Active attacks give intruders root control of Cisco firewalls

Next, the system used to manage network defenses is itself under active attack.

This is a Daily Cyber dot News update, brought to you by Bare Metal Cyber dot com, for Thursday, September 10th, 2026.

Next, the system used to manage network defenses is itself under active attack. A remotely exploitable authentication bypass can let an unauthenticated intruder take over affected Cisco Secure Firewall Management Center systems with root privileges. Cisco confirmed exploitation and said there are no workarounds. Its cloud-hosted Security Cloud Control service has already been patched. CISA also added the issue to its Known Exploited Vulnerabilities catalog and set a September 12th, 2026 deadline for federal agencies.

The business risk goes beyond one vulnerable server. A compromised firewall manager can give an attacker control over a platform that defines and monitors network defenses. Applying the fix can stop future exploitation, but it won’t remove an intruder who already has access. Leaders should therefore treat this as an incident-response priority rather than ordinary maintenance. Defenders should upgrade immediately, review the supplied indicators, and seek support if they find evidence of compromise. Patch affected systems now, then investigate them before returning them to trusted operation.

For the sources and the full Daily Cyber newsletter, visit Daily Cyber dot news.

Active attacks give intruders root control of Cisco firewalls
Broadcast by