Our Cybersecurity SOC partner has flagged one newly disclosed vulnerability and one updated vulnerability impacting Cisco Secure Firewall Management Center (FMC) Software. Cisco Secure FMC is the centralized management platform for Cisco firewall estates, making a compromise a high-impact event with broad downstream consequences across an organization’s network.
Both vulnerabilities affect on-premises Cisco Secure FMC Software regardless of device configuration.
Security management platforms like Cisco Secure FMC frequently operate with elevated privileges and extensive visibility into an organization’s network, making them attractive targets for adversaries seeking to weaken defensive controls. An attacker exploiting CVE-2026-20316 could log in using exposed static credentials and chain that access with other FMC vulnerabilities to escalate to full administrative privileges. CVE-2026-20079 is more severe on its own — it requires no authentication at all and can lead to full remote code execution with root-level access on the underlying system.
Yes, in part. Cisco has confirmed that CVE-2026-20316 is being actively exploited in the wild, and it has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation of CVE-2026-20079 has not been confirmed at the time of writing, but given its critical severity and unauthenticated attack path, it should be treated as an urgent patching priority.
Security technologies frequently operate with elevated privileges and broad visibility, making them attractive targets for adversaries seeking to weaken defensive controls. Our Cybersecurity SOC partner aligns its monitoring with the behaviors commonly observed following compromise of trusted security infrastructure and will continue to provide updates as new information becomes available.
If you have any questions about this advisory or would like help verifying your patch status, please contact your Black Diamond Solutions account team.