Cisco has released security updates addressing CVE-2026-20079. Users of affected Secure Firewall Management Center versions should upgrade to the latest patched releases immediately. Specific patch versions and download links are available in Cisco's security advisory PSA-2026-0282. As a defensive measure, restrict access to the FMC management interface to trusted networks and implement strong network segmentation.
Quick answers
What is CVE-2026-20079?
Cisco has released security updates addressing CVE-2026-20079. Users of affected Secure Firewall Management Center versions should upgrade to the latest patched releases immediately. Specific patch versions and download links are available in Cisco's security advisory PSA-2026-0282. As a defensive measure, restrict access to the FMC management interface to trusted networks and implement strong network segmentation.
How severe is CVE-2026-20079?
critical, CVSS 10
Is CVE-2026-20079 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-20079 be mitigated?
Cisco has released security updates addressing CVE-2026-20079. Users of affected Secure Firewall Management Center versions should upgrade to the latest patched releases immediately. Specific patch versions and download links are available in Cisco's security advisory PSA-2026-0282. As a defensive measure, restrict access to the FMC management interface to trusted networks and implement strong network segmentation.
CVSS
10
Vendor
Cisco
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
Secure Firewall Management Center (FMC)
Mitigation
Cisco has released security updates addressing CVE-2026-20079. Users of affected Secure Firewall Management Center versions should upgrade to the latest patched releases immediately. Specific patch versions and download links are available in Cisco's security advisory PSA-2026-0282. As a defensive measure, restrict access to the FMC management interface to trusted networks and implement strong network segmentation.
Cisco has confirmed that a maximum-severity authentication bypass vulnerability (CVE-2026-20079) in Secure Firewall Management Center (FMC) software is being actively exploited in attacks. The flaw allows unauthenticated remote attackers to bypass authentication controls and gain administrative access to the FMC web interface. Cisco has released security updates; users are urged to upgrade to patched versions immediately.