Cisco has confirmed active exploitation of CVE-2026-20079, a critical authentication-bypass vulnerability in Cisco Secure Firewall Management Center (FMC) Software with CVSS score of 10.0 and enables unauthenticated, remote attackers to bypass authentication and gain root-level access. Cisco first disclosed the vulnerability in March 2026 without evidence of exploitation, but updated its advisory on September 9 to confirm attacks. This vulnerability was added to Known Exploited Vulnerabilities catalog by CISA. The vulnerability stems from an improperly configured system process created during boot. Attackers can exploit the flaw through specially crafted HTTP requests to FMC web interface, enabling them to execute scripts and commands with root-level privileges. Cisco says the issue affects Secure FMC Software and Security Cloud Control Firewall Management, although the cloud-hosted service has already been patched. The risk of exploitation is lower when the FMC management interface is not publicly accessible. However, no workaround is available. Evidence suggests exploitation may have started before Cisco's August discovery. On July 29, Cisco disclosed CVE-2026-20316, a high-severity static-credential vulnerability that provides unauthenticated access through a low-privileged account. Both vulnerabilities share indicators of compromise, including activity involving /var/tmp/license.tmp. Cisco provided a July 23 log entry showing the www account executing package_info.pl with root. Administrators finding this activity should assume potential compromise and contact Cisco TAC, as installing a hot fix alone does not remediate already compromised systems. Organizations should immediately upgrade affected Secure FMC deployments to Cisco's latest fixed release or apply the appropriate Cisco hot fix for their software version. Fixes were provides for 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0 releases. Administrators should also review /var/log/messages* using Cisco's recommended zgrep command to identify possible exploitation. Any device showing the specified indicator should be isolated and investigated with Cisco TAC guidance before being returned to service. CISA's September 12, 2026 deadline further emphasizes the urgency of remediation for U.S. federal agencies.
Healthcare technology provider Veradigm disclosed a data breach involving a third-party vendor after attackers obtained vendor credentials that provided access to a limited Veradig...
A sophisticated, multi-stage malware campaign has been observed combining fake Google CAPTCHA verification pages, WebDAV infrastructure, malicious Cloudflare Workers and BNB Smart ...
SpyCloud, a leader in identity threat protection, has released its annual 2026 SpyCloud Identity Threat Report, revealing that non-human identities (NHIs)—including AI agents, se...