Cisco Patches 24 Flaws, Including a Perfect-Score Bug That Hands Attackers Full Control
A flaw in Cisco's firewall management software scores a rare 10 out of 10 on the severity scale, meaning a remote criminal needs no password to take complete control of an affected system.

Key points
- Cisco released patches for 24 security flaws across multiple products on Wednesday, including three rated critical in its Catalyst SD-WAN networking software.
- CVE-2026-20079, a flaw in Cisco Secure Firewall Management Center, scores a perfect 10 out of 10 for severity and lets an unauthenticated remote attacker gain full "root" control of the device.
- Two critical flaws in IOS XE, the software running many Cisco routers and switches, score 9.8 and 9.0 out of 10.
- A separate high-severity bug (CVE-2026-20200) already has publicly available proof-of-concept exploit code, meaning criminals can look up how to use it.
- Cisco says none of these vulnerabilities are known to be actively exploited yet, but that window can close quickly once patches are public.
Cisco, the company whose networking equipment routes much of the world's internet traffic, pushed out patches this week for 24 security flaws. Several of them are serious enough that an unpatched system could be handed over to criminals without a single password being guessed.
The worst of the bunch is CVE-2026-20079, a flaw in the Cisco Secure Firewall Management Center, which is the software IT teams use to control and monitor their firewalls. It earns a CVSS score (a standardised 0-to-10 rating of how dangerous a flaw is) of 10, which is as high as the scale goes. An attacker anywhere on the internet, with no account and no password, can send specially crafted web requests to a vulnerable system and run any commands they like with "root" access, meaning total administrative control.
How bad is the firewall flaw?
About as bad as it gets. A score of 10 is rare, and it means every ingredient for a serious breach is present: no login required, exploitable over a network, and the end result is full control of the device.
Cisco's own advisory describes it plainly: a successful exploit lets an attacker "execute a variety of scripts and commands that allow root access to the device."
Firewall management software is particularly sensitive because it sits at the heart of a network's defences. Controlling it means you can change what traffic is blocked or allowed, effectively opening doors that should stay shut.
What else was patched?
| Product | CVE ID | Severity score | What it lets an attacker do |
|---|---|---|---|
| Secure Firewall Management Center | CVE-2026-20079 | 10.0 | Full remote control, no login needed |
| IOS XE (routers/switches) | CVE-2026-20272 | 9.8 | Inject and run arbitrary commands |
| IOS XE | CVE-2026-20267 | 9.0 | Bypass access controls |
| Catalyst SD-WAN | CVE-2026-20303/04/10 | 9.9 | Input manipulation and unauthorised access |
| IMC server management | CVE-2026-20200 | 8.8 | Run commands remotely (exploit code is public) |
The Integrated Management Controller (IMC) flaw, CVE-2026-20200, deserves a second look. It affects Cisco's UCS C-Series M7 and M8 Rack Servers, physical machines commonly found in corporate data centres. Unlike the firewall bug, this one does require a valid login first. The concern is that working exploit code is already circulating publicly, as SecurityWeek reported, which means the bar for a criminal to use it just dropped significantly.
MFA, meaning multi-factor authentication (where a login requires both a password and a second verification like a code sent to a phone), would raise that bar further by making stolen credentials alone insufficient.
What should IT teams do right now?
Patch. That is the only real answer here. Cisco says none of these flaws are being actively used in attacks yet, but that situation tends to change quickly once patches are public and attackers can reverse-engineer what was fixed.
Prioritise the Firewall Management Center update first, given the perfect severity score and the lack of any login requirement. The IMC patch should follow immediately, given the public exploit code. Any organisation running Catalyst SD-WAN or IOS XE devices should treat this week's updates as urgent maintenance, not optional housekeeping.



