Cisco Flags Active Attacks Through Critical FMC Flaws Arabian Post
Cisco Talos said on September 9 that it had identified three clusters of post-compromise activity involving CVE-2026-20079 and CVE-2026-20316. The first flaw, rated a maximum 10.0 on the CVSS scale, can let an unauthenticated remote attacker bypass authentication and execute scripts and commands as root. The second involves static credentials for a low-privileged account and carries a CVSS score of 5.3, though Cisco rates it High because it can be chained with other flaws to elevate privileges.
The US Cybersecurity and Infrastructure Security Agency added CVE-2026-20079 to its Known Exploited Vulnerabilities catalogue on September 9 after confirming evidence of exploitation. Federal civilian agencies were given a September 12 remediation deadline for affected exposed assets, while CISA urged other organisations to prioritise the flaw because successful exploitation can hand attackers total control of a device.
Legal Disclaimer:
MENAFN provides the
information “as is” without warranty of any kind. We do not accept any
responsibility or liability for the accuracy, content, images, videos,
licenses, completeness, legality, or reliability of the information
contained in this article. If you have any complaints or copyright issues
related to this article, kindly contact the provider above.

Comments
No comment