What Happened
Cisco confirmed active exploitation of CVE-2026-20079, a maximum-severity authentication bypass in Secure Firewall Management Center. The flaw sits in the product’s web interface and stems from a system process created incorrectly at boot. An attacker with network access sends crafted HTTP requests to bypass login entirely, then executes scripts with root privileges on the device. Cisco Talos identifies three distinct activity clusters exploiting the bug, including state-sponsored operators and financially motivated groups, since attacks began in August. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on September 9 alongside a Citrix NetScaler authentication bypass and a Fortinet FortiOS buffer overflow, giving federal agencies until September 12 to patch all three. Cisco shipped hotfixes for FMC branches 7.0 through 7.7 and 10.0. No workaround closes the hole completely. Restricting management-interface access to trusted networks reduces exposure without eliminating it. Coverage is available from BleepingComputer.
Why This Matters for Canadian Organizations
Secure FMC sits at the center of firewall management for enterprises, universities, and government networks across Canada, often controlling policy for dozens of devices at once. Root access on the management platform hands an attacker the keys to the perimeter it exists to protect. Federally regulated institutions working under OSFI’s B-13 technology and cyber risk guideline face an expectation of accelerated remediation for internet-facing management interfaces once active exploitation is confirmed, and any resulting data exposure would trigger PIPEDA breach-notification duties. With three separate attacker groups already working the bug, the window for unpatched Canadian deployments narrows daily.
What to Do
Apply Cisco’s hotfixes immediately rather than waiting for a scheduled maintenance window. Confirm the FMC management interface sits off the public internet, and where it needs to remain exposed, restrict access with an interface access control list tied to known administrative addresses. Review FMC logs for unexpected script execution or new administrative accounts created since August, when Cisco says exploitation attempts began. Organizations without in-house detection capacity for this kind of activity should ask their managed security provider to confirm FMC devices sit under active monitoring. Additional technical detail is available from SecurityWeek.






