Find notable cyber news and cases, enriched with sources, timelines, and signals.

CISA mitigation guidance for CISA KEV remediation order for Cisco Secure FMC CVE-2026-20079

Advisory/Mitigation
First reported
Last updated
Happening score
H score 57
1 unique sources, 1 articles

Summary

Hide ▲

CISA added CVE-2026-20079 to the KEV catalog and ordered Federal Civilian Executive Branch agencies to secure vulnerable Cisco Secure Firewall Management Center (FMC) systems by September 12, 2026. Cisco says the flaw in Secure FMC is actively exploited, and it enables unauthenticated remote attackers to bypass authentication and run scripts and commands as root. Cisco says there are no workarounds and advises customers to upgrade to the latest software release.

Related Happenings

Cisco security patch release for CVE-2026-20303

Security Patch Release
H score43 First: 06.08.2026 20:13 Last: 06.08.2026 20:13 Sources 1

About this happening: Cisco rolled out updates for Cisco Catalyst SD-WAN Software to fix five critical CVEs across affected releases, including CVE-2026-20303 and CVE-2026-20304. Th...

SonicWall security patch release for CVE-2026-15409

Security Patch Release
H score54 First: 15.07.2026 00:23 Last: 15.07.2026 00:23 Sources 1

About this happening: SonicWall released hotfix security updates for SMA1000 appliances after confirming active exploitation of CVE-2026-15409 and CVE-2026-15410. The fixes are availabl...

Cisco Catalyst SD-WAN authentication bypass flaw actively exploited (CVE-2026-20182)

Vulnerability
H score60 First: 14.05.2026 23:09 Last: 14.05.2026 23:09 Sources 1

About this happening: CVE-2026-20182 is an actively exploited authentication bypass in Cisco Catalyst SD-WAN Controller and Cisco Catalyst SD-WAN Manager, creating a path to administr...

Latest development: 14.05.2026 23:25

Cisco released a patch for CVE-2026-20182, giving organizations using Cisco Catalyst SD-WAN Controllers a way to block the authentication bypass before UAT-8616 can continue using it for administrative access, SSH key insertion, NETCONF changes, and root escalation.

Cisco security patch release for CVE-2026-20188

Security Patch Release
H score35 First: 06.05.2026 21:06 Last: 06.05.2026 21:06 Sources 1

About this happening: Cisco released security updates for CVE-2026-20188, a high-severity DoS vulnerability in Crosswork Network Controller (CNC) and Network Services Orchestrator (NS...

Federal civilian executive branch agency hit by network compromise

Incident
H score21 First: 24.04.2026 23:34 Last: 24.04.2026 23:34 Sources 1

About this happening: A federal civilian executive branch agency was compromised in an early September 2025 intrusion that left attackers with persistent access on Cisco Firepower and Sec...

Timeline

  1. 10.09.2026 00:40 2 articles · 1h ago

    CISA mitigation guidance for CISA KEV remediation order for Cisco Secure FMC CVE-2026-20079

    Initial Disclosure

    CISA added CVE-2026-20079 to the KEV catalog and gave Federal Civilian Executive Branch agencies a September 12, 2026 deadline to secure affected Cisco FMC systems.

    Show sources