HomeIntelligenceBrief
VULNERABILITY BRIEF 🔴 Critical Vulnerability

Critical Authentication Bypass in Cisco FMC (CVE‑2026‑20079, CVE‑2026‑20316) Enables Remote Code Execution

Cisco Secure Firewall Management Center contains two critical authentication bypass flaws that are being exploited by nation‑state and ransomware actors. The vulnerabilities allow unauthenticated remote code execution, threatening privileged access and network control, and highlight the need for robust authentication controls and timely patch evidence for audit readiness.

Verisq™ Intelligence · 📅 September 10, 2026 · 📰 helpnetsecurity.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
2 recommended
📰
Source
helpnetsecurity.com

Critical Authentication Bypass in Cisco Secure Firewall Management Center (CVE‑2026‑20079, CVE‑2026‑20316) Enables Remote Code Execution

What It Is — Two separate flaws in the Cisco FMC web interface allow unauthenticated attackers to gain root‑level access. CVE‑2026‑20079 bypasses authentication via a crafted HTTP request; CVE‑2026‑20316 exploits hard‑coded low‑privilege credentials.

Exploitability — Both vulnerabilities are confirmed “exploited in the wild” and are being used by nation‑state (e.g., Sandworm) and ransomware groups. Public exploits and indicators of compromise are available.

Affected Products — Cisco Secure Firewall Management Center (FMC) software (all versions prior to the March 2026 and July 2026 patches).

Why It Matters for Trust & Control Assurance

  • Authentication controls – The flaws demonstrate how weak or missing authentication safeguards can undermine the entire network security stack, eroding the audit trail of who accessed management functions.
  • Continuous monitoring – Real‑time logging of FMC admin activity and credential use becomes essential evidence for a defensible security posture.
  • Patch management evidence – Demonstrating timely remediation of critical CVEs is a core control that satisfies multiple frameworks (e.g., NIST CSF Identify‑Protect, ISO 27001 A.12.6).

Recommended Actions

  1. Deploy Cisco’s March 2026 (CVE‑2026‑20079) and July 2026 (CVE‑2026‑20316) patches immediately on all FMC instances.
  2. Verify that the management interface is isolated from untrusted networks and enforce MFA for all admin accounts.
  3. Enable and forward detailed FMC authentication and command logs to a SIEM for continuous review.
  4. Conduct a rapid audit of privileged‑access controls and update your access‑control matrix.
  5. Document the remediation steps as evidence for audit readiness.

Source: Help Net Security article

📰 Original Source
https://www.helpnetsecurity.com/2026/09/10/cisco-fmc-exploited-cve-2026-20079-cve-2026-20316/

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →