Cisco Secure Firewall Management Center CVE-2026-20079 Authentication Bypass Actively Exploited—Enterprise Management-Plane Risk
Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is actively exploited in ongoing attacks. Because FMC acts as the control plane for managing deployed security appliances, successful exploitation can allow adversaries to gain unauthorized administrative access, tamper with security policies, and potentially pivot from the management environment to the broader network and connected security devices.
Threat Overview
CVE-2026-20079 is an authentication bypass flaw—meaning an attacker may be able to reach functionality that is normally restricted to authenticated users. Cisco’s confirmation of active exploitation elevates the risk from