# Critical Cisco Secure FMC Vulnerability Actively Exploited, Agencies Urge Immediate Action

*Published September 11, 2026*
*Source: [https://www.securityweek.com/organizations-warned-of-cisco-secure-fmc-exploitation/](https://www.securityweek.com/organizations-warned-of-cisco-secure-fmc-exploitation/)*

## Executive Summary

*This is a Premium edition. The Executive Summary is available to sec-news.ai members —*
*[read it here](https://www.sec-news.ai/news/critical-cisco-secure-fmc-vulnerability-actively-exploited-agencies-urge-immediate-action) or [see plans](https://www.sec-news.ai/pricing).*

## Article

Cisco and the Cybersecurity and Infrastructure Security Agency (CISA) have issued an urgent warning regarding the active exploitation of a vulnerability in Cisco Secure Firewall Management Center (FMC). This security flaw, identified as CVE-2026-20079, allows remote attackers to bypass authentication and execute malicious scripts, potentially gaining root access to the affected systems. The vulnerability originates from an improper system process that occurs during the device's boot time. Attackers can exploit this flaw by sending specially crafted HTTP requests to the vulnerable systems.

Although Cisco released a patch for this vulnerability in March and updated its advisory in July with indicators of compromise, it was not until September that the company confirmed active exploitation had been detected in August. In response, CISA has now added this vulnerability to its Known Exploited Vulnerabilities catalog, mandating federal agencies to address it by mid-September.

To mitigate the risk of exploitation, Cisco FMC users are strongly advised to apply the available patches and ensure that their FMC interfaces are not accessible from the internet. Notably, CVE-2026-20079 is the third FMC vulnerability to be added to CISA’s list this year, alongside CVE-2026-20316 and CVE-2026-20131, both of which have been exploited as zero-days.

Cisco’s Talos research group has identified three activity clusters exploiting CVE-2026-20079 and CVE-2026-20316. These include state-sponsored threat actors and financially motivated groups. Among them, the cluster known as UAT-12197 has deployed a web shell to deliver a malicious JAR file, facilitating the extraction of user credentials. Another cluster, UAT-11823, involves the Russian APT group Sandworm, which has been using Cyclops Blink malware in its attacks. Finally, UAT-11988 is linked to the Qilin ransomware group, which has been exploiting FMC vulnerabilities for reconnaissance and credential theft.
