Cisco Secure FMC exploitation scope
We are monitoring for Cisco publication of campaign scope, actor attribution, additional indicators or affected-version changes for CVE-2026-20079.
Five source-linked conditions across the current edition that would materially change our assessment or the action security leaders should prioritise.
We are monitoring for Cisco publication of campaign scope, actor attribution, additional indicators or affected-version changes for CVE-2026-20079.
We are monitoring whether additional threat actors adopt BlueMoon or defenders confirm activity beyond the documented Windows builds.
Our assessment changes if Springfield confirms data compromise, extends closures beyond September 14, 2026, or identifies wider municipal impact.
We are monitoring whether ENISA or national CSIRTs publish operational changes to Single Reporting Platform submission or fallback procedures.
Our assessment changes if Veradigm identifies the vendor, publishes an affected-person count, or finds access beyond the limited API.