CRITICAL: Cisco Firewall Management Center CVE-2026-20079 Under Active Attack
CISA added Cisco Secure Firewall Management Center flaw CVE-2026-20079 to its Known Exploited Vulnerabilities catalog on September 9 with a September 12 federal remediation deadline. The CVSS 10.0 authentication bypass chains a static boot-time session ID and hardcoded credentials into unauthenticated root code execution on the appliance that manages your firewall policy. Patches have been available since March.