Skip to main content
Network SecurityZero-Day Watch· 3 min read· in Technology

Cisco Secure Firewall Zero-Days Under Widespread Exploitation for Unauthenticated Access

Network administrators face an urgent patching mandate as multiple maximum-severity vulnerabilities in Cisco Secure Firewall and Email Gateway appliances are actively exploited in the wild.

By Lila Morgan

Cybersecurity Analysts 40%Vendor Incident Response 30%IT Administrators 30%
Cybersecurity Analysts
Focuses on tracking the exploitation in the wild, analyzing threat actor tactics, and disseminating indicators of compromise.
Vendor Incident Response
Focuses on identifying vulnerabilities, releasing hotfixes, and urging immediate customer patching.
IT Administrators
Focuses on the operational burden, the compressed timeline for remediation, and the challenge of securing perimeter devices.

Perspectives this story doesn't cover

  • Ransomware operators exploiting the vulnerabilities
  • Organizations compromised before patches were available

Network administrators managing Cisco Secure Firewalls face an immediate patching mandate this week as the Cybersecurity and Infrastructure Security Agency (CISA) orders federal agencies to secure vulnerable systems by September 17, 2026. The directive follows confirmation that multiple zero-day vulnerabilities, including a maximum-severity authentication bypass flaw, are being actively exploited in the wild to gain root access to enterprise networks.[1][5]

The core of the crisis centers on the Cisco Secure Firewall Management Center (FMC), the central console that holds firewall policies, virtual private network configurations, and administrative credentials for an organization's entire fleet of devices. A vulnerability tracked as CVE-2026-20079 carries a maximum Common Vulnerability Scoring System (CVSS) score of 10.0 and allows unauthenticated, remote attackers to execute scripts and commands as root.[5]

Cisco initially disclosed CVE-2026-20079 in March 2026 without evidence of active exploitation. However, the company updated its advisory on September 9, 2026, stating, "In August 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability." Threat actors are leveraging crafted HTTP requests sent directly to the web interface of affected FMC devices to bypass authentication entirely.[5]

The CVE-2026-20079 vulnerability allows attackers to bypass authentication via crafted HTTP requests.

The authentication bypass is frequently chained with a second vulnerability, CVE-2026-20316, which involves static credentials for a low-privileged account. While this second flaw carries a lower CVSS score of 5.3, Cisco assigned it a High Security Impact Rating because attackers use it to establish an initial foothold before elevating privileges. The two vulnerabilities share identical indicators of compromise, including a malicious file used to establish reverse shells.[5]

"On July 29, 2026, Cisco released software fixes to address vulnerabilities in Cisco Secure Firewall Management Center (FMC)," a Cisco spokesperson stated, adding that the company "strongly recommends customers immediately apply the available fixes." The cloud-hosted Security Cloud Control service has already been patched, but on-premise deployments require manual intervention.[5]

The FMC vulnerabilities are part of a broader wave of attacks targeting Cisco infrastructure in September 2026. On September 15, Cisco disclosed another zero-day vulnerability, CVE-2026-76461, affecting the Secure Email Gateway. This unauthenticated remote code execution flaw carries a CVSS score of 9.8 and allows attackers to execute malicious SQL statements by sending a specially crafted email through the appliance.[1]

The FMC vulnerabilities are part of a broader wave of attacks targeting Cisco infrastructure in September 2026.

Cisco's Product Security Incident Response Team (PSIRT) confirmed that the Secure Email Gateway vulnerability was also under active exploitation before a patch became available. CISA added CVE-2026-76461 to its Known Exploited Vulnerabilities catalog on September 15, setting a strict three-day remediation deadline for federal civilian executive branch agencies.[1]

Administrators are urged to review network and firewall logs for indicators of compromise, including unexpected uploads to external IP addresses.

