Independent cybersecurity news and intelligence
SourcesRSS
Cybersecurity News. Source-grounded Intelligence.
Back to newsroom
VulnerabilitiesCyberDeltaForce Newsroom

Active exploitation of Cisco Secure Firewall Management Center vulnerabilities

Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. Current public evidence does not establish active exploitation, so the disclosure should be treated as an exposure to validate rather than evidence that every affected installation has been…

Cisco TalosSep 9, 2026, 4:08 PM UTC3 min readActive exploitation reported
IN 30 SECONDS

What you need to know

What happenedSource reporting

Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. Current public evidence does not establish active exploitation, so the disclosure should be treated as an exposure to validate rather than evidence that every affected installation has been compromised. The significance for defenders depends on whether the organizations, technologies or attack path described in the reporting overlap with their own environment. Inventory affected products and versions. Additional reporting may change the picture as affected organizations, researchers or authorities publish more evidence.

Who is affectedSource reporting

Current public evidence does not establish active exploitation, so the disclosure should be treated as an exposure to validate rather than evidence that every affected installation has been compromised.

Exploitation statusSource reporting

Active exploitation is reported in the current sources reviewed.

Why it mattersSource reporting

The main concern is the security exposure created by the affected technology.

What to do nowCDF guidance

Inventory affected products and versions.

THE NEWS

What happened

Verified reporting in clear, practical language.

Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. Current public evidence does not establish active exploitation, so the disclosure should be treated as an exposure to validate rather than evidence that every affected installation has been compromised.

The significance for defenders depends on whether the organizations, technologies or attack path described in the reporting overlap with their own environment. Inventory affected products and versions. Additional reporting may change the picture as affected organizations, researchers or authorities publish more evidence.

REFERENCES

Reference sources

CYBERDELTAFORCE INTELLIGENCE

Reporting ends here. The sections below are CyberDeltaForce analysis and defender-focused interpretation.

DEFENDER ACTIONS

What security teams should do now

  • Inventory affected products and versions.
  • Validate external and internal reachability of the vulnerable function.
  • Apply the vendor fix or mitigation and review telemetry for exploitation indicators when available.
Continue the story

Related Cybersecurity Coverage

More cybersecurity news
CyberDeltaForce publication standards