Cisco Patches 24 Flaws, Including a Perfect-Score Bug That Hands Attackers Full Control

A flaw in Cisco's firewall management software scores a rare 10 out of 10 on the severity scale, meaning a remote attacker needs no password to take complete control of an affected system.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
A Cisco firewall management console displayed on a security operations center monitor, showing the vulnerability notification and severity rating of 10
Share

Key points

  • Cisco released patches for 24 security flaws across multiple products on Wednesday, including three rated critical in its SD-WAN networking software.
  • CVE-2026-20079, a flaw in Cisco Secure Firewall Management Center, scores a perfect 10 out of 10 for severity and lets an unauthenticated remote attacker gain full root control.
  • Two critical flaws in IOS XE, the software running many Cisco routers and switches, score 9.8 and 9.0 out of 10.
  • A separate high-severity bug, CVE-2026-20200, already has publicly available proof-of-concept exploit code.
  • Cisco says none of these vulnerabilities are known to be actively exploited yet.

Cisco, whose networking equipment routes much of the world's internet traffic, pushed out patches this week for 24 security flaws. Several are serious enough that an unpatched system could be handed to an attacker without a single password being guessed.

The worst is CVE-2026-20079, a flaw in Cisco Secure Firewall Management Center, the software IT teams use to control and monitor their firewalls. It earns a CVSS score (a standardised 0-to-10 rating of how dangerous a flaw is) of 10. An attacker with no account anywhere on the internet can send specially crafted web requests and run any commands they like with root access, meaning total administrative control. That's as high as the scale goes.

This is the second Secure Firewall Management Center story we've covered since late July: our 29 July report documented a hidden built-in account that was exploited as a zero-day before a patch existed. Two critical disclosures in six weeks for the same product should sharpen the urgency here.

How bad is the firewall flaw?

About as bad as it gets. A score of 10 is rare, and every ingredient for a serious breach is present: no login required, exploitable over a network, full control at the end.

Cisco's own advisory describes it plainly: a successful exploit lets an attacker "execute a variety of scripts and commands that allow root access to the device."

Firewall management software is particularly sensitive because it sits at the heart of a network's defences. Controlling it means rewriting what traffic is blocked or allowed, opening doors that should stay shut.

What else was patched?

Product CVE ID Severity score What it lets an attacker do
Secure Firewall Management Center CVE-2026-20079 10.0 Full remote control, no login needed
IOS XE (routers/switches) CVE-2026-20272 9.8 Inject and run arbitrary commands
IOS XE CVE-2026-20267 9.0 Bypass access controls
Catalyst SD-WAN CVE-2026-20303/04/10 9.9 Input manipulation and unauthorised access
IMC server management CVE-2026-20200 8.8 Run commands remotely (exploit code is public)

The Integrated Management Controller (IMC) flaw, CVE-2026-20200, deserves a closer look. It affects Cisco's UCS C-Series M7 and M8 Rack Servers in standalone mode, physical machines common in corporate data centres. Unlike the firewall bug, this one requires a valid login first. The concern is that working exploit code is already circulating publicly, as SecurityWeek reported, which drops the bar considerably for anyone wanting to abuse it.

MFA, meaning multi-factor authentication where a login requires both a password and a second verification such as a code sent to a phone, raises that bar by making stolen credentials alone insufficient.

What should IT teams do right now?

Patch. That's the only real answer. Cisco says none of these flaws are being actively used in attacks yet, but that tends to change quickly once patches are public and attackers can reverse-engineer what was fixed.

Prioritise the Firewall Management Center update first: no login requirement, perfect severity score, and a product that's already attracted zero-day attention this summer. The IMC patch follows immediately given the public exploit code. Anyone running IOS XE devices should treat this week's updates as urgent, not optional housekeeping.

© 2026 Threat Vectr