Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
Requested translation is not available. Showing the stored EN version.

What happened
Due to Talos identifying in the wild abuse of these CVE’s, customers are strongly advised to apply hotfixes for affected software versions already released by Cisco for CVE-2026-20079 and CVE-2026-20316 . Second, CVE-2026-20316 is a vulnerability that allows a remote attacker to log in using a low-privileged account.
CVE-2026-20079 is a critical vulnerability with a CVSS score of 10.0. Customers are strongly advised to follow Cisco’s guidance provided in the security advisory and apply the security patches previously made available.
CVE-2026-20316 has a CVSS score of 5.3, however it can be used with other Cisco Secure FMC vulnerabilities to elevate privileges. Subsequent actions and tactics, techniques, and procedures (TTPs) the threat actor used in the victim’s environment were consistent with those of Qilin ransomware affiliates.
Key facts
- Due to Talos identifying in the wild abuse of these CVE’s, customers are strongly advised to apply hotfixes for affected software versions already — released: by Cisco for CVE-2026-20079 and CVE-2026-20316
Sources & evidence
- Cisco Talos Primary / official
Active exploitation of Cisco Secure Firewall Management Center vulnerabilities ↗
https://blog.talosintelligence.com/fmc-ongoing-exploitation/