Cisco Says Attackers Are Exploiting a Flaw in Its Firewall Manager

Cisco has confirmed that attackers are exploiting a flaw in its Secure Firewall Management Center software, and the U.S. Cybersecurity and Infrastructure Security Agency added the same vulnerability to its Known Exploited Vulnerabilities catalog on Sept. 9, 2026.
The vulnerability itself is not new: Cisco first published the advisory on March 4, 2026. What changed on Sept. 9 is the confirmation that it is being used in attacks, and the federal patching obligation that comes with the listing.
In version 2.5 of the advisory, published Sept. 9, Cisco said its Product Security Incident Response Team became aware of active exploitation of CVE-2026-20079 in August 2026. Cisco scores it 10.0 out of 10 on the industry's standard severity scale, CVSS, and rates the impact as critical. An unauthenticated, remote attacker could bypass authentication and obtain root access on an affected device, the advisory says.
The flaw affects Cisco Secure FMC Software and Cisco Security Cloud Control Firewall Management, regardless of how a device is configured. Cisco says the cloud-delivered Security Cloud Control service has already been fixed and needs no customer action, and that Firewall Device Manager, Secure Firewall ASA Software and Secure Firewall Threat Defense Software are not affected.
There are no workarounds. Cisco has released emergency patches, which it calls hot fixes, for the 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0 releases of Secure FMC Software, available from its Software Center. The company says the hot fixes prevent future exploitation and may not address an existing compromise, and it tells customers who suspect a device was exploited to contact the Cisco Technical Assistance Center.
CISA listed four vulnerabilities that day citing evidence of active exploitation: the Cisco flaw, CVE-2025-25249 in multiple Fortinet products, CVE-2026-19490 in Citrix NetScaler and CVE-2026-87491 in Google's Chromium V8. Binding Operational Directive 26-04 requires federal civilian agencies to prioritize rapid remediation of listed flaws on publicly exposed assets, CISA says, and the agency encourages all organizations to do the same.
Neither Cisco nor CISA names who is exploiting the flaw or how many organizations are affected.
