Cisco’s Firewall Manager Is Being Hacked. CVSS 10.0 Gives Attackers Root
- The Mess: Cisco confirmed active exploitation of CVE-2026-20079 in Secure Firewall Management Center. The bug bypasses authentication and can hand an unauthenticated attacker root access to the underlying system.
- The Damage: Compromise the management plane and the attacker is sitting next to the controls that manage the firewall infrastructure.
- The Fix: Patch the FMC immediately, restrict its management interface, and investigate exposed systems for compromise.
The Bug
CVE-2026-20079 carries a CVSS score of 10.0 and affects the web interface of Cisco Secure Firewall Management Center.
The problem is an authentication bypass. An attacker does not need valid credentials to reach the vulnerable functionality. Cisco says its PSIRT became aware of active exploitation in August 2026.
That changes the priority completely.
This is not a theoretical “patch it during the next maintenance window” vulnerability. Attackers are already using it.
The Second Problem
CVE-2026-20079 is not the only issue.
Cisco also disclosed CVE-2026-20316, a static-credential vulnerability affecting the FMC web interface. It allows an unauthenticated remote attacker to log in using credentials embedded in the software and obtain access as a low-privileged user. Cisco rates it CVSS 5.3, but explicitly warns that it can be combined with other FMC vulnerabilities to elevate privileges.
In other words, the lower CVSS score does not make this one irrelevant.
An attacker targeting an internet-exposed FMC has multiple pieces to work with.
Why FMC Is a Bad Place to Lose Control
Secure Firewall Management Center is not some forgotten web application sitting beside the real infrastructure.
It is the management layer for Cisco firewall deployments.
Compromise the management system and the attacker potentially gains a far more valuable position than simply compromising one endpoint. Firewall policies, network segmentation, security controls and administrative operations are all concentrated around this layer.
That makes an authentication bypass here particularly nasty.
And if the attacker reaches the underlying operating system with root privileges, the incident stops being “a vulnerable web interface” and becomes a management-plane compromise.
What Defenders Should Do
Patch affected FMC installations using Cisco’s fixed software immediately.
Then check whether the management interface has been exposed to the public Internet. Cisco specifically notes that restricting public access reduces the attack surface for the static-credential vulnerability.
After patching, don’t stop there.
Review authentication logs, administrator activity, unexpected configuration changes and suspicious connections from the FMC itself. A successful exploit may leave a much larger problem than the vulnerable endpoint suggests.
Bugstoday Opinion
A firewall is supposed to be the thing standing between attackers and the network.
When the management system controlling that firewall has a CVSS 10.0 authentication bypass and is being exploited, the joke writes itself.
The lesson is brutally simple: never treat the firewall management plane as just another admin webpage.
Patch it. Isolate it. Monitor it.
Because once attackers own the thing writing your firewall rules, the firewall is no longer your defense.
Today’s Bugs. Tomorrow’s Breaches.
Technical Sources
Cisco Security Advisory — CVE-2026-20079
Cisco Security Advisory — CVE-2026-20316
Cisco PSIRT
CVE.org
BleepingComputer




