Skip to content
See the World Through ScienceA project of ALLATRA

Cisco Says Attackers Are Exploiting a Flaw in Its Firewall Manager

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

Front of a Cisco Unified Computing System blade server chassis mounted in a black equipment rack, rows of status lights lit green.
A Cisco Unified Computing System blade chassis in a data center rack. The hardware shown is illustrative and is not the affected product; the flaw Cisco reported is in its Secure Firewall Management Center software."CiscoUCS" by Raysonho @ Open Grid Scheduler / Grid Engine, via wikimedia, CC-BY-SA-3.0 · CC-BY-SA-3.0

Cisco has confirmed that attackers are exploiting a flaw in its Secure Firewall Management Center software, and the U.S. Cybersecurity and Infrastructure Security Agency added the same vulnerability to its Known Exploited Vulnerabilities catalog on Sept. 9, 2026.

The vulnerability itself is not new: Cisco first published the advisory on March 4, 2026. What changed on Sept. 9 is the confirmation that it is being used in attacks, and the federal patching obligation that comes with the listing.

In version 2.5 of the advisory, published Sept. 9, Cisco said its Product Security Incident Response Team became aware of active exploitation of CVE-2026-20079 in August 2026. Cisco scores it 10.0 out of 10 on the industry's standard severity scale, CVSS, and rates the impact as critical. An unauthenticated, remote attacker could bypass authentication and obtain root access on an affected device, the advisory says.

The flaw affects Cisco Secure FMC Software and Cisco Security Cloud Control Firewall Management, regardless of how a device is configured. Cisco says the cloud-delivered Security Cloud Control service has already been fixed and needs no customer action, and that Firewall Device Manager, Secure Firewall ASA Software and Secure Firewall Threat Defense Software are not affected.

There are no workarounds. Cisco has released emergency patches, which it calls hot fixes, for the 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0 releases of Secure FMC Software, available from its Software Center. The company says the hot fixes prevent future exploitation and may not address an existing compromise, and it tells customers who suspect a device was exploited to contact the Cisco Technical Assistance Center.

CISA listed four vulnerabilities that day citing evidence of active exploitation: the Cisco flaw, CVE-2025-25249 in multiple Fortinet products, CVE-2026-19490 in Citrix NetScaler and CVE-2026-87491 in Google's Chromium V8. Binding Operational Directive 26-04 requires federal civilian agencies to prioritize rapid remediation of listed flaws on publicly exposed assets, CISA says, and the agency encourages all organizations to do the same.

Neither Cisco nor CISA names who is exploiting the flaw or how many organizations are affected.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

Cisco Says Attackers Are Exploiting a Flaw in Its Firewall Manager

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.