Act
active
Cisco Secure FMC auth bypass CVE-2026-20079 actively exploited
- Engineer — Act: Patch Cisco Secure FMC immediately — CISA KEV listed, EPSS 0.75, public PoC on GitHub, and Cisco confirms active exploitation of this max-severity auth bypass. Check Cisco’s advisory for the patched version and apply it within your emergency patch window.
- SOC/IR — Act: Assume-breach posture for any environment with exposed FMC — sweep for unauthorized access or lateral movement from the FMC management plane since the vulnerability is actively exploited with a public PoC. Hunt for anomalous admin sessions or policy changes originating from the FMC host.
- Leader — Plan: Verify whether your network security team runs Cisco Secure FMC and confirm patching is underway; a max-severity auth bypass in a firewall management platform could expose the entire perimeter policy to attacker control, which is a board-level risk if unmitigated.
- Signals: CVE-2026-20079 — CISA KEV: listed, EPSS 0.75, public PoC on GitHub, reported by 2 collected sources
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.