Cisco has confirmed that attackers are actively exploiting a maximum-severity authentication bypass flaw in its Secure Firewall Management Center (FMC) software, raising urgent patching concerns for organisations that rely on the platform to administer their firewall estates.

The vulnerability, tracked as CVE-2026-20079, carries a CVSS score of 10.0 — the highest possible rating. It allows an unauthenticated, remote attacker to bypass authentication controls and gain administrative access to the FMC without valid credentials, according to a Cisco security advisory reported by BleepingComputer.

Why the FMC Is a High-Value Target

The Firewall Management Center serves as the centralised control plane for Cisco Secure Firewall deployments. It handles policy configuration, threat intelligence correlation, intrusion prevention, and device monitoring across an organisation's entire firewall infrastructure.

Because the FMC acts as a single point of command over potentially hundreds of firewall appliances, a successful exploit can hand an attacker control over an organisation's full network perimeter — far beyond the impact of compromising any individual firewall. Security researchers have long described management platforms like the FMC as "crown jewel" targets: once breached, the attacker can modify access rules, disable protections, exfiltrate traffic logs, or pivot deeper into the internal network with minimal resistance.

The fact that CVE-2026-20079 requires no authentication makes this scenario particularly alarming. There is no need for stolen credentials or social engineering; the flaw can be triggered directly by any party that can reach the management interface over the network.

Broader Lessons for Network Security Teams

The incident highlights a recurring pattern in enterprise network security: management planes remain prime targets precisely because they concentrate power and trust. Organisations that expose FMC or similar management interfaces to the public internet — or even to broadly segmented internal networks — face a significantly elevated risk when these kinds of flaws surface.

Security best practices consistently recommend several mitigations:

  • Network segmentation: Management interfaces should be isolated on dedicated, access-controlled VLANs or out-of-band management networks, reachable only from trusted administrative jump hosts.
  • Timely patching: Organisations should treat vendor advisories for actively exploited vulnerabilities as high-priority operational triggers, not routine maintenance items.
  • Monitoring and logging: Anomalies in management-plane activity — unexpected login sessions, configuration changes outside change windows, or unfamiliar source IPs — should trigger immediate investigation.

Cisco has released software updates addressing the vulnerability and has urged all customers running affected FMC versions to apply patches without delay. The company did not disclose details about the nature of the in-the-wild exploitation, including attribution or scale, at the time of reporting.

What Administrators Should Do Now

Organisations using Cisco Secure Firewall Management Center should immediately consult Cisco's advisory to determine whether their software versions are affected. If patching cannot be performed immediately, Cisco typically recommends restricting network access to the management interface as a temporary compensating control.

The discovery and active exploitation of a CVSS 10.0 flaw in a platform as widely deployed as Cisco's FMC underscores a fundamental reality for IT and security teams: the tools designed to protect networks can themselves become the weakest link if not rigorously maintained and shielded. As threat actors continue to target management infrastructure, proactive patching and disciplined network architecture remain the most reliable defences.


思科證實,攻擊者正積極利用其 Secure Firewall Management Center (FMC) 軟件中一個最高級別的認證繞過漏洞,令依賴該平台管理其防火牆資產的機構面臨緊急的修補關注。

根據 BleepingComputer 報導的思科安全通告,編號為 CVE-2026-20079 的漏洞獲得 CVSS 10.0 分——最高可能評級。漏洞容許未經認證的遠端攻擊者繞過認證控制,無需有效憑證即可取得 FMC 的管理權限。

為何 FMC 是高價值目標

防火牆管理中心作為思科 Secure Firewall 部署的集中控制平面,負責處理策略配置、威脅情報關聯、入侵防禦,以及整個機構防火牆基礎設施的設備監控。

由於 FMC 作為單一指揮點控制數百台防火牆設備,一次成功的利用攻擊可使攻擊者控制機構的完整網絡周邊——其影響力遠超入侵任何單一防火牆。安全研究人員長期將 FMC 等管理平台描述為「皇冠明珠」目標:一旦被入侵,攻擊者可修改存取規則、停用防護功能、竊取流量日誌,或幾乎毫無阻礙地潛入內部網絡更深處。

CVE-2026-20079 無需認證的特性令此情景特別令人擔憂。無需竊取憑證或社會工程;任何能透過網絡接觸管理界面的實體均可直接觸發漏洞。

對網絡安全團隊的更廣泛啟示

此事件凸顯企業網絡安全中一個反覆出現的模式:管理平面之所以仍是首要目標,正是因為它們集中了權力與信任。將 FMC 或類似管理界面暴露於公共互聯網——甚至是過於廣泛分段的內部網絡——的機構,在此類漏洞浮現時將面臨顯著升高的風險。

安全最佳實踐一致建議多項緩解措施:

  • 網絡分段: 管理界面應隔離在專用、受控存取的 VLAN 或帶外管理網絡,僅可從受信任的管理跳板主機接達。
  • 及時修補: 機構應將供應商針對正遭積極利用漏洞的通告視為高優先級營運觸發項,而非例行維護項目。
  • 監控與日誌記錄: 管理平面活動異常——如意外登入會話、非變更窗口內的配置修改,或陌生來源 IP——應觸發即時調查。

思科已發布針對該漏洞的軟件更新,並敦促所有運行受影響 FMC 版本的客戶立即應用修補程式。公司並未於報導時披露關於在野利用的詳細情況,包括歸屬或規模。

管理員現時應採取的行動

使用思科 Secure Firewall Management Center 的機構應立即查閱思科通告,確定其軟件版本是否受影響。如無法立即進行修補,思科通常建議限制網絡對管理界面的存取作為暫時性補償控制。

在廣泛部署的思科 FMC 平台上發現並積極利用 CVSS 10.0 漏洞,突顯 IT 與安全團隊面對的一個基本現實:旨在保護網絡的工具,若未經嚴格維護與防護,本身就可能成為最薄弱的一環。隨著威脅行為者持續針對管理基礎設施,前瞻性修補與嚴謹的網絡架構仍是最可靠的防禦。

新聞來源 / Original News Source