Cisco confirms that a maximum-severity authentication bypass vulnerability, CVE-2026-20079, affecting its Secure Firewall Management Center (FMC) software is being exploited in attacks. FMC is used to centrally manage multiple Cisco Secure Firewall devices across networks.
Multiple outlets report Cisco’s internal tracking indicates the exploitation involves actors with different motivations. Help Net Security says both state-sponsored attackers and ransomware operators are using FMC flaws. It also notes Cisco is actively tracking exploitation of more than one issue, identifying a second actively attacked vulnerability, CVE-2026-20316. Cisco’s confirmation in one report focuses specifically on CVE-2026-20079 as already under active exploitation.
Overall, the coverage aligns on the affected product area (Cisco Secure Firewall Management Center), the nature of the primary issue (an authentication bypass), and that exploitation is ongoing. Differences in emphasis reflect whether outlets spotlight only CVE-2026-20079 or also include the additional actively exploited CVE-2026-20316.