The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Cisco’s Secure Firewall Management Center (FMC) to its Known Exploited Vulnerabilities catalog on September 10, 2026.

The vulnerability, identified as CVE-2026-20079, carries a maximum CVSS severity score of 10.0. This flaw allows unauthenticated, remote attackers to bypass authentication and gain root access to the underlying operating system.

Cisco confirmed it identified active exploitation of this vulnerability in August 2026. CISA mandated that Federal Civilian Executive Branch agencies apply necessary patches by September 12, 2026.

This directive follows a separate announcement on September 9, 2026, regarding patches for multiple vulnerabilities in Cisco's IOS XR network operating system.