Cisco Secure FMC CVE-2026-20079 (CVSS 10.0) Added to CISA KEV as Talos Confirms Exploitation
One CVSS 10.0 flagship, a three-vendor KEV batch, and nation-state plus ransomware actors confirmed. Cisco Secure FMC lands under a federal remediation deadline this week.
CISA added a flaw in Cisco Secure Firewall Management Center (FMC), CVE-2026-20079, which carries the maximum severity score of CVSS 10.0, to its Known Exploited Vulnerabilities (KEV) Catalog on September 10, 2026. It did so the same day Cisco Talos confirmed the flaw is being exploited in real attacks, according to reporting from Help Net Security and SecurityWeek.
Two facts sit at the center of this story, and they arrived together. First, CVE-2026-20079 did not enter the KEV Catalog alone: The Hacker News reported it as part of a three-vendor batch that also names Citrix and Fortinet, all under a single federal remediation deadline of September 12, 2026. Second, Cisco Talos, the company's own threat intelligence group, tied the exploitation to a mix of state-sponsored and financially motivated actors. For a management console that sits above an organization's firewalls, that combination moves this out of the patch-when-convenient pile.
What this piece adds: it consolidates the KEV listing, the Talos exploitation confirmation, and the March-to-September timeline into one defender-facing view, and it separates what is confirmed from what is still unknown so security teams do not over-read the actor attribution.
What CISA Added to Its KEV Catalog
CISA's September 10 update added three vulnerabilities from three vendors and set one remediation deadline for federal agencies. The named flaw is Cisco's FMC bug, CVE-2026-20079. The other two entries belong to Citrix and Fortinet, though the specific CVE identifiers for those two vendors were not confirmed in reporting at publication.
The KEV Catalog is not a general severity list. A vulnerability lands there only when CISA has evidence it is being exploited in the wild, which is why a KEV entry changes the calculus even for a flaw that has been public for months. Under Binding Operational Directive 22-01, entries carry a remediation deadline for Federal Civilian Executive Branch (FCEB) agencies. Here that deadline is September 12, 2026, which is days, not weeks, from the listing date. The directive binds federal agencies directly, but the same catalog is widely used by private-sector teams as a prioritization signal, and it should be here too.
● CISA KEV Batch · September 10, 2026 Three vendors added to the catalog, one federal remediation deadline. |
Cisco Secure FMC · CVE-2026-20079 CVSS 10.0 authentication bypass. Confirmed exploited, per Cisco Talos. Fixed release available from Cisco. |
Citrix One flaw added to the catalog. The specific CVE identifier was not confirmed in reporting at publication. |
Fortinet One flaw added to the catalog. The specific CVE identifier was not confirmed in reporting at publication. |
FCEB remediation deadline September 12, 2026 |
Source: CISA Known Exploited Vulnerabilities Catalog and The Hacker News (September 10, 2026). Citrix and Fortinet CVE identifiers were not confirmed at publication. |
For context on how these batches usually read, see the last multi-vendor KEV batch we covered, which was led by a separate CVSS 10.0 flaw. What is different this time is that the vendor's own intelligence team confirmed the exploitation in parallel.
The Cisco Secure FMC Max-Severity Flagship
CVE-2026-20079 is an authentication bypass in Cisco Secure Firewall Management Center (FMC), the product Cisco customers use to centrally manage their Cisco Secure Firewalls. That is the detail that earns the 10.0 and the attention. FMC is not an endpoint on the edge; it is the console that administers a fleet of firewalls, so a flaw that undermines authentication on the management plane reaches across everything that console controls.
Cisco originally disclosed CVE-2026-20079 in March 2026, and a fixed software release is available. In other words, this is not a zero-day scramble for the patch itself. The patch exists. The problem the KEV listing surfaces is the set of FMC instances that have stayed on vulnerable releases in the roughly six months since disclosure, because those are the ones that a confirmed-exploited, maximum-severity flaw now puts squarely in scope.
