
This issue shares indicators of compromise with another actively exploited Secure FMC flaw, CVE-2026-20316, which involves hardcoded credentials. Cisco has issued hot fixes for both, but has not clarified whether they were used together, and explicitly states no workarounds exist, leaving software upgrades as the only mitigation.
Organizations relying on Cisco Secure Firewall Management Center to oversee network defenses could face severe operational disruption if attackers exploit this flaw. Unauthorized root-level access may allow adversaries to disable security controls, pivot into internal networks, or deploy persistent malware. Because no workarounds exist, affected enterprises and government agencies must prioritize rapid patching, though the tight federal deadline suggests urgency. The broader impact could include compromised network integrity for critical infrastructure, potentially affecting data confidentiality and service availability for downstream users.