Cisco says Secure FMC authentication bypass flaw is under active exploitation
Cisco has confirmed that attackers are actively exploiting CVE-2026-20079, a critical authentication bypass vulnerability affecting Cisco Secure Firewall Management Center (FMC) software. The company...
Cisco has confirmed that attackers are actively exploiting CVE-2026-20079, a critical authentication bypass vulnerability affecting Cisco Secure Firewall Management Center (FMC) software. The company assigned the issue a CVSS severity score of 10.0, the highest possible rating.
According to Cisco, a remote, unauthenticated attacker could send specially crafted HTTP requests to the web interface of a vulnerable system and bypass authentication. Successful exploitation may allow the attacker to run scripts and commands with root-level privileges.
The flaw stems from an improperly configured system process created during device startup. Cisco initially published an advisory for CVE-2026-20079 in March and said at that time it was not aware of exploitation. In an update issued this week, the company's Product Security Incident Response Team said it became aware of active exploitation during August.
Products and response
Cisco lists Secure FMC Software and Security Cloud Control Firewall Management as affected. The vendor said its cloud-hosted Security Cloud Control service has already been patched. For customer-managed deployments, Cisco recommends upgrading to a fixed software release, noting that no workaround is available.
The U.S. Cybersecurity and Infrastructure Security Agency has added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog. Federal Civilian Executive Branch agencies have been directed to address the vulnerability by September 12, 2026.
Potential earlier activity
Indicators released in July may point to exploitation before Cisco's August confirmation. Cisco had advised administrators to review /var/log/messages for activity involving /var/tmp/license.tmp, including executions of the package_info.pl utility under root privileges.
Those indicators were also included in Cisco's advisory for CVE-2026-20316, a separate Secure FMC vulnerability involving static credentials for a low-privileged account. Cisco previously said that flaw was exploited in attacks and warned it could be combined with other issues to increase privileges. Cisco has not publicly stated whether the two vulnerabilities were used together in the same incidents.
- Apply Cisco's available fixes as soon as possible.
- Review relevant system logs for published indicators of compromise.
- Contact Cisco Technical Assistance Center if suspicious activity is found, as patching alone does not remove an attacker from an already compromised device.
