
Executive Security Advisory: Cisco Secure Firewall FMC CVE-2026-20079 – active exploitation confirmed
Management summary
On September 9, 2026, Cisco confirmed active exploitation of CVE-2026-20079 in Secure Firewall Management Center (FMC). The flaw allows an unauthenticated remote attacker to bypass authentication through the web interface and execute scripts and commands with root privileges. Affected systems should be upgraded immediately to a fixed Cisco release.
What is Cisco Secure Firewall Management Center?
FMC is Cisco's central management platform for Secure Firewalls. It is used to manage devices, firewall rules, security policies and events. A compromise of the management center can therefore have broad consequences for the firewall environment.
Why is this critical?
Exploitation is possible remotely without prior authentication. Successful attackers can obtain root access to the underlying operating system. Cisco rates the vulnerability CVSS 10.0 and confirms active exploitation since August 2026. Internet-exposed FMC management interfaces are particularly at risk.
What to do now
Priority 1: Upgrade immediately to a Cisco release listed as fixed. Priority 2: Ensure the FMC management interface is not directly exposed to the internet and restrict access to trusted management networks or VPN connections. Priority 3: Review Cisco's published indicators of compromise and involve Cisco TAC or your incident-response team if compromise is suspected.
What to ask your IT provider
Do we use Cisco Secure Firewall Management Center? Which version is installed and is CVE-2026-20079 fixed? Is the FMC web interface reachable from the internet? Have Cisco's indicators of compromise been checked?
Our assessment
This clearly warrants immediate action: unauthenticated remote exploitation, root privileges and confirmed active attacks affect a central security-management component. Patching and removing unnecessary internet exposure should be prioritized today.





