KEV Entry

CVE-2026-20079

Known Exploited Vulnerability Entry ENISA

Entry Details
Confirmed Exploited

CVE-2026-20079

2026-09-09 02:00 CEST


Timestamps

2026-09-09

2026-09-09


Scope

Affected: Cisco / Cisco Secure Firewall Management Center (FMC) | Description: Vulnerability in the web interface could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. EU victimology was confirmed. Comprehensive hardening scheduled (Week of September 14th) | Patched since: 2026/08/05 | Exploitation type: ransomware | CWEs: CWE-288 | Origin source: ENISA | Notes: https://blog.talosintelligence.com/fmc-ongoing-exploitation/


References
  • {'id': 'CVE-2026-20079', 'url': 'https://www.cve.org/CVERecord?id=CVE-2026-20079'}
  • {'id': 'EUVD-2026-9438', 'url': 'https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-9438'}
  • {'id': 'source', 'url': 'https://blog.talosintelligence.com/fmc-ongoing-exploitation/'}

4e9ffd58-44ea-4b18-bc85-18c18ffccc66

ENISA
cce329bf-df49-4c6e-a027-80be2e6483bd

2026-10-02 08:52 CEST

2026-10-02 08:52 CEST

Evidence
1
Type Source Signal Confidence Details GCVE Metadata
csirt_report enisa-cnw-kev confirmed_compromise 0.75
View details
{
  "catalog": "ENISA / EU CSIRTs Network (CNW) KEV JSON",
  "cwes": [
    "CWE-288"
  ],
  "dateReported": "2026/09/09",
  "euvd": "EUVD-2026-9438",
  "exploitationType": [
    "ransomware"
  ],
  "notes": "https://blog.talosintelligence.com/fmc-ongoing-exploitation/",
  "originSource": "ENISA",
  "patchedSince": "2026/08/05",
  "product": "Cisco Secure Firewall Management Center (FMC)",
  "threatActorsExploiting": [],
  "vendorProject": "Cisco",
  "vulnerabilityName": ""
}
-