
Cisco FMC Auth Bypass Is Being Run By Ransomware And State Crews Alike
Kai Tanner has the Talos telemetry: three separate operators running the Cisco FMC bypass before most customers read the bulletin.
Continue reading
CVE-2026-20079 lets an unauthenticated attacker take over the console that manages Cisco firewalls, and both criminal and state-sponsored operators are already using it.
Cisco Talos confirmed this week that CVE-2026-20079, an authentication bypass in Cisco Secure Firewall Management Center, is being exploited by three separate clusters, some tied to ransomware, some to state-sponsored intrusion sets. FMC is the console that pushes policy to the firewalls themselves, so a bypass there does not compromise one box. It compromises whatever the console manages. Cisco's advisory frames this as a vulnerability disclosure with a patch attached. The Talos telemetry frames it as a vulnerability already being run in production by three unrelated operators before most customers finished reading the bulletin.
For a Hong Kong or Singapore bank, FMC sits inside the perimeter control set that HKMA's TM-G-1 and MAS's Technology Risk Management Guidelines both expect to be patched on a defined cycle, not a best-effort one. BIS said this week that routine patching schedules are inadequate against AI-accelerated exploitation and that banks should accept planned downtime for urgent fixes. A management-plane bypass under active three-way exploitation is exactly the scenario that guidance was written for. Any firm running FMC needs to confirm patch status today, not at the next change window, and check whether its own vulnerability management policy has a carve-out for CVSS 9-plus flaws with confirmed in-the-wild use.
The read-across for Check Point customers is not comfort. Check Point patched two 9.8-rated VPN certificate flaws (CVE-2026-16232 among the family) the same week, both unauthenticated RCE paths into firewall and management products. Two vendors, two management-plane compromises, one pattern: the control plane for the firewall estate is now the thing under attack, not the traffic it filters. The fix is not a firewall change. It is confirming FMC and SmartConsole are patched and that management interfaces are not reachable from anywhere they don't need to be.



