Cisco confirms active exploitation of CVE-2026-20079, a CVSS 10.0 auth bypass in Secure FMC
On September 9, 2026, Cisco confirmed that CVE-2026-20079, a CVSS 10.0 authentication bypass in Secure Firewall Management Center, is being actively exploited, even though a patch has existed since March. Network teams must patch immediately, then hunt for indicators of compromise before declaring a device healthy.