Hackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware
Cisco Talos has confirmed active exploitation of two vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software, the central console used by administrators to manage fleets of Cisco firewalls. The more severe flaw, tracked as CVE-2026-20079, carries a perfect CVSS score of 10.0 and allows an unauthenticated remote attacker to bypass login controls entirely, stemming from an improper system process created when an FMC device boots up. State-sponsored hacking groups and a ransomware affiliate have leveraged the flaws to seize root access, plant malware, and stage attacks on enterprise networks. BleepingComputer reports that a ransomware gang and state-linked actors are among those exploiting the vulnerabilities. The disclosure marks one of the year's more serious enterprise security incidents given FMC's role as the management hub for Cisco firewall deployments. Cisco Talos confirmed the active exploitation, though the company has not yet released full remediation details in the available reporting.
Global Impact
Economic: Enterprises face urgent patching costs, potential ransomware payouts, and business interruption losses; Cisco may see reputational damage and increased scrutiny of its security development lifecycle. Technological: The incident underscores the systemic risk of centralized management consoles—compromise of one FMC can expose an entire firewall fleet, potentially accelerating adoption of zero-trust architectures and segmented management planes.
Why this score
- Score
- 7.0/10
- Tier
- Significant
A perfect 10.0 CVSS vulnerability in Cisco's central firewall management console, actively exploited by both state-sponsored groups and a ransomware affiliate, creates immediate enterprise-wide risk for a large installed base; this is a Significant-tier event (55-74) due to its broad attack surface and confirmed in-the-wild exploitation, though it falls short of Major because it is a vendor-specific flaw rather than a systemic internet infrastructure collapse.
Across the sources
Agreed
- Cisco Talos confirmed active exploitation of vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software.
- The flaws allow attackers to gain root access and deploy malware on enterprise networks.
- Both state-sponsored hacking groups and a ransomware affiliate are exploiting the vulnerabilities.
Single-outlet claims
- BleepingComputer
- A ransomware gang and state-linked actors are exploiting the Cisco FMC flaws.
Sources on this story
- Total
- 2 sources
Score in context
| Story | Score | Tier | Date |
|---|---|---|---|
| OpenAI begins rolling out new GPT model | 6.6 | Significant | September 3, 2026 |
| CISA Warns of Actively Exploited Critical Citrix NetScaler Authentication Bypass | 6.3 | Significant | September 10, 2026 |
| SpaceX plans to build $100 billion spaceport in Louisiana | 6.3 | Significant | August 25, 2026 |
| Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days | 6.3 | Significant | August 11, 2026 |
| ChatGPT's Astra AI Rolls Out to Select Users | 6.0 | Significant | September 4, 2026 |