Maximum-severity Cisco firewall management flaw CVE-2026-20079 actively exploited, CISA sets federal patch deadline
A CVSS 10.0 authentication bypass in Cisco's Secure Firewall Management Center is being actively exploited, per Cisco's own advisory. CISA added it to its Known Exploited Vulnerabilities catalog with a September 12, 2026 federal patch deadline, alongside flaws in Citrix and Fortinet products.
A maximum-severity (CVSS 10.0) authentication bypass vulnerability, tracked as CVE-2026-20079, affects Cisco's $CSCO Secure Firewall Management Center (FMC) software. Cisco confirmed active exploitation beginning in August 2026, after first disclosing the flaw in March. The company said three distinct hacking clusters, internally tracked as UAT-12197, UAT-11823 and UAT-11988, used the bug to deploy web shells and malware on compromised devices. CISA added the flaw to its Known Exploited Vulnerabilities catalog, ordering US federal agencies to patch by September 12, 2026, alongside separately exploited flaws in Citrix NetScaler (CVSS 9.3) and Fortinet FortiOS (CVSS 7.3). Sources: The Hacker News, BleepingComputer.