$ techbeacon▋
CVE & Exploits

Cisco admits active exploitation of high‑severity FMC authentication bypass flaw

Cisco admits active exploitation of high‑severity FMC authentication bypass flaw

Cisco Systems has confirmed that a critical authentication bypass vulnerability identified as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is currently being leveraged by threat actors in active attacks.

Secure FMC is the centralized console that administrators use to configure, monitor, and manage Cisco firewalls across enterprise networks. Because it handles privileged access to firewall policies, any compromise of the management platform can cascade to the underlying security infrastructure.

The CVE‑2026‑20079 flaw allows an unauthenticated attacker to bypass normal login checks and gain administrative rights within the FMC console. Exploitation of the defect could enable adversaries to modify firewall rules, intercept traffic, or deploy additional malicious payloads, effectively undermining the protective barrier that the firewalls are meant to provide.

According to the information disclosed, the vulnerability is not merely theoretical; it is being exploited in the wild. While Cisco has not released detailed indicators of compromise, it warned that attackers are able to reach vulnerable FMC instances over the network and execute the bypass without needing prior credentials.

In response, Cisco has issued an emergency security advisory and released patches that remediate the authentication bypass. The company urged all customers running affected versions of Secure FMC to apply the updates immediately and to review any anomalous activity that could indicate prior exploitation.

Security experts note that the episode underscores a broader trend of attackers targeting management and orchestration tools, which often sit at the heart of network defenses. Similar high‑severity flaws have emerged in other vendors' management platforms in recent months, raising concerns about the attack surface presented by centralized control interfaces.

Organizations are advised to follow Cisco’s mitigation steps, which include disabling unnecessary remote access to the FMC console, enforcing strong network segmentation, and enabling multi‑factor authentication where possible. Continuous monitoring for unusual login attempts and rapid application of security updates are also recommended.

Cisco indicated that it will continue to work with the security community to track any further exploitation attempts and to provide additional guidance as needed. The confirmation of active exploitation serves as a reminder that timely patch management remains a critical component of cyber‑defence strategies.

Threat Desk — Threat desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related