All posts

Cisco FMC CVE-2026-20079 Now Actively Exploited

Senserva Watch

Join Senserva Watch and get Three Free Unlimited Audits with our full Claude MCP, a fresh audit credit every quarter, alerts when a CVE or KB you follow changes, critical security updates when they land, the Patch Tuesday wire on release day, and 20% off when you buy.

Join Senserva Watch

One email address. No tenant connection, no agent, no call.

The Senserva daily security read, September 11, 2026

Cisco FMC CVE-2026-20079 leads the KEV additions

The one to move on first is CVE-2026-20079, a Cisco Secure Firewall Management Center authentication bypass rated CVSS 10. CISA added it to the Known Exploited Vulnerabilities catalog on 2026-09-09, and BleepingComputer reports it is being exploited by both a ransomware gang and state-sponsored hackers. FMC controls your firewall policy, so a bypass here is not a device-level problem, it is a control-plane problem for your whole perimeter.

This is the difference between patch eventually and patch now. It is KEV listed, actively exploited, and sits at the top of the hot list with an EPSS of 0.747. If you run FMC or Security Cloud Control firewall management, treat it as an active incident, not a maintenance item.

More edge and gateway flaws hit KEV this week

CVE-2026-20079 arrived alongside several other network-edge additions since 2026-09-09. Citrix NetScaler CVE-2026-19490, an authentication bypass at CVSS 9.8, and Fortinet CVE-2025-25249, a heap-based buffer overflow also at CVSS 9.8, were both added on 2026-09-09. Two MikroTik RouterOS flaws, CVE-2026-67277 (missing authentication) and CVE-2026-86060 (argument delimiter injection), landed on 2026-09-10. Google Chromium V8 CVE-2026-87491, an out-of-bounds write at CVSS 8.8, rounds out the batch and means a browser update push as well.

On the ransomware-linked side, the hot list still features SonicWall SMA1000 CVE-2026-15409 and Palo Alto PAN-OS CVE-2026-0257, both KEV listed and both tied to ransomware activity. If any of these appliances face the internet, confirm your version now.

What the press adds: PaperCut, Check Point, and GitLab

SecurityWeek and Help Net Security both report an AI-assisted campaign that exploited PaperCut flaws to breach 395 organizations. Microsoft's own security blog published guidance on detecting and disrupting AI-themed attacks with Defender the same week, so if you run PaperCut NG or MF, prioritize its patch state and review Defender coverage.

Check Point patched critical VPN vulnerabilities CVE-2026-85102 and CVE-2026-85103, also flagged by CERT-EU in advisory 2026-012. GitLab is urging users to patch a maximum severity path traversal flaw, CVE-2026-85706. None of these are on KEV yet, but VPN and source-control platforms are high-value targets, so do not wait for exploitation to schedule them.

Windows patch notes and update side effects

This month's Windows 10 1809 cumulative updates KB5122880, KB5122871, KB5122882, and KB5124008 are flagged Critical and carry KEV-linked fixes across hundreds of CVEs each. On the operational side, BleepingComputer reports Microsoft fixed Teams and Outlook launch failures on ARM Windows PCs and resolved a mouse settings reset bug in the September Windows 11 update (KB5120998). Excel update KB5002914 reportedly breaks copy and paste for some users, so validate before broad deployment.

Do this first

Work the actively exploited items in order, then clear the near-term patches.

  • Patch or isolate Cisco FMC for CVE-2026-20079 immediately, then hunt for unauthorized policy changes.
  • Confirm Citrix NetScaler (CVE-2026-19490), Fortinet (CVE-2025-25249), and MikroTik RouterOS (CVE-2026-67277, CVE-2026-86060) versions against the KEV additions.
  • Verify SonicWall SMA1000 (CVE-2026-15409) and PAN-OS (CVE-2026-0257) are patched given their ransomware links.
  • Schedule Check Point (CVE-2026-85102, CVE-2026-85103) and GitLab (CVE-2026-85706) fixes, and check PaperCut exposure.
  • Deploy the September Windows cumulative updates after validating the known Excel copy-paste issue.
  • Use Siemserva by Senserva and its free Microsoft Patch Tracker to rank open patches by KEV, EPSS, and ransomware linkage, and the non-Microsoft exploited-CVE tracker to follow these KEV additions daily.

Sources

Written by Senserva Trustworthy AI from the day's live partner feeds (CISA KEV, MSRC, FIRST EPSS, and the trusted press list), validated so every CVE, KB, and reference resolves to that data. The sources behind every feed, and their terms, are on our Data sources & thanks page. Facts as of 2026-09-11.

Senserva is a Microsoft security company and a member of the Microsoft Intelligent Security Association. Senserva audits your Microsoft 365, Intune, Defender, and Entra ID environment: complete patch state, 650+ security checks, and full reports, with clear guidance on what to fix first.

All posts

Patching across Intune, Windows Autopatch, Defender, Azure, and your endpoint managers: see Senserva patching in action.