A maximum-severity flaw in Cisco's Secure Firewall Management Center software is being actively exploited by both ransomware gangs and state-sponsored hacking groups, and there is no workaround.
- What it is: CVE-2026-20079 is a maximum-severity (CVSS 10.0) authentication bypass in Cisco Secure Firewall Management Center (FMC), letting an attacker run commands as root without logging in.
- Who is affected: Any business running Cisco Secure FMC to manage firewall infrastructure, particularly appliances exposed to the internet.
- What the risk is: A Sandworm-linked group and a Qilin ransomware affiliate are among those exploiting this flaw to install web shells, harvest credentials and maintain long-term access. There is no workaround, only a software upgrade.
- What action is needed: Apply Cisco's fix immediately. If your FMC has been exposed to the internet, ask your IT provider to check system logs for signs of compromise, as the fix alone will not remove an existing intrusion.
If your business runs Cisco Secure FMC, we recommend treating this as urgent and confirming with your IT provider that the update has been applied and the device checked for compromise.
Source: BleepingComputer