

On September 9, Cisco confirmed what earlier warning signs had already hinted at: a security flaw in its Secure Firewall Management Center (Secure FMC) software, the tool that configures and controls Cisco firewalls across a network, is being actively exploited. The flaw, tracked as CVE-2026-20079, received a maximum severity score of 10.0 on the CVSS scale, the industry-standard scale used to rate how serious a vulnerability is.
In practice, that means an attacker doesn't need a password or any help from a user; they can simply send the right request to the FMC web interface and run commands with full administrative ("root") control over the device. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added it to its Known Exploited Vulnerabilities catalog, a government list of flaws confirmed to be under active attack, and gave federal civilian agencies until September 12 to fix it.
If you've spent time running a network, you'll recognize the gap this points to: the time between "we need to patch this" and "we've patched it and can prove we were never exposed." That gap isn't specific to this situation, and it's worth walking through what happened, what it means, and what it takes to close it.
Cisco first disclosed CVE-2026-20079 back in March 2026, stating at the time that it had no evidence the flaw was being used in real attacks. That changed over the following months. On July 29, Cisco disclosed a second, related flaw, CVE-2026-20316, and published indicators of compromise (IOCs) alongside it.
Those IOCs suggest exploitation activity going back to July 23. Then, in August, Cisco's own security team separately confirmed that CVE-2026-20079 itself was being actively used in attacks. We don't know who's behind the activity, how long it had been underway, or what attackers did once they had control.
Any organization running Cisco Secure FMC on its own infrastructure, as opposed to Cisco's cloud-hosted version, which has already been patched, and potentially anyone affected by the second flaw as well. Because Cisco's firewalls are used so deeply across large enterprise networks, this reaches financial services, public sector organizations, service providers, and multi-vendor networks across most industries, many of which treat firewall policy as exactly the kind of control that auditors and regulators expect them to be able to prove is working.
Only for organizations that take action. Cisco has fixed the issue in its cloud-hosted Security Cloud Control service, but for organizations running Secure FMC on their own hardware, there is no temporary workaround. Installing the update is the only fix. Cisco has also been clear that installing the fix only prevents future break-ins; it does not undo damage on a device that has already been compromised, which means any organization that finds the published warning signs in its logs is dealing with a security incident, not a routine software update.
Secure FMC is the central system that tells every connected firewall what traffic to allow or block, which means gaining full control of that manager effectively amounts to control over the rulebook for every firewall it oversees. That's a meaningfully bigger risk than one compromised device, since it can affect the security posture of the whole network at once.
It's also part of a broader trend rather than an isolated event. Verizon's 2025 Data Breach Investigations Report, an annual industry study of confirmed data breaches, found that among breaches where the attacker's way in was exploiting a vulnerability, the share involving "edge devices" (the VPNs, firewalls, and routers that sit at the boundary of a network) grew nearly 8x year-over-year, from 3% to 22%. The same report found that only 54% of these vulnerabilities are fixed in a given year, and it typically takes 32 days, the median, when they are.
A flaw this severe, with a government deadline attached, doesn't leave room for a timeline like that: responding well starts with being able to answer two simple-sounding but often surprisingly hard questions quickly: where does this vulnerability actually exist in our environment, and what could an attacker reach from it if they got in?
A maximum-severity flaw is a lot to absorb on top of an already full plate, especially with limited detail about who's behind it or what they're after. The response doesn't have to be complicated, but it does need to happen in a specific order:
The hardest part of responding to a flaw like this is rarely installing the update itself. It's making quick decisions with confidence, across a network with more vendors and more history than any one team can fully track. A network digital twin is a continuously updated, accurate digital model of the entire network — every device, every configuration, every connection. It's built to answer exactly these four questions directly, instead of relying on guesswork:
Repeatedly, and recently. In the roughly eighteen months before this disclosure, the same failure mode — an unauthenticated attacker gaining root-level or full control of an edge or perimeter security device — has shown up across multiple vendors:
Three different vendors, three different root causes, and one common thread: the device meant to enforce security policy became the way in.
Cisco is unlikely to be the last vendor to disclose a maximum-severity flaw in the software that manages security policy rather than the software that enforces it directly, and as management systems, automation tools, and AI-assisted operations take on more authority over the network, that software becomes a more attractive target. Vulnerabilities in management planes will continue to surface, but operating in the dark about them doesn't have to be the default. A network digital twin that can verify reachability and blast radius across the network replaces reactive patching with a clear, continuously updated picture of actual exposure.
Verifying exposure to a flaw like this starts with an accurate picture of the network — every device, every configuration, every connection. That's what a network digital twin gives you.
Download The Network Digital Twin Guide to see how it works.