What Cisco Talos Confirmed
Cisco Talos confirmed active exploitation of two FMC flaws, CVE-2026-20079 and CVE-2026-20316, and described the activity as coming from both state-sponsored and financially motivated (ransomware) actors, according to Help Net Security and SecurityWeek. The second flaw will be familiar to readers who followed our earlier coverage of CVE-2026-20316 in Cisco Secure FMC; the new development is that Talos now places it alongside the max-severity CVE-2026-20079 in the same exploitation reporting.
The actor description is worth reading carefully, because it is broad by design. A mix of nation-state and ransomware operators means the flaw is useful to well-resourced espionage groups and to opportunistic criminal crews at the same time, which usually signals that exploitation is reliable and the target set is worthwhile. It does not, on its own, tell a defender which group is in their environment.
Here is what the sources did not name, and what defenders should therefore not assume: no specific nation-state cluster, no named ransomware group, no named victim organizations, and no figure for how many FMC instances have been compromised. Treat the actor mix as a high-level characterization from Cisco Talos, not as attribution you can act on.
The March 2026 to September 2026 Exploitation Window
The gap between disclosure and KEV listing is the part defenders should reason about most. CVE-2026-20079 was public and patchable in March 2026. It was confirmed exploited and added to KEV in September 2026. Whatever exposure exists today has existed, in principle, across that window for any FMC instance left on a vulnerable release.
Our assessment, distinct from the reported facts above: the value of the September 10 events is not that a new patch dropped, but that the uncertainty around whether this flaw was worth prioritizing is now gone. A KEV entry plus a first-party Talos confirmation is about as clear a prioritization signal as a vulnerability program gets. Teams that deferred the March fix on the grounds that no exploitation had been observed have lost that justification, and the September 12 federal deadline should be read as a floor for urgency rather than a target that only federal agencies need to hit.
What Cisco FMC Operators and FCEB Agencies Should Verify
The single most useful action is straightforward: find every Cisco Secure Firewall Management Center instance, confirm its software version, and move any vulnerable release to Cisco's fixed version that remediates both CVE-2026-20079 and CVE-2026-20316. From there, a short verification list:
- Inventory before you patch. Confirm you know every FMC instance, including any in lab, staging, or acquired environments, since a central console is easy to forget precisely because there are few of them.
- Match the fixed release to both CVEs. Check Cisco's advisory for CVE-2026-20079 and CVE-2026-20316 and confirm the target release closes both, not just the max-severity one.
- Treat September 12 as the deadline, federal or not. FCEB agencies are bound by BOD 22-01 to remediate by that date. Everyone else should use it as the prioritization marker it is.
- Reduce management-plane exposure. Confirm FMC administration is reachable only from your management network and is not exposed to the public internet, which is good hygiene for any firewall console independent of this flaw.
- Review authentication and access logs on FMC per Cisco's guidance, and preserve them, so that if you were exposed during the window you can investigate rather than guess.
This is also a reminder that a management console belongs near the top of any vulnerability management program, because its blast radius is larger than any single device it controls. A max-severity authentication bypass on that tier is exactly the kind of asset-plus-severity pairing a program should flag automatically.
Open Questions
Several things remain unconfirmed as of publication, and they matter for how far you extend the story:
- The specific Citrix and Fortinet CVE identifiers in the same KEV batch were not confirmed in reporting.
- No named nation-state cluster has been attached to the FMC exploitation.
- No named ransomware group has been identified.
- No victim organizations have been named.
- The total number of compromised FMC instances is not known.
We will update this story as CISA, Cisco, or the reporting outlets add detail.
Primary Documents
- CISA, Known Exploited Vulnerabilities Catalog: cisa.gov/known-exploited-vulnerabilities-catalog
- The Hacker News, on the Cisco, Citrix, and Fortinet KEV additions: thehackernews.com
- Help Net Security, on Cisco FMC exploitation of CVE-2026-20079 and CVE-2026-20316: helpnetsecurity.com
- SecurityWeek, on the Cisco Secure FMC exploitation warning: securityweek.com
By Nicholas Robert, founder and editor of The CyberSignal.