Skip to content
The Cybersecurity Focus
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
CVEexploitHack

Cisco Critical FMC Authentication Bypass Confirmed Under Active Exploitation

By ogwatermelon
September 10, 2026 3 Min Read
0
September 10, 2026

Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. Furthermore, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this flaw to its Known Exploited Vulnerabilities (KEV) catalog on September 9, 2026, ordering Federal Civilian Executive Branch agencies to patch by September 12, 2026.

What Happened: Cisco FMC Authentication Bypass Grants Root Access to Attackers

On September 9, 2026, Cisco updated its security advisory to confirm active exploitation of CVE-2026-20079. This vulnerability carries a CVSS score of 10.0, the highest possible rating. Consequently, unauthenticated remote attackers can bypass authentication and execute scripts and commands as root on affected devices.

Cisco first disclosed this flaw in March 2026. At that time, the company reported no evidence of active exploitation. However, by August 2026, Cisco PSIRT became aware of attacks in the wild. In addition, indicators of compromise published in July suggest exploitation may have begun even earlier.

Technical Details of the CVE-2026-20079 Authentication Bypass

The vulnerability stems from an improper system process created at boot time. Attackers can exploit it by sending crafted HTTP requests to the web interface of an affected device.

A successful attack allows an unauthenticated attacker to execute scripts and commands on the device with root privileges. This grants complete control over the firewall management platform.

The following products are affected:

  • Cisco Secure FMC Software (on-premises deployments)
  • Cisco Security Cloud Control Firewall Management

Cisco has already patched the cloud-hosted Security Cloud Control service. However, on-premises installations require manual upgrades.

Indicators of Compromise

Cisco shared the following log entry as an indicator of potential exploitation:

Jul 23 16:16:33 firepower sudo: www : PWD=/ ; USER=root ; COMMAND=/usr/local/sf/bin/package_info.pl /var/tmp/license.tmp --lsm

Administrators should search /var/log/messages for activity related to /var/tmp/license.tmp. If this entry is found, the vulnerability may have been exploited on the examined device.

Connection to CVE-2026-20316

On July 29, 2026, Cisco disclosed another Secure FMC vulnerability tracked as CVE-2026-20316. This flaw involves static credentials for a low-privileged account. Cisco released identical hot fixes for both vulnerabilities. Moreover, both advisories share the same indicators of compromise. Therefore, threat actors may have chained these vulnerabilities in the same attacks.

Business and Operational Impact

The exploitation of CVE-2026-20079 poses severe risks to enterprise network security. A compromised firewall management center can undermine the entire perimeter defense strategy.

  • Complete device compromise: Attackers gain root access to the FMC platform.
  • Network visibility: Threat actors can modify firewall rules and access policies.
  • Lateral movement: Compromised FMC enables pivoting to other network segments.
  • Regulatory exposure: Federal agencies face CISA KEV compliance deadlines.

CISA added CVE-2026-20079 to its KEV catalog on September 9, 2026. Federal Civilian Executive Branch agencies must secure vulnerable systems by September 12, 2026.

Mitigation and Recommendations

Cisco states there are no workarounds for this vulnerability. Therefore, customers must upgrade to the latest software release immediately.

Immediate Actions for Defenders

  1. Upgrade Cisco Secure FMC Software to the latest patched version.
  2. Search /var/log/messages for references to /var/tmp/license.tmp.
  3. If IOCs are found, contact Cisco TAC for incident response support.
  4. Review firewall policies for unauthorized changes.
  5. Monitor network traffic for anomalous connections to FMC interfaces.

Patch Information

Cisco released hot fixes for affected versions in July 2026. However, installing patches prevents future exploitation but does not remediate devices already compromised. Consequently, organizations must also investigate for signs of prior compromise.

Bottom line: CVE-2026-20079 is a maximum-severity authentication bypass affecting Cisco Secure FMC. Active exploitation has been confirmed and CISA has added it to the KEV catalog with a September 12, 2026 patching deadline. Organizations should upgrade immediately, hunt for IOCs, and contact Cisco TAC if compromise is suspected.

Incident Summary

CVE ID / Incident: CVE-2026-20079
Affected Systems: Cisco Secure FMC Software, Cisco Security Cloud Control Firewall Management (on-premises)
Severity: CVSS 10.0 (Critical)
Disclosure Date: March 2026 (initial); September 9, 2026 (active exploitation confirmed)
Patch Status: Hot fixes available; cloud-hosted service patched automatically
CISA KEV Deadline: September 12, 2026

References

  1. Cisco Security Advisory, “Cisco Secure FMC Authentication Bypass Vulnerability,” September 9, 2026, https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2, accessed September 10, 2026.
  2. BleepingComputer, “Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks,” September 9, 2026, https://www.bleepingcomputer.com/news/security/cisco-confirms-cve-2026-20079-secure-fmc-flaw-exploited-in-attacks/, accessed September 10, 2026.
  3. CISA, “CISA Adds One Known Exploited Vulnerability to Catalog,” September 9, 2026, https://www.cisa.gov/news-events/alerts, accessed September 10, 2026.

Tags:

CVEExploitHack
Author

ogwatermelon

Follow Me
Other Articles
Previous

ShieldCrash Zero-Day Bypasses Microsoft Defender Patch and Grants SYSTEM Access

Next

Critical Path Traversal Flaw Under Active Exploitation

AI Botnet Breach CVE Exploit Hack Incident Infostealer Linux Mac Malware Network Phishing Ransomware RCE supply chain Vishing Vulnerability Windows World Zero Day

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026

Categories

  • AI
  • BotNet
  • Breach
  • CVE
  • exploit
  • Hack
  • Incident
  • Infostealer
  • Linux
  • Mac
  • Malware
  • Phishing
  • Ransomware
  • RCE
  • supply-chain
  • Uncategorized
  • Vishing
  • Vulnerability
  • Windows
  • World
  • Zero Day
Copyright 2026 — The Cybersecurity Focus. All rights reserved.