Key
Active In-the-Wild Exploitation
18:36
· The Hacker News
3 evidence
Cisco Talos confirms dual-CVE active exploitation in FMC by nation-state and ransomware actors; CISA Sept 12 patch deadline in effect
CISA added three actively exploited vulnerabilities affecting Cisco (CVE-2026-20079, CVSS 10.0, authentication bypass), Citrix, and Fortinet to its Known Exploited Vulnerabilities catalog, mandating FCEB agencies to patch by September 12, 2026. Cisco Talos has confirmed it is actively tracking exploitation of two separate vulnerabilities in Cisco Secure Firewall Management Center (FMC) software—CVE-2026-20079 and CVE-2026-20316—by both state-sponsored and financially-motivated (ransomware) actors. Because FMC is used for centrally managing multiple Cisco Secure Firewall devices across a network, successful exploitation extends control beyond a single appliance. The dual-CVE, dual-actor-type vendor confirmation escalates the incident from a single-patch KEV entry to a coordinated multi-vector threat against enterprise firewall-management infrastructure.
CVE CVE-2026-20079CVSS 10.0Patch Deadline Sept 12