Cisco has confirmed that a maximum-severity authentication bypass vulnerability in its Secure Firewall Management Center (FMC) is being actively exploited in the wild. The flaw, designated CVE-2026-20079, allows unauthenticated attackers to bypass authentication mechanisms in affected versions of the software.
What happened
The vulnerability affects Cisco Secure FMC, a centralized management platform for Cisco firewall appliances. Cisco disclosed the flaw after observing exploitation attempts, though the company has not released details about the scale or origin of the attacks. No patch is currently available, and Cisco has not specified when a fix will be released.
The company’s advisory states that successful exploitation could enable attackers to gain administrative access to the FMC interface, potentially allowing them to manipulate firewall policies, exfiltrate sensitive data, or deploy additional malicious payloads. The advisory does not indicate whether any customers have reported breaches resulting from the flaw.
What we don’t know yet
At this stage, Cisco has not provided a timeline for a patch or workaround. The company has also not disclosed whether the attacks are targeted or opportunistic, nor has it identified any specific threat actors involved. Details about the attack vectors used in the wild remain unclear, though the advisory suggests that exploitation requires network access to the FMC interface.
Companies mentioned
Automated pipeline · Security
Synthesized from 1 industry feed on 9 Sep 2026. Passed independent editor verification (score 95/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — Deduped batch of 1 candidates
- Checking for duplicates — New story No previously published or in-pipeline article covers this specific Cisco Secure FMC flaw.
- Checking for duplicates — New story pre_write:; No recent or in-pipeline article covers this specific Cisco Secure FMC flaw.
- Writing the article — Brief only thin sources; quick-read mode
- Writing the article — Draft created article_id=537 slug=cisco-secure-fmc-auth-bypass-under-active-attack quick_read=1
-
Editor review — Approved
- Score: 95/100
- Style compliance: Headline exceeds 90-character limit (92 characters). Shorten to meet style guide requirements.
- Factual grounding: The draft states 'No patch is currently available, and Cisco has not specified when a fix will be released,' but the source does not explicitly confirm the absence of a patch timeline. The source only states Cisco has not released details about the scale or origin of attacks. Omit or clarify the patch timeline claim.
- Style compliance: The section '## What we don’t know yet' is not one of the allowed section headings (e.g., 'What happened', 'Why it matters', 'What to watch'). Rename to comply with style guide.
- Generating reader Q&A — Generated 3 items
- Assigning hero image — Rejected library image #160: No candidate matches the article topic (Cisco Secure FMC auth bypass vulnerability). The provided candidate is unrelated to security, firewalls, or Cisco, and its alt text and URL slug do not indicate relevance to the article's subject.
- Assigning hero image — Reused library image reused image #1
- Linking related stories — Linked 4 relations from 468 candidates
- Publishing — Published cisco-secure-fmc-auth-bypass-under-active-attack
- Mastodon — Posted https://mstdn.social/@hostingpaper/117243535824452215




Discussion · coming soon
Be the first to join the thread when community discussion launches.