Skip to main content
Emerging ThreatsMalware & Ransomware

Cisco Secure FMC Flaw Exploited in Active Attacks

Network equipment and firewall devices mounted on racks in an industrial-style corridor.

"In August 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability," Cisco updated its CVE-2026-20079 advisory to say on Wednesday.

The flaw: unauthenticated, remote root via Secure FMC

CVE-2026-20079 is a maximum-severity authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC) software and Cisco Security Cloud Control Firewall Management. Cisco assigned the vulnerability a maximum CVSS score of 10.0 and says it "allows unauthenticated, remote attackers to bypass authentication and execute scripts and commands as root on vulnerable devices." The root cause is an improper system process created at boot time that can be triggered by sending crafted HTTP requests to the web interface of an affected device.

Timeline: March disclosure, July indicators, August confirmation

Cisco first disclosed CVE-2026-20079 in March, stating at that time it had no evidence of active exploitation. On July 29 Cisco disclosed a separate Secure FMC vulnerability, CVE-2026-20316, caused by static credentials for a low-privileged account, and said that CVE-2026-20316 had been actively exploited. In the July advisory update Cisco also published indicators of compromise (IOCs) that appeared in both the CVE-2026-20316 and CVE-2026-20079 advisories, and provided an example log entry dated Jul 23 that administrators were told to search for. The log entry Cisco shared reads:

Jul 23 16:16:33 firepower sudo: www : PWD=/ ; USER=root ; COMMAND=/usr/local/sf/bin/package_info.pl /var/tmp/license.tmp --lsm

Although Cisco's security team now says it became aware of active exploitation of CVE-2026-20079 in August, the presence of the July 23 log entry and the shared IOCs have led Cisco and outside observers to note that exploitation may have occurred earlier. Cisco's latest update confirms CVE-2026-20079 has been exploited but does not specify when attacks began, who carried them out, or what post-exploitation activity was observed.

Cisco mitigations, hot fixes, and remediation limits

Cisco says it has already patched the cloud-hosted Security Cloud Control service and released hot fixes for Secure FMC. The company states there are no workarounds and recommends customers upgrade to the latest software release. Cisco also advised administrators who discover the indicators of compromise to contact its Technical Assistance Center (TAC) for support, warning that installing the hot fixes will prevent future exploitation but "will not remediate devices already compromised."

In response to queries in late July about whether the two Secure FMC vulnerabilities were connected, a Cisco spokesperson told BleepingComputer: "On July 29, 2026, Cisco released software fixes to address vulnerabilities in Cisco Secure Firewall Management Center (FMC). Details are outlined in the security advisories (Static Credential vulnerability, Authentication Bypass vulnerability), and Cisco strongly recommends customers immediately apply the available fixes. Customers needing support should contact the Cisco Technical Assistance Center (TAC)." Cisco did not directly answer whether the July 23 activity included exploitation of both vulnerabilities.

CISA action: KEV listing and a federal deadline

On September 9, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to its Known Exploited Vulnerabilities (KEV) catalog and ordered Federal Civilian Executive Branch agencies to secure vulnerable systems by September 12, 2026. The CISA KEV listing makes the vulnerability a mandated remediation item for federal civilian agencies within that timeframe.

How security teams, procurement leaders, and federal agencies should respond

  • Security teams and technologists: Cisco says there are no workarounds; the vendor recommends upgrading to the latest software release and contacting TAC if indicators are found. Cisco also published IOCs (including the /var/tmp/license.tmp example) administrators were instructed to search for in /var/log/messages.
  • Procurement leaders and affected enterprises: The identical July hot fixes for both CVE-2026-20316 and CVE-2026-20079, and the shared IOCs, mean organizations running Secure FMC should verify whether the July updates were applied and treat the presence of the published log entry as a possible sign of compromise. Cisco warns that installing the hot fixes will not clean already compromised devices.
  • Federal Civilian Executive Branch agencies: CISA's KEV listing sets a formal remediation deadline of September 12, 2026, for vulnerable systems. Agencies will need to follow that directive and the vendor guidance to apply fixes and investigate possible prior exploitation.

The record in Cisco's advisories is clear about what is known and what Cisco did not disclose: the vulnerability is being exploited and can yield root command execution; Cisco did not reveal who is exploiting it, when the attacks began, or what post-exploitation actions were observed. The overlap of IOCs, identical hot fixes, and a Jul 23 log entry dated weeks before Cisco's August awareness raise a concrete question left on the table: whether the July activity involved exploitation of both CVE-2026-20316 and CVE-2026-20079. Cisco's advisories urge immediate patching, contact with TAC for suspected compromise, and recognition that remediation of already-compromised devices requires additional response beyond installing hot fixes.

Source: BleepingComputer — Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks