Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. Furthermore, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this flaw to its Known Exploited Vulnerabilities (KEV) catalog on September 9, 2026, ordering Federal Civilian Executive Branch agencies to patch by September 12, 2026.
What Happened: Cisco FMC Authentication Bypass Grants Root Access to Attackers
On September 9, 2026, Cisco updated its security advisory to confirm active exploitation of CVE-2026-20079. This vulnerability carries a CVSS score of 10.0, the highest possible rating. Consequently, unauthenticated remote attackers can bypass authentication and execute scripts and commands as root on affected devices.
Cisco first disclosed this flaw in March 2026. At that time, the company reported no evidence of active exploitation. However, by August 2026, Cisco PSIRT became aware of attacks in the wild. In addition, indicators of compromise published in July suggest exploitation may have begun even earlier.
Technical Details of the CVE-2026-20079 Authentication Bypass
The vulnerability stems from an improper system process created at boot time. Attackers can exploit it by sending crafted HTTP requests to the web interface of an affected device.
A successful attack allows an unauthenticated attacker to execute scripts and commands on the device with root privileges. This grants complete control over the firewall management platform.
The following products are affected:
- Cisco Secure FMC Software (on-premises deployments)
- Cisco Security Cloud Control Firewall Management
Cisco has already patched the cloud-hosted Security Cloud Control service. However, on-premises installations require manual upgrades.
Indicators of Compromise
Cisco shared the following log entry as an indicator of potential exploitation:
Jul 23 16:16:33 firepower sudo: www : PWD=/ ; USER=root ; COMMAND=/usr/local/sf/bin/package_info.pl /var/tmp/license.tmp --lsm
Administrators should search /var/log/messages for activity related to /var/tmp/license.tmp. If this entry is found, the vulnerability may have been exploited on the examined device.
Connection to CVE-2026-20316
On July 29, 2026, Cisco disclosed another Secure FMC vulnerability tracked as CVE-2026-20316. This flaw involves static credentials for a low-privileged account. Cisco released identical hot fixes for both vulnerabilities. Moreover, both advisories share the same indicators of compromise. Therefore, threat actors may have chained these vulnerabilities in the same attacks.
Business and Operational Impact
The exploitation of CVE-2026-20079 poses severe risks to enterprise network security. A compromised firewall management center can undermine the entire perimeter defense strategy.
- Complete device compromise: Attackers gain root access to the FMC platform.
- Network visibility: Threat actors can modify firewall rules and access policies.
- Lateral movement: Compromised FMC enables pivoting to other network segments.
- Regulatory exposure: Federal agencies face CISA KEV compliance deadlines.
CISA added CVE-2026-20079 to its KEV catalog on September 9, 2026. Federal Civilian Executive Branch agencies must secure vulnerable systems by September 12, 2026.
Mitigation and Recommendations
Cisco states there are no workarounds for this vulnerability. Therefore, customers must upgrade to the latest software release immediately.
Immediate Actions for Defenders
- Upgrade Cisco Secure FMC Software to the latest patched version.
- Search
/var/log/messagesfor references to/var/tmp/license.tmp. - If IOCs are found, contact Cisco TAC for incident response support.
- Review firewall policies for unauthorized changes.
- Monitor network traffic for anomalous connections to FMC interfaces.
Patch Information
Cisco released hot fixes for affected versions in July 2026. However, installing patches prevents future exploitation but does not remediate devices already compromised. Consequently, organizations must also investigate for signs of prior compromise.
Bottom line: CVE-2026-20079 is a maximum-severity authentication bypass affecting Cisco Secure FMC. Active exploitation has been confirmed and CISA has added it to the KEV catalog with a September 12, 2026 patching deadline. Organizations should upgrade immediately, hunt for IOCs, and contact Cisco TAC if compromise is suspected.
Incident Summary
| CVE ID / Incident: | CVE-2026-20079 |
| Affected Systems: | Cisco Secure FMC Software, Cisco Security Cloud Control Firewall Management (on-premises) |
| Severity: | CVSS 10.0 (Critical) |
| Disclosure Date: | March 2026 (initial); September 9, 2026 (active exploitation confirmed) |
| Patch Status: | Hot fixes available; cloud-hosted service patched automatically |
| CISA KEV Deadline: | September 12, 2026 |
References
- Cisco Security Advisory, “Cisco Secure FMC Authentication Bypass Vulnerability,” September 9, 2026, https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-onprem-fmc-authbypass-5JPp45V2, accessed September 10, 2026.
- BleepingComputer, “Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks,” September 9, 2026, https://www.bleepingcomputer.com/news/security/cisco-confirms-cve-2026-20079-secure-fmc-flaw-exploited-in-attacks/, accessed September 10, 2026.
- CISA, “CISA Adds One Known Exploited Vulnerability to Catalog,” September 9, 2026, https://www.cisa.gov/news-events/alerts, accessed September 10, 2026.