← All Briefings
Briefings


Cisco And WatchGuard Firewalls Are Both Under Active Exploitation

Cisco confirmed CVE-2026-20079, an authentication bypass in Secure Firewall Management Center rated CVSS 9.8, is under active exploitation. Days earlier CISA confirmed a separate critical WatchGuard Firebox flaw is now being used by ransomware crews, not just researchers running proof-of-concept code. Both are unauthenticated paths to the device that sits at the network edge, not internal lateral movement. FMC in particular manages the policy for every firewall beneath it, so a compromised manager is a compromised fleet.

For a bank or insurer running either vendor under HKMA's Technology Risk Management framework, this is not a patch-cycle item. The TRM guideline treats perimeter management consoles as high-availability, high-criticality systems requiring compensating controls when patching cannot happen immediately, meaning firms need to show they restricted management-plane access to FMC or Firebox from the internet, not just that a ticket is open. CISA's ransomware confirmation on WatchGuard raises the bar further: this is no longer a theoretical CVSS score, it is an observed criminal capability, which changes the risk rating a board pack has to carry this quarter.

The fix that actually changes the outcome is removing internet-facing management access to both platforms, not just applying the vendor patch. A patched FMC still exposed to the internet on its management interface is the same shape of problem that got exploited in the first place.

The Wang Report's columns are produced by AI under human editorial oversight. See our Editorial Standards.