IT Advisory
A Maximum-Severity Cisco Firewall Vulnerability and a Record Patch Tuesday Hit at Once
Two separate emergencies landed on IT teams this month — and Las Vegas businesses running Cisco firewalls or unpatched Windows machines are exposed to both.
Published by CMIT Solutions of Las Vegas · Cybersecurity · 6 min read
A CVSS 10.0 Cisco Firewall Vulnerability — And No Workaround
If your business runs a Cisco Secure Firewall Management Center (FMC), you now have one of the most dangerous flaws Cisco has published this year. CVE-2026-20079 lets an unauthenticated, remote attacker send crafted HTTP requests to the FMC web interface, bypass authentication entirely, and execute scripts as root — full control of the device that manages your entire firewall fleet. It carries a CVSS score of 10.0, the maximum possible severity, and Cisco has confirmed there is no workaround. The only fix is to patch immediately.
A related flaw, CVE-2026-20131, compounds the risk on the same platform, and researchers have already documented exploitation activity in the wild. For Las Vegas businesses in hospitality, healthcare, gaming, construction, and professional services — where a firewall management console often sits at the center of a multi-site network — this isn’t a “patch it next maintenance window” issue. It’s a “patch it today” issue.
CVE-2026-20079 requires no authentication, no user interaction, and no workaround exists — and it’s landed the same month Microsoft shipped its largest Patch Tuesday of 2026.
Then Came the Biggest Patch Tuesday of the Year
Days before the Cisco disclosure, Microsoft released its September 2026 Patch Tuesday — fixing a record-breaking 966 vulnerabilities, the largest single Patch Tuesday Microsoft has ever shipped. Two of those flaws were already being actively exploited as zero-days before the patch existed:
- CVE-2026-81963 (Windows Update Stack): An elevation-of-privilege bug that lets an attacker who already has a foothold escalate to full SYSTEM control. It’s the first Windows Update Stack flaw ever exploited as a zero-day — meaning attackers found a fresh way in that most defenses weren’t built to catch.
- CVE-2026-85880 (Windows ALPC): A heap buffer overflow in Windows’ internal Advanced Local Procedure Call component. An attacker running low-privilege code can use it to escape a sandbox and seize SYSTEM privileges with zero user interaction required.
- 20 “wormable” bugs: Flaws in DHCP Server, Active Directory, DNS Server, SMB Client, and Netlogon that could let malware spread across a network the way WannaCry once did — no clicks, no phishing email, just an unpatched machine on the network.
Neither Windows zero-day requires the victim to click anything. Both assume an attacker already has some foothold on the network — through phishing, a compromised vendor account, or exactly the kind of firewall-management compromise CVE-2026-20079 hands them — and then uses these bugs to go from “one infected laptop” to “full domain control” in minutes.
- ⚠ Multi-location businesses managing several offices through one firewall console are a single point of failure if that console is compromised.
- ⚠ Hospitality and gaming networks with dozens of connected point-of-sale, badge, and camera systems give wormable malware plenty of room to spread once inside.
- ⚠ Healthcare and legal offices handling regulated data face breach-notification and compliance exposure on top of the technical damage.
- ⚠ Any business still running its own patch schedule “when there’s time” is, by definition, running behind attackers who are already exploiting these bugs.
▸ Patch Your Firewall Management Platform First
The GapFirewall management consoles are treated as “set it and forget it” appliances. Most small businesses have no process for tracking Cisco security advisories at all.
The FixConfirm your FMC version against Cisco’s advisory today, apply the patch immediately, and if you can’t verify it yourself, have your IT provider check it this week — not at the next scheduled maintenance window.
▸ Get the September Windows Updates Installed Now
The GapMany small businesses let Windows Update run “eventually” on its own schedule, which can leave machines exposed for weeks after a zero-day is public knowledge.
The FixForce-install the September cumulative update across every server and workstation this week, prioritizing internet-facing servers and domain controllers first, since the wormable bugs target exactly those roles.
▸ Assume a Foothold Already Exists
The GapBoth Windows zero-days require an attacker to already have some level of access — which means patching alone doesn’t undo a compromise that happened before the patch existed.
The FixPair this patch cycle with a review of recent admin logins, new local accounts, and firewall config changes going back 60 days — the window these vulnerabilities have realistically been exploitable.
Las Vegas Businesses: Don’t Wait for the Breach.
If you don’t know whether your firewall and servers are patched against this month’s flaws, that’s the first thing to find out.
Defending Las Vegas with CMIT Solutions
Two major vulnerability events in the same week isn’t unusual anymore — it’s the new normal. CMIT Solutions of Las Vegas tracks Cisco, Microsoft, and vendor security advisories as part of our managed IT and cybersecurity service, so our clients’ firewalls and workstations are patched before an exploit becomes a headline, not after. If you’re not certain your business is covered against this month’s flaws, we can tell you in one conversation.
Cisco Security Advisory: Secure Firewall Management Center Authentication Bypass (CVE-2026-20079)
SecurityWeek: Microsoft Patches Record Vulnerabilities, Including Two Exploited Zero-Days
Protect Your Las Vegas Business Today
This month’s Cisco and Microsoft vulnerabilities won’t wait for your next IT review — and neither should you.
Prefer to talk? Call (702) 725-2877 or email LVSales@cmitsolutions.com