Beyond the actively exploited zero-days, Cisco released a massive hardening update in mid-September 2026, addressing dozens of additional flaws across its security portfolio. This included fixes for CVE-2026-76412, CVE-2026-76413, and CVE-2026-76420—multiple vulnerabilities in FMC software with CVSS scores of 9.0 that could allow remote attackers to perform session forgery or impersonation.[2][4]

The September hardening release also addressed an access control list bypass vulnerability, tracked as CVE-2026-20349, affecting the Adaptive Security Appliance (ASA) and Threat Defense (FTD) software. This logic error in populating group access control policies allows attackers to send traffic that should be blocked through the device, reaching protected internal networks.[6]

The concentration of vulnerabilities in perimeter security devices highlights a shift in threat actor tactics. Ransomware groups and state-sponsored actors are increasingly targeting management interfaces and VPNs because these systems are highly privileged and often excluded from standard endpoint detection and response monitoring.[3]

Perimeter security devices have become a primary target for initial access brokers and ransomware groups.

For organizations running affected Cisco Secure Firewall and Secure Email Gateway appliances, the immediate operational requirement is applying the vendor-supplied hotfixes. Cisco has explicitly stated that there are no effective workarounds for the authentication bypass or the email parsing vulnerabilities, making patching the only reliable mitigation.[2][5]

Key points

  • CISA has mandated that federal agencies patch multiple Cisco Secure Firewall vulnerabilities by September 17, 2026.
  • CVE-2026-20079 carries a maximum CVSS score of 10.0 and allows unauthenticated root access to the Firewall Management Center.
  • A separate zero-day, CVE-2026-76461, affects the Cisco Secure Email Gateway and is also under active exploitation.
  • Cisco confirms there are no effective workarounds for these vulnerabilities, requiring immediate software upgrades.

Viewpoints in depth

Vendor Incident Response

Cisco's focus on rapid patch deployment and system hardening.

For Cisco's Product Security Incident Response Team, the priority is containing the attack surface through rapid hotfix deployment. The vendor emphasizes that because attackers gain root privileges, they can delete logs and hide indicators of compromise, making behavioral network monitoring essential. Cisco's strategy relies on pushing customers to upgrade to the September 2026 hardening releases, which address the zero-days alongside dozens of other internally discovered flaws.

Cybersecurity Analysts

Security researchers tracking the exploitation patterns and threat actor tactics.

Threat intelligence teams observe a clear pattern of ransomware groups and state-sponsored actors pivoting to perimeter devices. Because firewalls and VPNs sit outside the internal network and cannot run standard endpoint detection agents, they offer a blind spot for attackers to establish persistence. Analysts note that the chaining of the authentication bypass (CVE-2026-20079) with the static credential flaw (CVE-2026-20316) demonstrates a high level of sophistication in the initial access phase.

Why this matters

Perimeter security devices are designed to protect internal networks, but these zero-day vulnerabilities allow attackers to bypass those defenses entirely, granting root access to the very systems meant to keep them out.

Sources

Source coverage

6 outlets

3 viewpoints surfaced

Cybersecurity Analysts 40%Vendor Incident Response 30%IT Administrators 30%
  1. [1]SecurityWeekCybersecurity Analysts

    Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation

    Read on SecurityWeek →
  2. [2]CiscoVendor Incident Response

    Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026

    Read on Cisco →
  3. [3]CybernewsIT Administrators

    Tough week for Cisco admins: network security system under attack, firewall management center vulnerable

    Read on Cybernews →
  4. [4]SecurityWeekCybersecurity Analysts

    Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard

    Read on SecurityWeek →
  5. [5]BleepingComputerCybersecurity Analysts

    Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

    Read on BleepingComputer →
  6. [6]CiscoVendor Incident Response

    Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Object Group Access Control List Bypass Vulnerabilities

    Read on Cisco →

Comments

Stay informed

Every angle. Every day.

Get Technology stories with full source coverage and perspective breakdowns delivered to your inbox.